Support Center > Search Results > SecureKnowledge Details
Harmony Connect - What's New? Technical Level
Solution

 

The web management and enforcement engine of Harmony Connect are delivered over the cloud. New features are added dynamically and provided to all customers.

Additional Resources:

What's New

May 6, 2021

Harmony Connect App for Remote Users

  • Harmony Connect App is available in Japanese.
  • Improved zero-touch deployment for end users with an identity provider, by automatically collecting the corporate domain name from the end user's managed device. For more, read sk172550.

Logs & Events

  • The Access Control overview page now includes the total source IP addresses for the selected time period.

Other Improvements

  • Fixed an issue where new deployments with Full SSL Inspection enabled may get several valid websites appear as untrusted at the web browser.
  • Improved the search functionality for users at Internet Access Policy for customers with Azure AD, Okta or PingID as their identity provider.

 

April 28, 2021

Policy

  • Create custom service objects and use them at the Internet Access Policy.
  • All users are automatically synchronized with Harmony Connect and available for selection as source objects at the Internet Access Policy.
    • The feature is available for Azure AD, Okta and PingID identity providers. An alternative option is creating New User Object at the Access Control policy and specifying the user's email address.

Settings

  • Administrators can choose to automatically turn off Harmony Connect App when at corporate offices using ICMP requests or HTTP requests to resources that are only available at the office (in addition to custom TCP services).

REST API

  • Harmony Connect API Version 1.4 has been published. The API to get locations has changed from /regions to /locations.
    • Note! The previous commands for /regions continue to work in this version but will be deprecated by July 28, 2021.

 

March 22, 2021

Assets

  • Our cloud service location selection in Japan is now split between Japan-East and Japan-West.

Policy

  • Import URL lists from .csv and .txt files and use them at the Access Control and SSL Inspection policies.

Settings

  • Stability fixes when configuring bypass destination and deactivation codes at Harmony Connect App.

Harmony Connect App for Remote Users

  • Harmony Connect App is now available in French and Italian.

 

March 10, 2021

Secure Client-Less Access To Corporate Applications

  • Getting Started now consists of 3 flows: secure Internet access for remote users, and secure Internet access for branch offices, and the new secure access to corporate applications.
  • Connect your data center or cloud infrastructure at Assets > Data Center & Cloud.
  • Assets > Users & Devices now enables users to get secure Internet access, secure corporate access, or both.
  • Access Control Policy now consists of 2 sub-pages: Internet Access, and the new Trusted Applications. Use the new Trusted Applications page to define your corporate applications and apply the security policy.
  • Manage your user groups (in case you do not use an identity provider), your remote server keys (for secure client-less SSH and RDP based access) or define security policies based on tags of applications from Policy > Access Control > Trusted Applications.
  • The new Settings > Trusted Applications provides additional control of the end-user portal, automatic discovery of cloud assets, and logging options.

  • Note: These capabilities are being gradually rolled out to all customer accounts. It may take some time to reach all accounts. If you would like to get earlier access, please fill this form.

Sites

  • Improved user experience when adding branch sites. The default site address is automatically calculated from the external IP address of the device or from the admin’s machine location. The default location of the cloud service is automatically set as the optimal location fit for the site address.

Harmony Connect App for Remote Users

  • Significant network performance improvements when using Harmony Connect App for secure Internet access.

 

February 28, 2021

Public Beta - Securing Remote Users

  • Secure your users' Internet Access with Harmony Connect App for Windows 10.
  • Follow the steps at Getting Started to add your users, define the policy, and configure app-specific settings.
  • Manage your remote users with the new Assets > Users & Devices page.
  • The new Trust column at Policy > Access Control allows access conditions for all users compared to only users running Harmony Connect App.
  • The new Settings > Harmony Connect App page contains important restrictions for remote users such as domains and IP addresses that should be accessed outside of Check Point's cloud, behavior of the app when users are at corporate offices, and restrictions to deactivate or uninstall the app for the end users.

General

  • The new Getting Started page enables a step-by-step onboarding for securing branch offices and remote users.

 

February 23, 2021

Infinity Portal

  • Infinity Portal now reflects Check Point's product re-organization as new families: Quantum, CloudGuard, Harmony, and Infinity Vision. Previously named CloudGuard Connect, now Harmony Connect, is Check Point's solution for up to date Access Control and Threat Prevention for branch offices and remote users delivered as a service.

Policy

  • Creation of access control policy rules based on users and user groups is now available.

Settings

  • The Identity Provider settings now include an option to set automatic sync of user groups. Administrators can see all user groups and select them at the Access Control Policy.
    • This feature is available for Azure AD, Okta and PingID identity providers. An alternative option is creating New User Group object at the Access Control Policy and specifying the Group Identifier as appearing at the identity provider.

REST API

  • Harmony Connect API Version 1.3 has been published. The changes are renaming the solution from CloudGuard Connect to Harmony Connect. There are no breaking changes at this version.

 

February 17, 2021

Policy

  • New objects: Office365 Domains of type URL List and Office365 Address Ranges of type Network List are now available to select at Access Control and SSL Inspection.
    • Both objects are automatically periodically updated.
    • A common use case is selecting both of these objects at SSL Inspection under Do not inspect the following.
  • Administrators can release locks from objects and rules by navigating to Policy > Policy Revisions and selecting the new Discard Policy Revision button for revisions that are in progress.
    • Discarding in-progress revisions is available for administrators that have the new role Manage Admin Sessions. Assign this new role to one or more administrators at Global Settings > Users.

 

February 1, 2021

Policy

  • Threat Prevention configuration is now available. Exclude IPS protections, set reminders for reviewing your exceptions as well as automatic expiration dates.

 

December 30, 2020

Policy

  • New URL List object HTTPS Inspection - Recommended Bypass is now part of the default exclusion list at the HTTPS Inspection Policy. An additional URL List object HTTPS Inspection – Optional Bypass is available for selection. Both objects are automatically periodically updated. Contents of the objects are available at sk163595.

Global Settings

  • Navigate to Global Settings - Users and assign the new Support Contact Point role for one or more administrators that should be contacted over email in case of emergency, proactive support, planned or unplanned service maintenance. In case none of the administrators at your Infinity Portal account have the Support Contact Point role, all administrators will be contacted. This is a service-specific role for Harmony Connect.

 

November 10, 2020

Settings

  • Added support for PingID as Identity Provider.

 

November 5, 2020

Sites

  • New options for creating sites with branch device type set to Aryaka, Nuage, Oracle (Talari), Versa and Asavie. Available at the Sites page and at the REST API.

Logs

  • The new Cloud Applications tab provides an overview of cloud applications and file sharing use for your connected users.
  • The Logs tab has reordered columns, emphasizing users going to applications.
  • Search for Login and Logout operation logs and find your connected users.

Settings

  • Added support for OneLogin as Identity Provider.
REST API
  • Harmony Connect API Version 1.2 (appearing as CloudGuard Connect API) has been published. The changes include additional options for Device Type when creating, updating or viewing a Site. There are no breaking changes at this version.

September 11, 2020

Global Settings

  • Visibility for your contract is now available. Navigate to Global Settings > Contracts, associate your User Center account, and your Harmony Connect SKUs will be associated to your Infinity Portal account, impacting the expiration date, threat prevention package and number of seats.

Sites

  • After enabling Harmony Connect, the creation time of the first site has been reduced to 25 minutes. Creation of other sites is now between 5 to 18 minutes.

 

July 2, 2020

Sites

  • New automatic integration with Microsoft Azure Virtual WAN. Check Point automatically creates sites and secures traffic for each resource marked as secured at your Azure portal. See this CheckMates topic for detailed steps.
REST API
  • Harmony Connect API Version 1.1 (appearing as CloudGuard Connect API) has been published. The changes include additional options for Device Type when creating, updating or viewing a Site. There are no breaking changes at this version. A Postman collection is now available and will be available in all future API versions.   

May 26, 2020

Sites

  • New cloud service locations in Italy and South Africa.

 

May 14, 2020

Global Settings

  • The new Partner Settings page allows partners and MSSPs to create child-accounts for their customers and manage them centrally.

    Partner Mode allows customers to become a partner in either one of two modes:

    • Distributor/Reseller Partner - can create child accounts, but cannot access their security
    • MSSP Partner - can create child accounts, log into the accounts and manage their security

    Enable Partner Mode by navigating to Global Settings -> Account Settings.

 

April 26, 2020

Sites

  • Sites with dynamic IP addresses and multiple ISP's are now supported. You can now create Sites, assign them with a pair of FQDN and pre-shared key for every network interface, and set up tunnels between each of your dynamic network interfaces to the two destination endpoints provided by Check Point's Harmony Connect.

 

February 24, 2020

Policy

  • DLP is now available!
    • Enable it from the Access Control policy by clicking the column headers and selecting the new Content column.
    • You can now allow or block traffic based on file types, such as source control files, or contents, such as certificates or insurance records. Combined with application-aware rules you can create more granular access rules.

Sites

  • Stability improvements when creating large number of sites, for example when using Harmony Connect API.

 

January 23, 2020

Settings

  • Identity Awareness is now available! Connect your identity provider with Harmony Connect and get your end user names shown up at the logs.

Other Improvements

  • Silver Peak, a leading SD-WAN vendor, now has a Check Point Harmony Connect page, allowing you to get Check Point security as a service without leaving the SD-WAN management dashboard. See this CheckMates topic for detailed steps.

 

January 6, 2020

Sites

  • You can now create sites with a dynamic IP address.
  • New cloud service locations in France, Sweden, Hong Kong and Bahrain.

Policy

  • Stability improvements for Full HTTPS Inspection.

Logs

  • Additional fields at threat prevention log cards: referrer URL, user agent, HTTP method.
  • Improved readability of logs for HTTPS traffic.

Other Improvements

 

November 21, 2019

Other Improvements

  • Customers that have more than one Infinity Portal account can switch between their accounts at the top-level navigation.

 

November 10, 2019

Global Settings

  • Administrators can now have a read-only or read-write role.

 

November 6, 2019

Policies

  • Review your changes before installing them with a new changes panel.
  • Undo and redo each change.

Settings

  • View which changes are currently in-progress by other administrators and which changes were previously installed with a new Revisions page.
    • Note: The new change management features refer to changes made at the Policy: access control and HTTPS Inspection rules and objects. These changes need to be installed after you make them. Changes made to Sites or Global Settings don’t require a policy install and are activated right away. For a full list of all changes across Infinity Portal, refer to Global Settings > Audits

Sites

  • We added new optional fields, Estimated Number of Users and Device Type, in order to operate our cloud service towards specific usage patterns.

 

November 6, 2019

Policies

  • Review your changes before installing them with a new changes panel.
  • Undo and redo each change.

Settings

  • View which changes are currently in-progress by other administrators and which changes were previously installed with a new Revisions page.
    • Note: The new change management features refer to changes made at the Policy: access control and HTTPS Inspection rules and objects. These changes need to be installed after you make them. Changes made to Sites or Global Settings don’t require a policy install and are activated right away. For a full list of all changes across Infinity Portal, refer to Global Settings > Audits

Sites

  • We added new optional fields, Estimated Number of Users and Device Type, in order to operate our cloud service towards specific usage patterns.

 

August 29, 2019

Settings

  • The new SmartConsole page lets you choose to manage your security policy from SmartConsole. For more, see sk156632.

 

August 27, 2019

Policies

  • Introducing rule and object locks.
    • Previously, any change made by one person was immediately visible for editing by another.
    • From now on, objects and rules that are modified by one administrator appear as locked for editing to other administrators.
    • Only after the administrator completes an Install, other administrators can edit the newly-changed rules and objects.
  • You can now discard changes that you made but that were not yet installed.

Global Settings

  • Improved user experience for the global settings pages: Administrators, Audits, API Keys, Account Settings, as well as the product menu.

 

August 12, 2019

Sites

  • We added support for ISP Redundancy. You can now create Sites with multiple external IPs, and set up tunnels between each of your external IPs to the two destination endpoints provided by Check Point's Harmony Connect.

July 18, 2019

Logs

  • Administrators can receive a weekly Security Report by email. Unsubscribe by visiting Settings > Reports & Logs.

Other Improvements

  • Fixed an issue where in some circumstances, end users browsing to a malicious website receive a browser error instead of the page blocked by company policy page.
  • All configuration changes are logged at the Audits page.

 

June 26, 2019

Policy

  • You can now receive policy installation alerts from the new notification menu. Test Check Point's advanced threat prevention immediately after receiving the Policy Installation Completed alert.

Other Improvements

  • The new API Keys page, available in Global Settings, lets users automate creation of sites. Contact us if you are interested in the API for Harmony Connect.

 

June 13, 2019

Improvements

  • Fixed issues occurring when administrators upload their organization's certificate in order to have Full HTTPS Inspection.
  • Stability improvements with policy installation process.

 

May 27, 2019 

Logs

  • Improved our Security Report, showing prevented attacks as well as application visibility in a format available for PDF Export. 

Other Improvements

  • Stability improvements when adding sites.

 

May 15, 2019

Full HTTPS Inspection is now available

  • Not inspecting HTTPS traffic exposes you to 70% of the Internet and the majority of cyberattacks.
  • Use the web management to switch from Basic HTTPS Inspection to Full HTTPS Inspection and manage the exceptions. The regulatory-dependent categories are excluded by default.

Sites

  • Onboarding is now easier. Newly-created sites now appear with the status waiting for traffic. Only after a Site receives packets from the branch does the status of the Site change to active.
  • We added official instructions for connecting with CloudGenix.

Logs

  • We improved our Cyber-Attack View, highlighting prevented attacks that relate to Internet traffic.

Other improvements

  • Japanese user interface is now available.
  • Fixed issues with browser compatibility for Safari on Mac.

 

April 24, 2019

Sites

  • We added official instructions for connecting with Citrix SD-WAN, Aruba, and Check Point Gateways. We fixed the instructions for VeloCloud. Email us for information about about integration with other vendors. 
  • In addition to managing your sites in Card Mode and Table Mode, you can now manage them over a world map.

Logs

  • Traffic logs now show the name of the application for accepted traffic.

 

Updates from before April of 2019 are available upon request.

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment