- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good afternoon Tell me, is it possible to allow remote connection with the Harmony agent only through SCV policies or is there another way? And if we use SCV policies to check the installed Harmony agent on the end device, is it possible to make sure that the first group of users has the Harmony agent checked, and the second group of users have some other checks?
Thanks for the answer! Is there any information for the first question? Checking your installed Harmony by looking at a registry entry or the name of a running application is not at all safe.
Sorry, but i do not fully comprehend the first question ! I think you are talking about Harmony Endpoint Security VPN client https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN...
Here, you do not need to check for the Harmony Version as you have automatic In-Place updates https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN...
The question is, how can I allow VPN connections only through Harmony Endpoint? The only solution I found was to configure Harmony Endpoint presence checking on the end device through SCV policies.
You only need to enable EPS VPN alone:
In this case, I, as a user, can use Endpoint Secuirty Client VPN. And Harmony Endpoint will not be mandatory for me here. And if I check the presence of Harmony Endpoint through the registry, then I can manually add this entry to the registry and it will still let me through. :(
Connection with this option checked is only possible using Endpoint Security VPN client, so it is mandatory to use this client anyway. I do not understand why you need to check the registry ?
Or do you think of Harmony Endpoint client ? That will be unable to connect without EPM active on-site or in cloud.
I want users to be able to use the VPN only after Harmony Endpoint confirms that the device is secure. For this, apparently my only option is to use SCV policies to verify that Harmony Endpoint is running on the end device.
So you want to use Harmony Endpoint like here: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_HarmonyEndpointWebManagement...
You will see in the HEP portal the state of the client and not have to use SCV at all (you do not want to look for the latest Win11 update?):
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY