Check Point Capsule
This VPN connection type is supported on iOS, macOS, and Windows devices only. It is not supported on Android devices
Use the following guidelines to configure the Check Point Capsule VPN connection type:
Within these selections, you may make settings for:
Proxy - None (default)
Use the following guidelines to configure a Check Point Capsule VPN without a proxy.
Item |
Description |
|||||||||
Name |
Enter a short phrase that identifies this VPN setting. |
|||||||||
Description |
Provide a description that clarifies the purpose of these settings. |
|||||||||
Channel |
For macOS only. Select one of the following distribution options:
|
|||||||||
Connection Type |
Select Check Point Capsule. |
|||||||||
Server |
Enter the IP address, hostname, or URL for the VPN server. |
|||||||||
Proxy |
None is the default setting. To configure a Manual or Automatic proxy, go to Proxy - Manual or Proxy - Automatic. |
|||||||||
Username |
Specify the user name to use. The default value is $USERID$. Use this field to specify an alternate format, such as: $USERID$, $EMAIL$, $SAM_ACCOUNT_NAME$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$ You can use combinations such as the following:
Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant username.
|
|||||||||
User Authentication |
Select the user authentication to use:
If you select Certificate, and extended authentication (EAP) is not used, this certificate will be sent out for IKE client authentication. If extended authentication is used, this certificate can be used for EAP-TLS. |
|||||||||
Specify the password to use (required.) The default value is $PASSWORD$. Include at least one of the following variables: $USERID$, $EMAIL$, $PASSWORD$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$ You can use combinations such as $EMAIL$:$PASSWORD$ Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant password. |
||||||||||
Send All Traffic |
Select to send all traffic from the Windows device through the VPN gateway. When Send All Traffic is checked, all traffic is sent through the VPN gateway with the exception of traffic from the resources you enter in this table. When Send All Traffic is unchecked, only traffic from the resources you enter in this table is sent through the VPN gateway. |
Continue to Windows Configuration.
Continue to Custom Data.
Proxy - Manual
If you select Manual, you must specify the proxy server, port number. and proxy domain information.
Item |
Description |
|||||||||
Name |
Enter a short phrase that identifies this VPN setting. |
|||||||||
Description |
Provide a description that clarifies the purpose of these settings. |
|||||||||
Channel |
For macOS only. Select one of the following distribution options:
|
|||||||||
Connection Type |
Select Check Point Capsule. |
|||||||||
Server |
Enter the IP address, hostname, or URL for the VPN server. |
|||||||||
Proxy |
Select Manual. For an Automatic proxy, see Proxy - Automatic. |
|||||||||
Enter the name for the proxy server. |
||||||||||
Enter the port number for the proxy server. Type - Select Static or Variable for the type of authentication to be used for the proxy server. |
||||||||||
Type |
Select Manual proxy to see this option. Select Static or Variable. |
|||||||||
Proxy Server User Name |
If the authentication type is Static, enter the user name for the proxy server. If the authentication type is Variable, the default variable selected is $USERID$. |
|||||||||
Proxy Server Password |
If the authentication type is Static, enter the password for the proxy server. Confirm the password in the field below. If the authentication type is Variable, the default variable selected is $PASSWORD$. |
|||||||||
|
||||||||||
Username |
Specify the user name to use. The default value is $USERID$. Use this field to specify an alternate format, such as: $USERID$, $EMAIL$, $SAM_ACCOUNT_NAME$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$ You can use combinations such as the following:
Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant username.
|
|||||||||
User Authentication |
Select the user authentication to use:
If you select Certificate, and extended authentication (EAP) is not used, this certificate will be sent out for IKE client authentication. If extended authentication is used, this certificate can be used for EAP-TLS. |
|||||||||
Password |
Specify the password to use (required.) The default value is $PASSWORD$. Include at least one of the following variables: $USERID$, $EMAIL$, $PASSWORD$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$ You can use combinations such as $EMAIL$:$PASSWORD$ Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant password. |
|||||||||
Send All Traffic |
Select to send all traffic from the Windows device through the VPN gateway. When Send All Traffic is checked, all traffic is sent through the VPN gateway with the exception of traffic from the resources you enter in this table. When Send All Traffic is unchecked, only traffic from the resources you enter in this table is sent through the VPN gateway. |
Continue to Windows Configuration.
Continue to Custom Data.
Proxy - Automatic
If you selected an Automatic proxy, you must specify the proxy server URL and proxy domain(s).
WARNING: | For Windows 10 devices, please add the configuration and value for automatic proxy in the Custom Data Grid. Automatic proxy is not supported in Windows 8.1. |
Item |
Description |
||||||
Name |
Enter a short phrase that identifies this VPN setting. |
||||||
Description |
Provide a description that clarifies the purpose of these settings. |
||||||
Channel |
For macOS only. Select one of the following distribution options:
|
||||||
Connection Type |
Select Check Point Capsule. |
||||||
Server |
Enter the IP address, hostname, or URL for the VPN server. |
||||||
Proxy |
Select Automatic. For a manual proxy, see Proxy - Manual |
||||||
Enter the URL for the proxy server. Enter the URL of the location of the proxy auto-configuration file. |
|||||||
|
|||||||
Username |
Specify the user name to use (required.) The default value is $USERID$. Include at least one of the following variables: $USERID$, $EMAIL$, $SAM_ACCOUNT_NAME$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$ You can use combinations such as the following:
Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant username. |
||||||
User Authentication |
Select the user authentication to use:
If you select Certificate, and extended authentication (EAP) is not used, this certificate will be sent out for IKE client authentication. If extended authentication is used, this certificate can be used for EAP-TLS. |
||||||
Specify the password to use (required.) The default value is $PASSWORD$. Include at least one of the following variables: $USERID$, $EMAIL$, $PASSWORD$, $USER_CUSTOM1$, $USER_CUSTOM2$, $USER_CUSTOM3$, $USER_CUSTOM4$, $CUSTOM_DEVICE_Attributename$, $CUSTOM_USER_Attributename$, $NULL$ You can use combinations such as $EMAIL$:$PASSWORD$ Enter $NULL$ if you want the field presented to the user to be blank. Users will need to fill in the relevant password. |
|||||||
Send All Traffic |
Select to send all traffic from the Windows device through the VPN gateway. When Send All Traffic is checked, all traffic is sent through the VPN gateway with the exception of traffic from the resources you enter in this table. When Send All Traffic is unchecked, only traffic from the resources you enter in this table is sent through the VPN gateway. |
Continue to Windows Configuration.
Continue to Custom Data.
Windows Configuration
Allowed Secured Resources (Windows Phone only)
Excluded Secured Resources (Windows Phone only)
See Application-triggered VPN for Windows devices for information on how to configure these settings to set up application-triggered VPN for 8.0.1 devices.
Item |
Description |
Windows Configuration |
Enter the secured resources (domains, IP ranges, or apps) used by the Send All Traffic option. |
Always On |
Select this option to keep the VPN on. Lock Down supersedes this option for Windows devices. |
Lock Down |
You cannot change the assigned settings unless 1) the Lock Down setting is removed from the profile and the new profile is pushed to the device or 2) the device is un-enrolled from Core. This option supersedes the Always On option. |
Custom Data
- Add+ - Click to add a new key / value pair.
- Key / Value - Enter the Key / value pairs necessary to configure the VPN setting. The app creator should provide the necessary key / value pairs.