- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
We are trying to setup the Microsoft Always on VPN with our Checkpoint 6200 running R80.40. In our research we have found there are two ways to connect the remote devices with the 6200 and that is:
1. User based
2. Machine based
The user based uses the Checkpoint Capsule plugin from the Microsoft store and some configuration on the machine side but beyond that it should "just work" from what we are told. The drawback on this is no connection to the device if the user is not logged in so no automatic updates and such.
The machine based is certificate based but I cannot find if it requires anything beyond the 6200 to be configured. The drawback on this is it uses IKEv2 which is blocked by some firewalls. The advantage for this is if it is powered on and has a network connection it is connected to the home base so we can manage the device as if it was on our network.
With all that said, can anyone point me in the direction of some tutorials or guides on setting this up? I would prefer to get the machine based certificates going but if I can get a good walkthrough on setting up the user based side I will take it.
What I gather from your message is that you'd like both machine and user-based authentication.
For that, you have to use our Endpoint VPN client, not the Capsule one from the Microsoft Store.
That's mentioned here: https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/C...
The guide for Capsule VPN can be found here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
This client only supports one method of authentication, as far as I know, not multiple as the Endpoint VPN client does.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY