Support Center > Search Results > SecureKnowledge Details
Enterprise Endpoint Security E86.30 Windows Clients Technical Level
Solution
  • New Features
  • In a Nutshell
  • Resolved Issues and Enhancements
  • Endpoint Security Clients Downloads
  • Standalone Clients Downloads
  • Endpoint Security Server Downloads
  • Management Console Downloads
  • Utilities/Services Downloads
  • Documentation and Related SecureKnowledge Articles

Notes:

  • See Endpoint Security Homepage.
  • To support SmartLog or SmartView Tracker reporting with Endpoint Security Clients for all supported servers (except R80.20 and higher), you must update the log schema. Follow instructions in sk106662.
  • Starting from E80.85, anonymized incident related data is sent to Check Point ThreatCloud, by default. See sk129753.
  • This release includes all limitations of earlier releases unless explicitly shown as resolved.

Click Here to Show the Entire Article

List of New Features in E86.30

Show / Hide this section

ID Description
General
AHTP-22532 Through network-level URL Filtering, the entire network traffic of the endpoint can now be monitored by the URL filtering logic. If any application on the user's endpoint tries to access a URL that belongs to a forbidden category, it is blocked.
EPS-33584 Endpoint Security Client new User Interface is now available in Early Availability mode. The new UI can be enabled through the Advanced settings page. See sk178346.
AHTP-24318 The "Block BitLocker Encryption" feature for non-encrypted volumes is now enabled, preventing Ransomware attackers from encrypting drives using BitLocker.


In a Nutshell

Item Description Download Link
Managed Client E86.30 Endpoint Security Clients for Windows OS (ZIP)
E86.30 Endpoint Security Clients for Windows OS - Dynamic package (EXE)
VPN Standalone Client E86.30 Remote Access Clients for Windows (MSI)
Capsule Docs E86.30 Capsule Docs Standalone Client (EXE)
Documentation E86.30 Endpoint Security Client for Windows Release Notes
sk164896 - Video: How to deploy and upgrade Endpoint Security Client?

List of Resolved Issues and Enhancements in E86.30

Show / Hide this section

Enter the string to filter the below table:

ID Description
General
EPS-38570 Enhancement: Endpoint Client now supports Log4j detection and mitigation in Compliance blade. See sk177503.
ZA-3587 C++ and SEH exceptions are improperly handled, which results in leaks and corruptions.
VPN
ESVPN-3237  Enhancement: In the roaming feature, when a VPN client works in Hub Mode with "Exclude local network" enabled, the user now does not have to re-enter credentials in case of a short network outage.
ESVPN-3135 As a result of a potential security vulnerability in Virtual Network Adapter, a local user with administrative permissions may be allowed to cause a BSOD to the local PC.
ESVPN-3241 VPN client is unable to authenticate using machine certificate if that certificate is signed with the latest Subordinate CA certificate and older Subordinate CA certificates are present in the system.
ESVPN-3270 An "Invalid CSRF token" log appears when attempting to authenticate via SAML Authentication and Google Chrome. See sk178228.
Firewall
EPS-32229 In a rare scenario, the Vsmon process unexpectedly exits during the Endpoint Client upgrade procedure.
EPS-34427 The Firewall blade does not function correctly for a short period of time when other blades are added or removed.
EPS-40450 In a rare scenario, when the Firewall blade does not block traffic after the blade is started, the "Host Isolation" feature may also malfunction.
Installation
EPS-37770 In some scenarios javaw.exe causes high CPU spikes during and after the upgrade process.
EPS-38121 The InstallLocation registry value is not preserved after adding or removing blades in the same version.
Media Encryption & Port Protection
EPS-38072 Enhancement: Media Encryption & Port Protection blade now certified for Vmware Horizon environment.
EPS-39663 Burning CD/DVD when Media Encryption and Port Protection is installed is unsuccessful. See sk178504.
Behavioral Guard
AHTP-24071 Enhancement: Upon any detection log, the user can now right-click the log and exclude the detection, which adds an exclusion to the management. The exclusion prevents this detection from taking place. It is a simplified way to automatically create exclusions when incorrect detections are identified in the logs.

Endpoint Security Client Downloads

Show / Hide this section
  • Starting from E80.85, Harmony Endpoint improves coverage of malicious threats by sending anonymized Incident related data to the Check Point Threat Cloud. This feature is turned on by default. For more information, including how to disable this feature, refer to sk129753.
  • To support SmartLog or SmartView Tracker reporting with Endpoint Security Clients for all supported servers (except R80.20), you must update the log schema. Follow instructions in sk106662.

Endpoint Security E86.30 Clients

Platform Package Description Links
Windows
Endpoint Security Clients for Windows OS - Dynamic package (Recommended, with R80.40 and higher):
Complete Endpoint Security Client for any CPU (32bit or 64bit). This is a self-extracting executable EXE file with all components (Blades) to be used as Dynamic package with R80.40 and higher.
(EXE)
Initial client:
Initial client is a very thin client without any blade used for software deployment purposes.
(ZIP)
Package Description 32bit 64bit
A package that includes Endpoint Complete package:
  • Desktop FW and Application Control
  • Anti-Malware
  • Forensics and Anti-Ransomware
  • URL Filtering
  • Anti-Bot
  • Threat Emulation
  • Media Encryption and Port Protection
  • Full Disk Encryption
  • Compliance
  • Remote Access VPN
  • Capsule Docs 
(ZIP)  (ZIP)
A package that includes Endpoint Complete package with the exception of Anti-Malware:
  • Desktop FW and Application Control
  • Forensics and Anti-Ransomware
  • URL Filtering
  • Anti-Bot
  • Threat Emulation
  • Media Encryption and Port Protection
  • Full Disk Encryption
  • Compliance
  • Remote Access VPN
  • Capsule Docs 
(ZIP)  (ZIP)
Harmony Endpoint package:
  • Forensics and Anti-Ransomware
  • Anti-Bot
  • Threat Emulation
(ZIP)  (ZIP)
Full Disk Encryption and Media Encryption and Port Protection package:
Full Disk Encryption and Media Encryption and Port Protection package.
 (ZIP)  (ZIP)
Threat Prevention package:
  • Desktop FW and Application Control
  • Anti-Malware
  • Forensics and Anti-Ransomware
  • Anti-Bot
  • Threat Emulation
  • Compliance
(ZIP) (ZIP)
Package Description Links
Endpoint Security Clients for Windows OS - Full:
A zip file that contains all package permutations listed above (excluding Dynamic package and Initial client)
(ZIP)

Standalone Clients Downloads

Show / Hide this section
Note: These Standalone clients do not require Endpoint Security Server installation as part of their deployment.

Endpoint Security E86.30 Clients

Platform Package Description Link
Windows Remote Access Clients for Windows Remote Access VPN Client for SmartDashboard-managed clients (MSI)
Remote Access VPN Clients - Automatic Upgrade file Remote Access VPN Client for automatic upgrade through the gateway. For SmartDashboard-managed clients only. (CAB)
Remote Access VPN Clients for ATM Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface. (MSI)
Remote Access VPN Clients for ATM - Automatic Upgrade file Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface for automatic upgrade through the gateway. For SmartDashboard-managed clients only. (CAB)
Capsule Docs Standalone Client Capsule Docs package for environments that are managed by Capsule Docs Cloud Service. (EXE)
Capsule Docs PC Viewer Check Point Capsule Docs Viewer is a stand-alone client that lets you view documents that were protected through Capsule Docs. Get from: Capsule Docs Portal

Endpoint Security Server Downloads 

Show / Hide this section
Endpoint Security Server Package Link
R81.10 Endpoint Security Server R81.10 sk170416
R81  Endpoint Security Server R81 sk166715
R80.40  Endpoint Security Server R80.40 sk160736
R80.30  Endpoint Security Server R80.30 sk144293

Management Console Downloads

Show / Hide this section

Management Console for Endpoint Security Server

The SmartConsole for Endpoint Security Server allows the Administrator to connect to the Endpoint Security Server and to manage the new Endpoint Security Software Blades.

Latest Versions

Endpoint Security Server Package Link
R81.10 SmartConsole for Endpoint Security Server R81.10  sk175188
R81  SmartConsole for Endpoint Security Server R81  sk170116
R80.40  SmartConsole for Endpoint Security Server R80.40  sk165473

Previous Versions

Endpoint Security Server Package Link
R80.30  SmartConsole for Endpoint Security Server R80.30 sk153153
R80.20  SmartConsole for Endpoint Security Server R80.20 sk137593
R77.30.03  SmartConsole for Endpoint Security Server R77.30.03 / E86.30 and higher (EXE)
R77.30  SmartConsole for Endpoint Security Server R77.30 / E86.30 and higher (EXE)
R80.10  SmartConsole for Endpoint Security Server R80.10 sk119612
R77.30 EP6.5  SmartConsole for Endpoint Security Server R77.30 EP6.5 / E86.30 and higher  (EXE)
R77.20 EP6.2 SmartConsole for Endpoint Security Server R77.20 EP6.2 / E86.30 and higher (EXE)
Note: The above packages include the Recovery Image of version 86.8.62.6

Utilities/Services Downloads

Show / Hide this section
Utilities

Platform Package Description Link
Windows Harmony Endpoint Remediation Manager for Administrators

The administrator utility contains the capabilities of the end-user utility plus these additional features:

  • Quarantine - Send files to quarantine. 
  • Delete - Use the Harmony Endpoint remediation service to delete a file. 
  • Import - Import a quarantined file from a different computer or location. Get the administrator utility from the release homepage
(EXE)
Capsule Docs Bulk Protection Services for Windows-based Servers and Workstations Capsule Docs Bulk Protection lets you manage file protection settings based on file locations and properties.  (EXE)
R77.30 DLP Gateway HF for Content-aware Capsule Docs protection (Mail attachments / Network locations)   (TGZ)

For more information about Capsule Docs Bulk Protection, refer to Capsule Docs Bulk Protection Services Reference Guide.

Full Disk Encryption Offline Management Tool

Platform Package Description Link
Windows Full Disk Encryption Offline Management Tool The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery. (TGZ)

Known Limitations

Show / Hide this section
Issue ID Description
EPS-41907 Upgrading a stand-alone VPN product version 86.30 to Harmony Endpoint Client version 86.30 requires a manual machine restart.
EPS-41920 Endpoint Security reaches a "disconnected" state after a long period of use without rebooting. See sk178587.

Documentation

Show / Hide this section
Document
Endpoint Security Server
R81.10 Release Notes
Harmony Endpoint Server R81.10 Administration Guide
Harmony Endpoint Web Management R81.10 Administration Guide
R81 Release Notes
Harmony Endpoint Server R81 Administration Guide
Harmony Endpoint Web Management R81 Administration Guide
R80.40 Release Notes
Endpoint Security R80.40 Administration Guide
R80.30 Release Notes 
Endpoint Security R80.30 Administration Guide
Endpoint Security Clients
Endpoint Security Client for Windows User Guide
Endpoint Security Client for Windows E86.30 Release Notes
sk164896 - Video: How to deploy and upgrade Endpoint Security Client?
Remote Access VPN Clients
Remote Access Clients for Windows E86.30 Release Notes
Remote Access Clients for Windows 32/64-bit E80.72 and Higher Administration Guide
Capsule Docs Client
Capsule Docs Plugin E80.72 and Higher
Check Point Capsule Docs Viewer User Guide: Get from: Capsule Docs Portal

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment