- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Good afternoon Tell me, is it possible to allow remote connection with the Harmony agent only through SCV policies or is there another way? And if we use SCV policies to check the installed Harmony agent on the end device, is it possible to make sure that the first group of users has the Harmony agent checked, and the second group of users have some other checks?
Thanks for the answer! Is there any information for the first question? Checking your installed Harmony by looking at a registry entry or the name of a running application is not at all safe.
Sorry, but i do not fully comprehend the first question ! I think you are talking about Harmony Endpoint Security VPN client https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN...
Here, you do not need to check for the Harmony Version as you have automatic In-Place updates https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN...
The question is, how can I allow VPN connections only through Harmony Endpoint? The only solution I found was to configure Harmony Endpoint presence checking on the end device through SCV policies.
You only need to enable EPS VPN alone:
In this case, I, as a user, can use Endpoint Secuirty Client VPN. And Harmony Endpoint will not be mandatory for me here. And if I check the presence of Harmony Endpoint through the registry, then I can manually add this entry to the registry and it will still let me through. :(
Connection with this option checked is only possible using Endpoint Security VPN client, so it is mandatory to use this client anyway. I do not understand why you need to check the registry ?
Or do you think of Harmony Endpoint client ? That will be unable to connect without EPM active on-site or in cloud.
I want users to be able to use the VPN only after Harmony Endpoint confirms that the device is secure. For this, apparently my only option is to use SCV policies to verify that Harmony Endpoint is running on the end device.
So you want to use Harmony Endpoint like here: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_HarmonyEndpointWebManagement...
You will see in the HEP portal the state of the client and not have to use SCV at all (you do not want to look for the latest Win11 update?):
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY