- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good day.
According to R81.20 Remote Access manual created SVC check with additional test desktop security firewall policy (just simple block outgoing traffic to 8.8.8.8).
SCV works perfectly but firewall policy always in active state even when there is no connection to VPN server.
How to enforce Endpoint client to disable firewall in disconnected state? I would not like to allow remote clients to decide for themselves when to turn off the firewall.
I know that Harmony has such functionality, but we use simple SCV.
You can configure a different policy for connected and disconnected using the Desktop Security features (not as part of SCV).
I don't believe you can disable the firewall entirely, but you can make the policy "any any" if you'd like: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...
Added next:
:allow_ipv6 (
:gateway (allow_ipv6
:default (false)
)
)
:disconnected_in_house_fw_policy_enabled (
:gateway (disconnected_in_house_fw_policy_enabled
:default (true)
)
)
:disconnected_in_house_fw_policy_mode (
:gateway (disconnected_in_house_fw_policy_mode
:default (any_any_allow)
)
)
Installed policy
Nothing on client. After several tries Any Any Deny in Desktop Security rule still in active state after VPN disconnection.
Where did you put this configuration exactly?
These look like ttm settings, just want to confirm.
Yes in trac_client_1.ttm.
There are errors in the official documentation:
1) any_any_allow - is wrong. In sk75221 there is no any_any_allow in disconnected_in_house_fw_policy_mode section. Only all_allow instead off any_any_allow
2) Even with enabled right all_allow option "Any - Any - Allow" will not be enforced. Enforced will be first "Any User@Any" with block or allow action.
3) With enabled Location Awareness for desktop firewall is much better to use "Any - Any - Encrypt" default implied rules for inbound and outbound connections + encrypt_to_allow in disconnected_in_house_fw_policy_mode section in ttm file.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY