Hi all,
I've been struggling to find an answer to the following two questions, so hoping someone here might be able to help. I also think some of us might also have the same questions.
---
First, the easy question. As I understand it both Endpoint Security VPN and Mobile for Windows are IPSec clients that can wrap the communication to the gateway in HTTPS (aka visitor mode). Am I right in assuming that this is simply a case of IPSec over port 443 and there is no SSL involved? I am trying to work out if adding, for example, 200 extra VPN client users will have a big effect of gateway performance. If they are simple IPsec tunnels then no, but if they each need to be SSL decrypted, then that is more of an impact.
---
Second, the harder question. Imagine I have an existing deployment of Endpoint Security VPN with appropriate endpoint container licensing for VPN and FW and that I have enough licensing for 50 VPN users. Due to the COVID-19 situation I want to use the  Check Point's 60-day MAB license offer for an additional 200 remote users. I understand that these extra users won't have the client FW capability as it's not part of the MAB license. Let's assume that I have obtained the 200 MAB user license from Check Point and added it.
1) Can I deploy the Endpoint Security VPN client to ALL users. I understand users connecting under MAB licensing will not get the endpoint FW capability, but I would like to keep things simple by only having a single client type deployed.
2) I now have two two remote access VPN license schemes installed (50 Endpoint containers and 200 MAB licenses). When a remote VPN user connects, which license scheme is used first? This is important as it will dictate whether the user gets the endpoint FW or not. 
1) When enough remote users connect to exhaust one licensing scheme, will it automatically start using the next licensing scheme?  For example, if the endpoint container scheme is used first, when the 51st user connects will it automatically see this as a MAB license?   
Thanks,
Dave