Hi,
The main issue with Harmony Connect is the connection to the DC. Even tough you have an IPSEC to the DC - you will not be able to route everything over the tunnel, you need to use defined applications... And these applications are limited to HTTP/s, RDP and SSH ..and a few more. Go look at the "Assets" and "Appløication sites" - the application site is pretty much your datacenter, and then you need to add applications to it...
You would think that the clients would be able to reach the DC ip addresses, but this is not possible. I spent hours figuring this out - and when asking Check Point when we would be able to tunnel all traffic over to the on-prem DC, they told med q4 2021 - but that did not happen.. Now they are saying q4 2022 - but I have still not seen av roadmap that verifies this.
Harmony connect is pretty much useless if you ask me 🙂 .. That is maybe a bit harsh, but.. yeah : )