- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I've set to block client's connection Upon verification failure in Global properties. then test to connect a non-compliant to gateway, but the vpn still able to connect.
here are my SCV global parameters :
:SCVGlobalParams (
:enable_status_notifications (false)
:status_notifications_timeout (10)
:disconnect_when_not_verified (false)
:block_connections_on_unverified (false)
:scv_policy_timeout_hours (168)
:enforce_ip_forwarding (false)
:not_verified_script ("")
:not_verified_script_run_show (false)
:not_verified_script_run_admin (false)
:not_verified_script_run_always (false)
:allow_non_scv_clients (false)
:skip_firewall_enforcement_check (false)
)
is value in SCV's global parameters overrides setting on SMS Global properties > Remote Access > Upon Verification failure?
Hello @Gorbiabimanyu
Do you have access rule which accept traffic to encryption domain with VPN column = "RemoteAccess"?
As you can see this settings are relevant for Simplified mode FW policy:
Hello @Gorbiabimanyu
Do you have access rule which accept traffic to encryption domain with VPN column = "RemoteAccess"?
As you can see this settings are relevant for Simplified mode FW policy:
thanks, now it worked just fine.
just to be clear, when a client is non-compliant.the VPN will still be connected, but the traffic will be blocked from the rule base?
Not from the rulebase.
You can configure in Global Properties (don't have a screenshot handy) what servers you can connect to when SCV fails.
Traffic from such machines will be dropped by FW with the message "Client's configuration is not verified":
If you need to disconnect VPN you will need to set this to "true":
:disconnect_when_not_verified (true)
In this case users will not have access to ANY resources inside of encryption domain.
Exceptions mentioned by @PhoneBoy should be configured in here and will not work if you drop VPN tunnel:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY