- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We're in the middle of a cluster migration and have built a separate cluster with new public IPs for VPN users. Is there still no easy way to push out a new config for end-users so that the next time they connect, it goes to our new cluster and VPN? We initially point them to a DNS record but it appears that after the initial setup, it's hard-coding an IP address so messing with DNS is not going to work.
I ran across this SK: https://support.checkpoint.com/results/sk/sk103440 but that looks to only work after manually touching the end-user once to reconfigure the sites.
Is a manual touch or a push of an uninstall/reinstall with proper sites the only way?
Do you use Remote Access (Enterprise VPN client with VPN blade only) or Harmony Endpoint ? You did not post this in Endpoint, so i assume it is VPN client only. Abyway, manual touch or a push of an uninstall/reinstall with proper sites is the only way to achieve the goal you have.
Correct, Endpoint Security E8X with VPN Blade. No Harmony involved.
That is not correct - you are using Harmony Endpoint Security E8X with VPN Blade. sk103440 is only for Endpoint Security VPN & SecuRemote that you do not use.
But correctly you assume that a push operation will deploy a new vpnj site - you have
Add VPN Site
Remove VPN Site
Look here, you have to scroll down and click Agent Settings: https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/...
No, see https://support.checkpoint.com/results/sk/sk117536 - Harmony is not shown everywhere, but this is now a Harmony product. Manual touch is not possible as sk103440 does not apply as $FWDIR/conf/trac_client_1.ttm file on GW does not exist with Endpoint. But you can delete the VPN site and replace it using push operations.
If you can run scripts on remote computers, you can update trac.config with the appropriate settings.
See: https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN...
Looking at the note (Important - The client version in the Administrator's computer must be the same as the version on the user's computer.) We do have multiple versions out there... 84.XX, 85.XX, 86.XX,etc. We need a different config for every single build that's different? Could take a little bit of work but might be worth it.
If you can run the old and the new cluster at the same time you can use MultipleEntryPoint feature, called MEP. Both clusters should have the same encryption domain for remote access but different office mode IPs to avoid routing problems for the clients. With MEP you can use both clusters in active/active, active/backup, first to response….. The clients get‘s the new gateway IP if they connect to the old system once and then they use both gateways regarding your MEP configuration. If the old system is gone and did not response the new one is used.
Multiple Entry Points for Remote Access VPNs
Yes, they're both fully operational at the moment and I'm connected to the new cluster VPN right now. Different OM subnet like you said so it can route internally but almost everything else is the same. The new cluster has it's own Management Server also... if that matters?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY