Good afternoon.
I have a cluster of 6700 with R81.20 and a virtual SMS.
An unlimited Mobile Access license has been purchased for remote access and a blade is enabled.
In addition, the IPsec blade is enabled.
Using E87.50_Check Point VPN.msi, I performed the installation of Remote Endpoint VPN on Windows 10.
I would like to set up a policy compliance check before connecting, for example: antivirus is installed and enabled, Windows updates are installed, etc.
In the cluster properties, I followed the path of Mobile Access - Endpoint Compliance Settings and selected a policy for the test.
As far as I can see, you can set up a policy through SmartDashboard.
But it worked, when I connect in the client, I see that Copmliance is disabled.
After reading, I could not find the answer, but I found the SCV, while:
1) in Global Properties - Remote access, you must enable the Apply Secure Configuration Verification on Simplified mode Firewall Policies option;
2) Add at least 1 policy with the Remote Access community;
3) Add a policy for Desktop.
It is clear that you can manually create a large configuration file for yourself, but then why Endpoint Compliance Settings and at what point (under what conditions) Do they apply? after all, it is much more convenient for Endpoint Compliance Settings to create a policy.
I have not worked in this direction before, so I ask for help.