> Source: [sk34989](https://support.checkpoint.com/results/sk/sk34989)

# sk34989 - How to configure platform based bypass to Endpoint Security On Demand enforcement

| Property | Value |
|----------|-------|
| Solution ID | sk34989 |
| Date Created | 2008-05-11 |
| Last Modified | 2015-05-25 |
| Technical Level | General |

## Solution

Endpoint Security On Demand and Security Workspace are platform limited. Connectra or SSL VPN support configuring platforms that are not enforced with Endpoint Security On Demand or Security Workspace.

**Note:**
* This configuration is possible only by using the GuiDBedit tool.
* The platform identification is based on the User Agent HTTP header and therefore is not secure. ***Procedure:***

  1. Close all open GUI clients.
  2. Open GuiDBedit.
  3. Under the 'Tables' tab, expand the 'Other' table and select 'connectra_global_properties'.
  4. In the right pane, select the 'connectra_global_properties' object.
  5. In the bottom pane, find the 'ics_relax_mode_settings' field, select 'enforce_gw_and_app_repuirements' under it, and set its value to 'false'.
  6. Set the 'use_platform_exception_list' field to true.
  7. Add to the 'platform_exception_list' any User Agent pattern (ex. for iPhone use the following string - iPhone).
  8. Save all changes and close GuiDBedit.
  9. Open the SmartDashboard and install the Security Policy on the relevant Connectra or SSL VPN.

  To configure Secure Workspace configuration, repeat the procedure with the 'isw_relax_mode_settings' field.
  When a client connects to the Connectra or SSL VPN, the User Agent is analyzed.  
  If one of the patterns that were added to the 'platform_exception_list' is found in the User Agent, the Endpoint Security On Demand or Secure Workspace are not run and are not enforced.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
