<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN license consumed by a remote user in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90224#M10218</link>
    <description>That's right. The SBA comes with two separate licenses and both can be installed on a single management server (endpoint and gateway management) or separate (CPSB-SBA-XXXX for the Endpoint Manager and CPSB-SB-EP-VPN for Network Manager).&lt;BR /&gt;&lt;BR /&gt;Sorry if I should have made a new post for these questions, but...in an escenario with 100 SBA-Basic users already deployed, of which only 20 are laptops that go outside and use VPN (the rest are desktops or servers that will not use VPN):&lt;BR /&gt;&lt;BR /&gt;1.- Would it be valid to deploy only the Endpoint Security VPN agent and consume the remaining 80 unused VPN licenses in the Gateway Management (CPSB-SB-EP-VPN)? This while still using the 100 SBA client installed on the Endpoint Manager??&lt;BR /&gt;&lt;BR /&gt;2.- Would enforcement of CPSB-SB-EP-VPN licenses installed in the gateway Management, using the Endpoint Security VPN client, be by concurrent users connected to the VPN?? .&lt;BR /&gt;&lt;BR /&gt;3.- If the client had two or more VPN gateways managed from the same Gw Management, remote users could connect to either of them with this license (CPSB-SB-EP-VPN)?&lt;BR /&gt;&lt;BR /&gt;I hope I was able to make myself understood and thank you very much in advance!</description>
    <pubDate>Tue, 30 Jun 2020 16:57:46 GMT</pubDate>
    <dc:creator>MikeB</dc:creator>
    <dc:date>2020-06-30T16:57:46Z</dc:date>
    <item>
      <title>VPN license consumed by a remote user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90098#M10214</link>
      <description>&lt;P&gt;Is there a way to see which VPN license (CPSB-MOB in GW or CPSB-EP-VPN in Management) is being consumed by a specific user?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 17:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90098#M10214</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2020-06-29T17:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN license consumed by a remote user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90117#M10215</link>
      <description>From the gateway perspective, there are two features that matter: Office Mode and Desktop Policy.&lt;BR /&gt;Office Mode uses either MOB (includes legacy SNX licenses) or EP (SBA, CPEP-ACCESS, or legacy SecureClient) licensing.&lt;BR /&gt;The number of Office Mode addresses you can use is the sum of your MOB and EP licenses (they are additive).&lt;BR /&gt;So, for example, if you have 200 MOB and 50 EP license, your gateway can issue up to 250 Office Mode addresses.&lt;BR /&gt;&lt;BR /&gt;Desktop policy for a Remote Access user is an EP licensed feature.&lt;BR /&gt;This is a function of two things: the client variant installed (SNX, SecuRemote, and Check Point Mobile don't have a desktop firewall, Endpoint Security VPN does), and the required policy you've configured.&lt;BR /&gt;&lt;BR /&gt;I suppose you could run into a situation where more than X users decide to install as Endpoint Security VPN than you have licenses for.&lt;BR /&gt;Offhand, I'm not sure how you'd troubleshoot that precise situation.</description>
      <pubDate>Tue, 30 Jun 2020 00:13:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90117#M10215</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-30T00:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN license consumed by a remote user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90125#M10216</link>
      <description>but how does the gateway know the number of CPSB-EP-VPN licenses you have, if this license is installed in the Management???</description>
      <pubDate>Tue, 30 Jun 2020 02:25:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90125#M10216</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2020-06-30T02:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN license consumed by a remote user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90135#M10217</link>
      <description>Simple: the management lets it know as part of the policy installation.&lt;BR /&gt;Note if your Endpoint Management and Gateway Management are separate, I believe there is a license string to install specifically on the gateway management to enable the specific features.</description>
      <pubDate>Tue, 30 Jun 2020 05:07:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90135#M10217</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-30T05:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN license consumed by a remote user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90224#M10218</link>
      <description>That's right. The SBA comes with two separate licenses and both can be installed on a single management server (endpoint and gateway management) or separate (CPSB-SBA-XXXX for the Endpoint Manager and CPSB-SB-EP-VPN for Network Manager).&lt;BR /&gt;&lt;BR /&gt;Sorry if I should have made a new post for these questions, but...in an escenario with 100 SBA-Basic users already deployed, of which only 20 are laptops that go outside and use VPN (the rest are desktops or servers that will not use VPN):&lt;BR /&gt;&lt;BR /&gt;1.- Would it be valid to deploy only the Endpoint Security VPN agent and consume the remaining 80 unused VPN licenses in the Gateway Management (CPSB-SB-EP-VPN)? This while still using the 100 SBA client installed on the Endpoint Manager??&lt;BR /&gt;&lt;BR /&gt;2.- Would enforcement of CPSB-SB-EP-VPN licenses installed in the gateway Management, using the Endpoint Security VPN client, be by concurrent users connected to the VPN?? .&lt;BR /&gt;&lt;BR /&gt;3.- If the client had two or more VPN gateways managed from the same Gw Management, remote users could connect to either of them with this license (CPSB-SB-EP-VPN)?&lt;BR /&gt;&lt;BR /&gt;I hope I was able to make myself understood and thank you very much in advance!</description>
      <pubDate>Tue, 30 Jun 2020 16:57:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90224#M10218</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2020-06-30T16:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN license consumed by a remote user</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90265#M10219</link>
      <description>1. It might technically work, but I believe it's a EULA violation to do that. For users without the full Endpoint, a MOB license is what you want.&lt;BR /&gt;2. Endpoint VPN licenses are counted based on installed instances versus Concurrent Users like MOB licenses.&lt;BR /&gt;3. Yes.</description>
      <pubDate>Wed, 01 Jul 2020 05:16:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-license-consumed-by-a-remote-user/m-p/90265#M10219</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-01T05:16:24Z</dc:date>
    </item>
  </channel>
</rss>

