This website uses Cookies. Click Accept to agree to our website's cookie use as described in our Privacy Policy. Click Preferences to customize your cookie settings.
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
Hi, Is it possible to block any macOS machine from logging into the VPN client? I have already verified sk182226, but it only works if you enable the compliance function when installing the client. But in this case I need to block any macOS, even without the compliance function installed.
Hello, thanks for the reply. It's working fine on Windows. I enabled the options for MacOS, but if I don't enable the compliance option on the MAC endpoint, it won't allow clients that don't verify SVC to log in. These are unmanaged MACs and I can't guarantee that they will enable the compliance option, so I wanted to block VPN access from any MAC. Would that be possible? Attached is the SVC file I'm testing.
It shouldn't matter if you enable Compliance on the Mac endpoint or not. You've included Mac-specific checks in your local.scv file (the SCVPolicyMac abd SCVNamesMac sections). These should be removed if you do not want Macs to connect.
Please check that SCV is actually enabled in Global Properties and the option to ignore when the client doesn't support it is NOT checked as shown below. Otherwise, I suggest engaging with TAC.
K, understood. I dont know for sure how SCV would work in such instance (never really tested it), but maybe worth check with TAC. let me do some tests in the lab and see how far I get.
sudo launchctl bootout system /Library/LaunchDaemons/com.checkpoint.epc.service.plist
These commands will stop the Check Point VPN client from running on the macOS endpoint computer. If you need to start the services again, you can use the following commands: