<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: All Remote User use Visitor Mode ( Endpoint Connect VPN ) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/92730#M10441</link>
    <description>&lt;P&gt;It is&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107433&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank"&gt;sk107433: How to change transport method with Endpoint Clients&lt;/A&gt;&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jul 2020 10:27:59 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-07-29T10:27:59Z</dc:date>
    <item>
      <title>All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85017#M10433</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;i've a question related to the use of visitor mode&lt;/P&gt;&lt;P&gt;we have a VS r80.30 installed on a 5900 appliance that manage vpn access for our users ( other than another VS )&lt;BR /&gt;&lt;BR /&gt;we have enabled both ipsec and mobile blade, so "visitor mode" is enabled by default and cannot be removed.&lt;/P&gt;&lt;P&gt;Most of the users use "Endpoint Connect VPN" as a client.&lt;BR /&gt;&lt;BR /&gt;with "vpn show_tcpt" , "vpn tu tlist" and using the "one liner" in previous message I see that most of them use visitor mode.&lt;BR /&gt;&lt;BR /&gt;With 100 users is ok, With 340 it's a crap because is managed in "user area".&lt;/P&gt;&lt;P&gt;We contacted Checkpoint but it was useless.&lt;BR /&gt;They said the at first all the client try to use nat-t and THEN 443 and visitor mode.&lt;BR /&gt;But capturing traffic on both the client ( many clients indeed ) and the firewall we have evidence that Endpoint Connect VPN don't use NAT-T but goes directy with 443.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;This is a fresh check of our users&lt;BR /&gt;REMOTE ACCESS VPN STATS - Current&lt;BR /&gt;----------------------------------------------------------------------&lt;BR /&gt;Assigned OfficeMode IPs : 181 (Peak: 181)&lt;BR /&gt;Capsule/Endpoint VPN Users : 179 (Peak: 179) using Visitor Mode: 177&lt;BR /&gt;Capsule Workspace Users : 0 (Peak: 0)&lt;BR /&gt;MAB Portal Users : 0 (Peak: 4)&lt;BR /&gt;L2TP Users : 0 (Peak: 0)&lt;BR /&gt;SNX Users : 0 (Peak: 8)&lt;/img&gt;&lt;/P&gt;&lt;P&gt;LICENSES&lt;BR /&gt;----------------------------------------------------------------------&lt;BR /&gt;SecuRemote Users : 45000&lt;BR /&gt;Endpoint Connect Users :&lt;BR /&gt;Mobile Access Users : Unlimited&lt;BR /&gt;SNX Users :&lt;/P&gt;&lt;P&gt;Can the behaviour written above be cause by our licences? (&amp;nbsp;Endpoint Connect Users : "" )&lt;BR /&gt;&lt;BR /&gt;Too many visitor mode users cause really BAD performance,i'm talking about 800ms for a ping response, using Web Portal or the SSL Extender solve the problem but the customer don't want to use this solution.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 06:23:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85017#M10433</guid>
      <dc:creator>Supporto_Checkp</dc:creator>
      <dc:date>2020-05-13T06:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85023#M10434</link>
      <description>&lt;P&gt;Quoting from&amp;nbsp;&lt;SPAN&gt;sk105119&lt;/SPAN&gt;&lt;/P&gt;
&lt;H4&gt;&lt;EM&gt;Visitor mode&lt;/EM&gt;&lt;/H4&gt;
&lt;UL type="disc"&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;Visitor Mode is supported by the legacy SecureClient and by Endpoint Connect (Endpoint Security) Client.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;U&gt;&lt;STRONG&gt;Each packet in Visitor Mode is processed in user space, which causes a load on CPU on Security Gateway (only several hundred Visitor Mode clients can be handled by the Security Gateway).&lt;/STRONG&gt;&lt;/U&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;EM&gt;In SecureClient, if enabled by the user, Visitor Mode is never automatically turned off. It is recommended that users only enable Visitor Mode when essential (typical to Airport and Hotel Wi-Fi spots), and disable it afterwards.&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You can disable Mobile Access. hence forcing Endpoint Clients to use IPsec.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 07:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85023#M10434</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-05-13T07:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85025#M10435</link>
      <description>we cannot disable mobile access because we have users that use it.&lt;BR /&gt;&lt;BR /&gt;Also the same client ( I mean example PC and SAME version of endpoint connect )&lt;BR /&gt;use 443 for auth and 4500 for traffic on a physical cluster configured in the same way&lt;BR /&gt;BUT use visitor mode on this vsx.&lt;BR /&gt;We don't USE SecureClient.&lt;BR /&gt;We use Endpoint Connect VPN as Client or SSL Extender&lt;BR /&gt;and with "same configuraion" i really mean that are the same.&lt;BR /&gt;Each global properites,each license,each gateway setting related to vpn</description>
      <pubDate>Wed, 13 May 2020 07:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85025#M10435</guid>
      <dc:creator>Supporto_Checkp</dc:creator>
      <dc:date>2020-05-13T07:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85027#M10436</link>
      <description>&lt;P&gt;Basically, you are saying the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;You have identical VPN config for both VSX and physical environment&lt;/LI&gt;
&lt;LI&gt;Same Endpoint clients use ports 4500 &amp;amp; 443 to connect to physical, while using &lt;EM&gt;only&lt;/EM&gt; 443 when connecting to a VS.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This does not make a lot of sense, to be honest. How did you check? Any traces on the client side?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 07:58:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85027#M10436</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-05-13T07:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85032#M10437</link>
      <description>&lt;P&gt;problem solved.&lt;BR /&gt;On the vsx cluster there was a setting changed in database , not GUI or SmartConsole ( i don't know if was a default on older version ,this DB was born with 77 or older or someone changed it )&lt;BR /&gt;and the transport mode was set to "Visitor Mode"&lt;BR /&gt;i've changed it to "Auto Detect" and now .. NAT-T! (That surely is the default on newer DB version )&lt;/P&gt;&lt;P&gt;+-----------------------------------------+-----------------------+---------------------+&lt;BR /&gt;| Peer: x.x.x.x (ae0d46b71e22993d) | MSA: 2aab11bf1040 | i: 0 ref: 17 |&lt;BR /&gt;| Methods: ESP Tunnel AES-128 SHA1 | | i: 1 ref: 9 |&lt;BR /&gt;| My TS: 0.0.0.0/0 | | i: 2 ref: 11 |&lt;BR /&gt;| Peer TS: 10.115.0.16 | | i: 3 ref: 5 |&lt;BR /&gt;| User: y.y.y.y | NAT-T | i: 4 ref: 11 |&lt;BR /&gt;| MSPI: 5b (i: 0, p: 0) | Out SPI: d43a4be8 | i: 5 ref: 7 |&lt;BR /&gt;| | | i: 6 ref: 9 |&lt;BR /&gt;| | | i: 7 ref: 9 |&lt;BR /&gt;+-----------------------------------------+-----------------------+---------------------+&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 09:29:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85032#M10437</guid>
      <dc:creator>Supporto_Checkp</dc:creator>
      <dc:date>2020-05-13T09:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85033#M10438</link>
      <description>&lt;P&gt;i've found the solution comparing two debug of the same client after a connection to both sites.&lt;/P&gt;&lt;P&gt;on VSX I had&lt;/P&gt;&lt;DIV&gt;[ 2696 4196][13 May 10:36:11][CONFIG_MANAGER] transport return value Visitor-Mode, because it is Gateway config variable. Scope: site "sitename"&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;[ 2696 4196][13 May 10:36:11][TR_CONN_MANAGER] &amp;nbsp;ConnGetInfo: vpn conn data:&lt;BR /&gt;(&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:gw-ipaddr (x.x.x.x)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:vpnd_ipaddr (x.x.x.x)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:authentication-method (username-password)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:is_saa (false)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:transport (Visitor-Mode)&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;On Physical I had&lt;BR /&gt;[ 2696 4196][13 May 10:36:11][CONFIG_MANAGER] transport return value Automatic ( or auto detect , i dont' have them anymore here with me ) , because it is Gateway config variable. Scope: site "sitename"&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:gw-ipaddr (x.x.x.x)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:vpnd_ipaddr (x.x.x.x)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:authentication-method (username-password)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:is_saa (false)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:transport (Auto-Detect)&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;i've looked both the DB with DBGUIEDIT for some value with "auto-detect" or "visitor-mode" ...and solved &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 13 May 2020 09:28:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85033#M10438</guid>
      <dc:creator>Supporto_Checkp</dc:creator>
      <dc:date>2020-05-13T09:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85036#M10439</link>
      <description>&lt;P&gt;Correct, this is exactly the way described in&amp;nbsp;sk10743. I can only guess why your VSX did not have the default method set up. It is usually the other way around, forcing Visitor Mode, if NAT-T port is closed&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 09:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85036#M10439</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-05-13T09:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85038#M10440</link>
      <description>&lt;P&gt;I don't know why, to be honest.&lt;BR /&gt;I didn't follow the startup of this customer many years ago.&lt;BR /&gt;Maybe the default setting was different on R77 ? or someone changed it for any (wrong) reason ( or maybe the old ISP didn't allow NAT-T port )&amp;nbsp; before we managed the customer&lt;BR /&gt;Pre-Covid19 this wasn't a problem with 100/120 user so nobody had issues.&lt;/P&gt;&lt;P&gt;Problem is solved but&amp;nbsp;I think that an option like this should be on GUI ,and not only on DBGUIEDIT.... like many other interesting option&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 10:02:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/85038#M10440</guid>
      <dc:creator>Supporto_Checkp</dc:creator>
      <dc:date>2020-05-13T10:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/92730#M10441</link>
      <description>&lt;P&gt;It is&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107433&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank"&gt;sk107433: How to change transport method with Endpoint Clients&lt;/A&gt;&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 10:27:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/92730#M10441</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-29T10:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/128110#M10442</link>
      <description>&lt;P&gt;Did you resolve this ? we had the same issue and turned out to be the firewall objects ip we was using was not the one which was published for our vpn user to connect, so what it was doing was hitting another external IP we have on our cluster and using visitor mode always we had to change link selection in our issue to be the external ip users was resovling our VPN host to and now all we get is NAT-T users and a few vistor mode.&lt;/P&gt;&lt;P&gt;CPView shows what they are connected with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check your ip you resolve for vpn is the one that matches the link selection IP.&lt;/P&gt;&lt;P&gt;vistor mode has a massive impact on 700 users or more from what I remember we was fine to around 650 after that we saw issue 15600 cluster R80.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 13:42:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/128110#M10442</guid>
      <dc:creator>frankcar</dc:creator>
      <dc:date>2021-08-26T13:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188427#M10443</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;Is this dangerous behavoir still on going? According to&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk168297" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk168297&lt;/A&gt; it should be fixed&lt;/P&gt;
&lt;P&gt;Is this true also for VSX ?&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 12:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188427#M10443</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-08-02T12:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188428#M10444</link>
      <description>&lt;P&gt;I can't tell you about VSX, we&amp;nbsp; dont use checkpoint vpn they went down the zcrawler zscaler route.&lt;/P&gt;&lt;P&gt;articles says its fixed, vistor mode in user space was the issue if in kernel should be fine then i guess still slow compared to NAT-T&lt;/P&gt;&lt;P&gt;Check Point has developed a new fix to handle Visitor Mode connections in the kernel on the Security Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 12:40:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188428#M10444</guid>
      <dc:creator>frankcar</dc:creator>
      <dc:date>2023-08-02T12:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188430#M10445</link>
      <description>&lt;P&gt;i think your clients are tring to connect to something different from your link selection setting&lt;/P&gt;
&lt;P&gt;the solution is here&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk32229" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk32229&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 12:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188430#M10445</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-08-02T12:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188431#M10446</link>
      <description>&lt;P&gt;the chaps packages our client up in applications using the wrong external IP was our issue to, so link selection changed that for the endpoint and forced it to use the main ip, probably the article you mention may have done same thing for us, we dont use Checkpoint vpn client anymore shame was 100x better than zscaler performance wise.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 12:43:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188431#M10446</guid>
      <dc:creator>frankcar</dc:creator>
      <dc:date>2023-08-02T12:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188432#M10447</link>
      <description>&lt;P&gt;VSX or not, Visitor mode is still the same and handled by vpnd. However, since R80.40, there is a performance enhancement, mentioned in that SK.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What do you call "This dangerous behavior", not sure I follow&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 12:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188432#M10447</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-02T12:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188436#M10448</link>
      <description>&lt;P&gt;This dangerous behavior ? i didn't mention that anywhere i just searched&lt;/P&gt;&lt;P&gt;we had performance issue in user space if its fixed it fixed.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 12:59:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188436#M10448</guid>
      <dc:creator>frankcar</dc:creator>
      <dc:date>2023-08-02T12:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188438#M10449</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;dangerous behavior" I mean the high load overall on the system if large numers of visitor mode are connected&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 13:02:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188438#M10449</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-08-02T13:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188440#M10450</link>
      <description>&lt;P&gt;the only high load i had was manager calling me for it to be fixed because users was struggling to download word documents when we had over 700 on visitor mode but that was in user space, if they moved to kernel must have been resolved as they say.&lt;/P&gt;&lt;P&gt;the vpn core was maxed out too i think from memory&lt;/P&gt;&lt;P&gt;NAT-T is faster than https visitor mode we found, i am not sure if visitor mode is capable of doing the same speeds as NAT-T.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 13:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188440#M10450</guid>
      <dc:creator>frankcar</dc:creator>
      <dc:date>2023-08-02T13:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188457#M10451</link>
      <description>&lt;P&gt;Visitor mode is not accelerated and treated in the User Mode by a process. By definition, it is not the most performant RAS VPn solution. For a large deployment, I would recommend the classic IPsec based VPN.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 14:18:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188457#M10451</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-02T14:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: All Remote User use Visitor Mode ( Endpoint Connect VPN )</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188458#M10452</link>
      <description>&lt;P&gt;according to&amp;nbsp;sk168297 this is no longer true&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 14:20:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/All-Remote-User-use-Visitor-Mode-Endpoint-Connect-VPN/m-p/188458#M10452</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-08-02T14:20:28Z</dc:date>
    </item>
  </channel>
</rss>

