> Source: [sk182251](https://support.checkpoint.com/results/sk/sk182251)

# sk182251 - Troubleshooting Connectivity Issues with Harmony SASE Agent

| Property | Value |
|----------|-------|
| Solution ID | sk182251 |
| Date Created | 2024-04-25 |
| Last Modified | 2026-02-13 |
| Technical Level | General |
| Products | SASE |
| Versions | Cloud |

## Symptoms

- Unable to connect to the network with the Harmony SASE Agent.

## Cause

* Incorrect connection protocol.
* Firewall rules blocking traffic.

## Solution

Step 1 - Change the Connection Protocol
---------------------------------------

The Harmony SASE Agent offers two major VPN protocols through which you can connect to your public and private gateways:  

* WireGuard
* OpenVPN

**Notes:**

* Your Harmony SASE Agent may be set to **Default** , that can only be modified by either an Admin or a Manager using a Policy rule under [Agent Configuration](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/SASE-Admin-Guide/Content/Topics-SASE-AG/Team/User-Profiles.htm?TocPath=Team%7CUser%20Configuration%20Profiles%7CAgent%20Configuration%7C_____0#Agent_Configuration).
* **Default** is set to the **Wireguard** protocol for most workspaces.

WireGuard and OpenVPN protocols provide high speed and security, but one may perform better based on your device and internet connection. If you encounter issues with one, switch to the other protocol. For more information, see [User Configuration Profile](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/SASE-Admin-Guide/Content/Topics-SASE-AG/Team/User-Profiles.htm?TocPath=Team%7CUser%20Configuration%20Profiles%7CAgent%20Configuration%7CWindows%7C_____0#Windows).   

Step 2 - Make sure you have connectivity to these URLs
------------------------------------------------------

* Perimeter81:
  * `yarkon-443.perimeter81.com:443 `
  * `yarkon.perimeter81.com:50051`
  * `api.perimeter81.com`
  * `sdpv2-agent-ws.perimeter81.com`
  * `sdp.perimeter81.com`
  * `perimeter81.com`
  * `<tenant-id>.perimeter81.com`
  * `auth.perimeter81.com`
  * `static.perimeter81.com`
  * `cp-external.perimeter81.com`
  * `cdn.auth0.com`
  * `*.auth0.com`  
    where `perimeter81.com` can be replaced by any other prod environment, for example, `eu.sase.checkpoint.com` or `au.sase.checkpoint.com` or `in.sase.checkpoint.com`
* Check Point:
  * `upgrade.bitdefender.com`
  * `p81-assets.perimeter81.com`
  * `fonts.googleapis.com`
  * `url-rep.kube1.iaas.checkpoint.com`
  * `cws.checkpoint.com`
  * `web-rep.iaas.checkpoint.com`
  * `te.checkpoint.com`
  * `url-rep.iaas.checkpoint.com`
  * `www.w3.org/2000/svg`
  * `c2pa.org/manifest`
  * `cloudinfra-gw.portal.checkpoint.com/`
  * Global and EU Region - `cloudinfra-gw.portal.checkpoint.com`
  * US Region - `cloudinfra-gw-us.portal.checkpoint.com `
  * AU Region - `cloudinfra-gw.ap.portal.checkpoint.com `
  * IN Region - `cloudinfra-gw.in.portal.checkpoint.com`

Step 3 - Make sure your Firewall allows Incoming and Outgoing Traffic
---------------------------------------------------------------------

The Harmony SASE Agent attempts to establish a Transport Layer Security (TLS) connection to these URLs using TCP port 443:

* <https://api.perimeter81.com> for Harmony SASE Agent in US.
* [https://api.eu.sase.checkpoint.com](https://api.eu.sase.checkpoint.com/) for Harmony SASE Agent in EU.
* <https://api.au.sase.checkpoint.com> for Harmony SASE Agent in AU.
* <https://api.in.sase.checkpoint.com> for Harmony SASE Agent in IN.

After authentication, the Harmony SASE Agent attempts to pull configurations from these SDP controllers using TCP port 5050:  
**Note**: Starting agent version 11.7, the agent uses port 443 for SDP communication.

* For Harmony SASE Agent from AU, **sdp.au.sase.checkpoint.com**
* For Harmony SASE Agent from IN, **sdp.in.sase.checkpoint.com**
* For Harmony SASE Agent from the US,**sdp.perimeter81.com**
* For Harmony SASE Agent from EU,**sdp.eu.sase.checkpoint.com**

For US Tenant:  

* **swg-pu-lb-production.safersoftware.net**using port 50051 for URL category queries
* **yarkon.perimeter81.com** using port 50051 for agent usage information. Starting agent version 11.7, the agent uses port 443 for agent usage information.

For EU Tenant:  

* **swg-pu-lb-production.safersoftware.net**using port 50051 for URL category queries
* **yarkon.eu.sase.checkpoint.com** using port 50051 for agent usage information. Starting agent version 11.7, the agent uses port 443 for agent usage information.

For AU Tenant:  

* **swg-pu-lb-production.safersoftware.net** using port 50051 for URL category queries
* **yarkon.au.sase.checkpoint.com** using port 50051 for agent usage information. Starting agent version 11.7, the agent uses port 443 for agent usage information.

For IN Tenant:  

* **swg-pu-lb-production.safersoftware.net** using port 50051 for URL category queries
* **yarkon.in.sase.checkpoint.com** using port 50051 for agent usage information. Starting agent version 11.7, the agent uses port 443 for agent usage information.

Based on the connection protocol chosen, inbound and outbound traffic is enabled with these service ports:

|------------------|-------------------|------------|
| **VPN Protocol** | **UDP**           | **TCP**    |
| WireGuard        | 51821, 8000, 8055 | N/A        |
| OpenVPN          | 1194, 636         | 1195, 8443 |

<br />

**Notes:**

* The ICMP (ping) protocol is not supported on the gateways.
* To find the list of Gateway IPs that are used by your private network, access the Harmony SASE Administrator Portal and click **Networks** .  
  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk182251/image-1670366961471202404291037381.png)

Step 4 - Open a Support Ticket
------------------------------

Open a [support ticket](mailto:sase-support@checkpoint.com) with these details attached:  

**Note** - Make sure that your Harmony SASE Agent and the Operating System are up to date with the latest updates and patches, before you open a support ticket with Check Point.

* Issue description.
* Screenshot of the error message.
* Detailed procedure followed.
* Expected outcome, for example, I expect to be able to connect using Wireguard, but all of our users can only use the OpenVPN protocol.
* Last occurrence of the issue.
* Has this issue occurred previously, or is it the first time? If it has occurred before, when did it initially start?
* [Log](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/SASE-P81-Admin-Guide/Content/Topics-SASE-AG/Devices/Using-Agent.htm#Automatic_log_collect) files from the device that experienced the issue.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
