- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello, Team,
I hope you can help me to clarify the doubt.
To work with the Remote Access VPN solution, in your experience, is it better to work it using the Mobil Access blade? Because I know that you can also have this solution, activating only the IPsec VPN Blade. So, could we say that the decision of which blade to work with depends on the Firewall administrator?
I have an equipment in Standalone deployment, which has 2 active blades, both the IPsec VPN blade and the Mobile Access blade, but it is difficult for me to "know" which blade is the one that is "working" for the connection of the remote users of the VPN.
Thank you for your support.
Remote Access VPN can be “served” either by IPsec VPN or Mobile Access Blade being enabled.
The logging is somewhat ambiguous at times because they’re using the same infrastructure underneath for this function.
My opinion: unless you need the web-based portal of Mobile Access Blade, which would include the use of SNX portal, use IPsec VPN.
The license/blade requirements depend on the type of client to be used, please refer:
sk67820: Check Point Remote Access Solutions - Gateway-Based Access
Remote Access VPN can be “served” either by IPsec VPN or Mobile Access Blade being enabled.
The logging is somewhat ambiguous at times because they’re using the same infrastructure underneath for this function.
My opinion: unless you need the web-based portal of Mobile Access Blade, which would include the use of SNX portal, use IPsec VPN.
Thanks for the feedback.
As far as I remember, and according to the SK that was shared with me in this forum, using for example the "Endpoint Security VPN" agent, only works with the IPsec VPN blade, am I correct?
I understand that when you use this agent, the "negotiation" by default in Checkpoint is using the certificate that by default is in the "community" of "RemoteAccess" (all this, to achieve to lift the tunnel), to avoid that the connections of the users "are complex" for them.
Is my point of view correct?
It seems that the environment I have, use both blades, because according to what I have inquired with the client, many users also use the Capsule VPN on their phones and mobiles (Android), and according to the SK, I understand that this application "depends" on the Mobile Access blade.
There may be some minor differences in how you configure Remote Access when doing MAB “exclusively” (without IPsec VPN enabled), but Endpoint Security VPN should work with it.
You are correct that the Capsule VPN clients require MAB, this is documented here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Buddy.
So in your experience, the "Endpoint Security VPN" agent can work, if I only have the Mobile Access blade active?
Greetings.
You simply need VPN blade enabled to run base endpoint vpn client.
If you want to control the Firewall and Endpoint Compliance features of Endpoint Security VPN, that requires IPsec VPN.
Otherwise, Mobile Access Blade can be used.
To clarify these are only the Gateway side license requirements.
It would be remiss of us not to mention (again) that specific clients require seat licenses applied to the Management server e.g. CPEP-ACCESS-XX
In my experience, most people would stick with ipsec VPN blade, and use mobile access for their mobile users (you connect with app from your smart phone).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY