- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have an existing deployment of Check Point Mobile for Windows clients.
When the clients were installed we manually configured the Site properties for each user.
We now want to add a second site to each client configuration (as a DR option if the main site is down).
Is it possible to push the additional site configuration to the clients when they next log in?
I haven't been able to find a reference/instructions for this.
Thanks
Pedro
E86.40 and above on Windows allows updating the VPN Site details via a push operation via the Harmony Endpoint web management.
Mac support for this feature is planned for later in 2022.
This is, to my knowledge, not supported for standalone VPN clients (i.e. not managed by Harmony Endpoint).
See: https://sc1.checkpoint.com/documents/E86.40/EN/CP_E86.40_RemoteAccessClients_forWin_ReleaseNotes/Con...
Yes, you should configure the site as a MEP gateway.
Then when the client connects again, it will get the information about the alternate site.
https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/C...
Thanks, I've found the configuration instructions.
I will give this a go when we next have a window where everyone isn't on the VPN at once.
I have been reviewing the 80.20 Remote Access VPN Admin guide to try and understand MEP and I am confused about the best way to proceed.
We have a gateway at head office configured with Mobile Access and IP Sec VPN.
It provides Office mode address to Check Point Mobile for Windows clients. This is working fine.
We have now configured a new gateway at a second office. We want this to be used if the internet link at head office fails.
The offices are connected via a WAN link. The Remote Access VPN Domains overlap/are the same.
The moment the second gateway was up and configured we started to see some clients connect via it instead of head office.
I think this is Implicit - First to Respond at work.
Both gateways are configured for Visitor Mode.
I have tried disabling MEP but we are still seeing some clients connect via the second site.
"To disable MEP, set the following command to true in DBedit, the Check Point database tool:
Ideally I would prefer to set Primary-Backup but I am finding this next set of instructions regarding the backup gateway configuration confusing:
Primary-Backup
To configure Implicit Primary-Backup:
To configure the backup gateway settings:
The gateway window opens and shows the General Properties page.
For our scenario, where the gateways are linked by an internal WAN and hence have the same overlapping VPN domain, do I use option 6 and select just the gateway object as the VPN domain on the backup gateway?
And if we are using Office Mode with an Office Mode range for each gateway with our internal routing configured can we ignore step 8 and remove NAT from Office mode?
Thanks
Pedro
E86.40 and above on Windows allows updating the VPN Site details via a push operation via the Harmony Endpoint web management.
Mac support for this feature is planned for later in 2022.
This is, to my knowledge, not supported for standalone VPN clients (i.e. not managed by Harmony Endpoint).
See: https://sc1.checkpoint.com/documents/E86.40/EN/CP_E86.40_RemoteAccessClients_forWin_ReleaseNotes/Con...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY