Support Center > Search Results > SecureKnowledge Details
Enterprise Endpoint Security E87.10 Windows Clients Technical Level
Solution
  • In a Nutshell
  • New Features and Enhancements
  • Resolved Issues
  • Endpoint Security Client Downloads
  • Standalone Client Downloads
  • Endpoint Security Server Downloads
  • Management Console Downloads
  • Utilities/Services Downloads
  • Known Limitations
  • Documentation & Related SK Articles

Notes:

  • See Endpoint Security Homepage.
  • To support SmartLog or SmartView Tracker reporting with Endpoint Security Clients for all supported servers (except R80.20 and higher), you must update the log schema. Follow instructions in sk106662.
  • Starting from E80.85, anonymized incident related data is sent to Check Point ThreatCloud, by default. See sk129753.
  • This release includes all limitations of earlier releases unless explicitly shown as resolved.

Click Here to Show the Entire Article

In a Nutshell

Item Description Download Link
Managed Client E87.10 Endpoint Security Clients for Windows OS (ZIP)
E87.10 Endpoint Security Clients for Windows OS - Dynamic package (EXE)
VPN Standalone Client E87.10 Remote Access VPN Clients for Windows (MSI)
Capsule Docs E87.10 Capsule Docs Standalone Client (EXE)
Documentation E87.x Endpoint Security Client for Windows Release Notes
sk164896 - Video: How to deploy and upgrade Endpoint Security Client?

List of New Features and Enhancements in E87.10 for Windows

ID Description
Compliance
EPS-49237 NEW: Vulnerability Management capability is now available for EA customers.
It reduces the attack surface through accurate assessment of vulnerabilities, risky applications, and computers within the organization.
VPN
ESVPN-3576 NEW: Added ability to specify fingerprint of the Gateway when creating a site from CLI.
Browser Extension
AHTP-26304 Enhancement: Admins can now force pinning of the Endpoint Security browser extension in Chromium-based browsers (Chrome, Edge and Brave).
Media Encryption
EPS-48294 Enhancement: Owner settings are now available under Advanced settings > Advanced Encryption.
EPS-48292 Enhancement: The "Allow user to change the size of encrypted media" option is now available under Advanced settings > Advanced Encryption.
EPS-48284 Enhancement: The "Allow user to change the file system of the encrypted storage" option is now available under Advanced settings > Advanced Encryption.


List of Resolved Issues in E87.10 for Windows 

ID Description
Installation
EPS-48128 An incorrect message ("Note: Restart is not required") is shown during deployment.
Threat Emulation, Anti-Malware DHS
AHTP-26525 Opening an -.exe file located in a network shared folder fails if the file was set to be run as administrator.
Forensics
EPS-49861 The EFR service may cause a high CPU load.
AHTP-26711 Working with DataTube One on version E86.70 and higher may cause the 403 error.
Anti-Malware
EPS-47468
  • E1 Anti-Malware Engine stability issues.
  • Veritas DLO application incompatibility issue.
If Anti-Malware signatures are updated from a local Server, refer to sk141033.
User Interface
EPS-45979 In Overview, when during an update, the Threat Emulation blade status is changed to "Updating", Anti-Malware blade disappears.
EPS-42461 Navigation arrows for ignoring/accepting multiple UserChecks are missing.
EPS-45697 Applied Server profiles are not shown together with policies.
VPN
ESVPN-3632 VPN service unexpectedly exits when using machine authentication and Entrust Entelligence Security Provider 10.0 for machine certificate.
General
EPS-43308 During a manual upgrade, the Endpoint Security Client icon and tooltip may not change.
EPS-49551 There may be multiple client UI processes on the Terminal Server.
EPS-48579 Configuring credentials for remote deployment in Advanced settings fails.


Endpoint Security Client Downloads

Show / Hide this section
  • Starting from E80.85, Harmony Endpoint improves coverage of malicious threats by sending anonymized Incident related data to the Check Point Threat Cloud. This feature is turned on by default. For more information, including how to disable this feature, refer to sk129753.
  • To support SmartLog or SmartView Tracker reporting with Endpoint Security Clients for all supported servers (except R80.20), you must update the log schema. Follow instructions in sk106662.

Endpoint Security E87.10 Clients

Package Description Links
Endpoint Security Clients for Windows OS - Dynamic package (Recommended, with R80.40 and higher):
Complete Endpoint Security Client for any CPU (32bit or 64bit). This is a self-extracting executable EXE file with all components (Blades) to be used as Dynamic package with R80.50 and higher.
(EXE)
Initial client:
Initial client is a very thin client without any blade used for software deployment purposes.
(ZIP)
Package Description 32bit 64bit
A package that includes Endpoint Complete package:
  • Desktop FW and Application Control
  • Anti-Malware
  • Forensics and Anti-Ransomware
  • URL Filtering
  • Anti-Bot
  • Threat Emulation
  • Media Encryption and Port Protection
  • Full Disk Encryption
  • Compliance
  • Remote Access VPN
  • Capsule Docs 
(ZIP)  (ZIP)
A package that includes Endpoint Complete package with the exception of Anti-Malware:
  • Desktop FW and Application Control
  • Forensics and Anti-Ransomware
  • URL Filtering
  • Anti-Bot
  • Threat Emulation
  • Media Encryption and Port Protection
  • Full Disk Encryption
  • Compliance
  • Remote Access VPN
  • Capsule Docs 
(ZIP)  (ZIP)
Harmony Endpoint package:
  • Forensics and Anti-Ransomware
  • Anti-Bot
  • Threat Emulation
(ZIP)  (ZIP)
Full Disk Encryption and Media Encryption and Port Protection package:
Full Disk Encryption and Media Encryption and Port Protection package.
 (ZIP)  (ZIP)
Threat Prevention package:
  • Desktop FW and Application Control
  • Anti-Malware
  • Forensics and Anti-Ransomware
  • Anti-Bot
  • Threat Emulation
  • Compliance
(ZIP) (ZIP)
Package Description Links
Endpoint Security Clients for Windows OS - Full:
A zip file that contains all package permutations listed above (excluding Dynamic package and Initial client)
(ZIP)


Standalone Client Downloads

Show / Hide this section
Note: These Standalone clients do not require Endpoint Security Server installation as part of their deployment.

Standalone E87.10 Clients

Package Description Link
Remote Access VPN Clients for Windows Remote Access VPN Client for SmartDashboard-managed clients (MSI)
Remote Access VPN Clients
(Automatic Upgrade file)
Remote Access VPN Client for automatic upgrade through the gateway. For SmartDashboard-managed clients only. (CAB)
Remote Access VPN Clients for ATM Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface. (MSI)
Remote Access VPN Clients for ATM
(Automatic Upgrade file)
Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface for automatic upgrade through the gateway. For SmartDashboard-managed clients only. (CAB)
Capsule Docs Standalone Client Capsule Docs package for environments that are managed by Capsule Docs Cloud Service. (EXE)
Capsule Docs PC Viewer Check Point Capsule Docs Viewer is a stand-alone client that lets you view documents that were protected through Capsule Docs. Get from:
Capsule Docs Portal


Endpoint Security Server Downloads 

Show / Hide this section
Endpoint Security Server Package Link
R81.20  Endpoint Security Server R81.20 sk173903
R81.10  Endpoint Security Server R81.10 sk170416
R81  Endpoint Security Server R81 sk166715
R80.40  Endpoint Security Server R80.40 sk160736
R80.30  Endpoint Security Server R80.30 sk144293


Management Console Downloads

Show / Hide this section

Management Console for Endpoint Security Server

The SmartConsole for Endpoint Security Server allows the Administrator to connect to the Endpoint Security Server and to manage the new Endpoint Security Software Blades.

Latest Versions

Endpoint Security Server Package Link
R81.10  SmartConsole for Endpoint Security Server R81.10 sk175188
R81  SmartConsole for Endpoint Security Server R81 sk170116
R80.40  SmartConsole for Endpoint Security Server R80.40  sk165473

EOL Versions

Endpoint Security Server Package Link
R80.30  SmartConsole for Endpoint Security Server R80.30 Latest Build
R80.20  SmartConsole for Endpoint Security Server R80.20 Latest Build
R77.30.03  SmartConsole for Endpoint Security Server R77.30.03 / E86.30 and higher (EXE)
R77.30  SmartConsole for Endpoint Security Server R77.30 / E86.30 and higher (EXE)
R80.10  SmartConsole for Endpoint Security Server R80.10 sk119612
R77.30 EP6.5  SmartConsole for Endpoint Security Server R77.30 EP6.5 / E86.30 and higher  (EXE)
R77.20 EP6.2  SmartConsole for Endpoint Security Server R77.20 EP6.2 / E86.30 and higher (EXE)
Note: The above packages include the Recovery Image of version 86.8.62.6


Utilities/Services Downloads

Show / Hide this section
Utilities

Package Description Link
Harmony Endpoint Remediation Manager for Administrators

The administrator utility contains the capabilities of the end-user utility plus these additional features:

  • Quarantine - Send files to quarantine.
  • Delete - Use the Harmony Endpoint remediation service to delete a file. 
  • Import - Import a quarantined file from a different computer or location. Get the administrator utility from the release homepage
(EXE)

Full Disk Encryption Offline Management Tool

Package Description Link
Full Disk Encryption Offline
Management Tool
The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery. (TGZ)
Full Disk Encryption Offline Management Tool (Japanese) The Endpoint Offline Management Tool lets administrators manage offline mode users and give them password recovery and disk recovery. (TGZ)


Known Limitations

Show / Hide this section
Issue ID Description
EPS-48987 Computers with 12th Gen Intel Core processor (such as Microsoft Surface Pro 9) do not support Smart Preboot. Legacy Preboot should be used instead.
When installing Endpoint Security Client on such computers, black screen is shown. To switch to Legacy Preboot, enter the Customization menu (by holding ctrl down + space while booting the computer) and then select "to boot Legacy Preboot".
EPS-50215 On some computers, when Media Encryption blade is installed, it is not possible to use the ISOmorphic tool. The workaround is to disable Authorization scanning in Media Encryption policy.


Documentation & Related SecureKnowledge Articles

Show / Hide this section
Endpoint Security Server
  R81.20 Release Notes
  Harmony Endpoint Server R81.20 Administration Guide 
  Harmony Endpoint Web Management R81.20 Administration Guide
  R81.10 Release Notes
  Harmony Endpoint Server R81.10 Administration Guide
  Harmony Endpoint Web Management R81.10 Administration Guide
  R81 Release Notes
  Harmony Endpoint Server R81 Administration Guide
  Harmony Endpoint Web Management R81 Administration Guide
  R80.40 Release Notes
  Endpoint Security R80.40 Administration Guide
  sk109196 - Endpoint Security Server Supported Upgrade Paths
Endpoint Security Clients
  Endpoint Security Client for Windows User Guide
  Endpoint Security Client for Windows E87.x Release Notes
  Harmony Endpoint Security for Windows MDM Deployment Guide
  sk164896 - Video: How to deploy and upgrade Endpoint Security Client?
  sk133174 - Enterprise Endpoint Security Windows Client for ATM
  sk120667 - How to upgrade to Windows 10 1607 and above with FDE in-place
  sk107255 - Endpoint Security Server versions and supported Endpoint Security Client versions
  sk110420 - Endpoint Security Client Supported Upgrade Paths
Remote Access VPN Clients
  Remote Access VPN Clients for Windows Administration Guide
  E87.x Remote Access VPN Clients for Windows Release Notes

For more information on Check Point releases, see: Release map, Upgrade and Backward Compatibility maps, Releases plan.

You can also visit our Endpoint forum, Remote Access forum, or any other CHECKMATES forum to ask questions and get answers from technical peers and Support experts.

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment