Configuring Compliance Policy Rules

Ensuring Alignment with the Deployed Profile

This action makes sure that all installed components are running and defines what happens if they are not running. The action options are:

Action Description
Inform if assigned Software Blades are not running Send a warning message if one or more Endpoint Security components are not running.
Restrict if assigned Software Blade are not running Restrict network access if one or more Endpoint Security components are not running.
Monitor if assigned Software Blades are not running Create log entries if one or more Endpoint Security components are not running. No messages are sent.
Do not check if assigned Software Blades are not running No check is made whether Endpoint Security components are running.

Remote Access Compliance Status

Remote Access Compliance Status selects the procedure used to enforce the upon verification failure from Policy > Access & Compliance > Remote Access Compliance Status.

The options available are:

  • Endpoint Security Compliance - Uses the Endpoint Security policy to control access to organizational resources.

  • VPN SCV Compliance - Uses SCV (Security Configuration verification) settings from the Check Point Firewall to control access to organization resources. SCV checks, which are defined in the Local.scv policy, always run on the client. This option is described in the "Secure Configuration Verification (SCV)" section of the Remote Access VPN Client for Windows Administration Guide.

    Note:

    Endpoint Security clients on macOS always get their compliance status from Endpoint SecurityCompliance, even if VPN Client verification process will use VPN SCV Compliance is selected.