- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello, Team,
I hope you can help me to clarify the doubt.
To work with the Remote Access VPN solution, in your experience, is it better to work it using the Mobil Access blade? Because I know that you can also have this solution, activating only the IPsec VPN Blade. So, could we say that the decision of which blade to work with depends on the Firewall administrator?
I have an equipment in Standalone deployment, which has 2 active blades, both the IPsec VPN blade and the Mobile Access blade, but it is difficult for me to "know" which blade is the one that is "working" for the connection of the remote users of the VPN.
Thank you for your support.
Remote Access VPN can be “served” either by IPsec VPN or Mobile Access Blade being enabled.
The logging is somewhat ambiguous at times because they’re using the same infrastructure underneath for this function.
My opinion: unless you need the web-based portal of Mobile Access Blade, which would include the use of SNX portal, use IPsec VPN.
The license/blade requirements depend on the type of client to be used, please refer:
sk67820: Check Point Remote Access Solutions - Gateway-Based Access
Remote Access VPN can be “served” either by IPsec VPN or Mobile Access Blade being enabled.
The logging is somewhat ambiguous at times because they’re using the same infrastructure underneath for this function.
My opinion: unless you need the web-based portal of Mobile Access Blade, which would include the use of SNX portal, use IPsec VPN.
Thanks for the feedback.
As far as I remember, and according to the SK that was shared with me in this forum, using for example the "Endpoint Security VPN" agent, only works with the IPsec VPN blade, am I correct?
I understand that when you use this agent, the "negotiation" by default in Checkpoint is using the certificate that by default is in the "community" of "RemoteAccess" (all this, to achieve to lift the tunnel), to avoid that the connections of the users "are complex" for them.
Is my point of view correct?
It seems that the environment I have, use both blades, because according to what I have inquired with the client, many users also use the Capsule VPN on their phones and mobiles (Android), and according to the SK, I understand that this application "depends" on the Mobile Access blade.
There may be some minor differences in how you configure Remote Access when doing MAB “exclusively” (without IPsec VPN enabled), but Endpoint Security VPN should work with it.
You are correct that the Capsule VPN clients require MAB, this is documented here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Buddy.
So in your experience, the "Endpoint Security VPN" agent can work, if I only have the Mobile Access blade active?
Greetings.
You simply need VPN blade enabled to run base endpoint vpn client.
If you want to control the Firewall and Endpoint Compliance features of Endpoint Security VPN, that requires IPsec VPN.
Otherwise, Mobile Access Blade can be used.
To clarify these are only the Gateway side license requirements.
It would be remiss of us not to mention (again) that specific clients require seat licenses applied to the Management server e.g. CPEP-ACCESS-XX
In my experience, most people would stick with ipsec VPN blade, and use mobile access for their mobile users (you connect with app from your smart phone).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY