<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access Users license + count in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/39181#M13945</link>
    <description>&lt;P&gt;I have already used the following lines in a reply, but now decided to make it a document &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;.&lt;/P&gt;
&lt;P&gt;The "old" RA VPN client licensing worked by counting client IPs (called "seats", CLI "&lt;EM&gt;dtps lic&lt;/EM&gt;" on policy server), and the used licenses count showed the number of clients that did connect during the last 30 days. This is different with MAB licenses, they are defined as the number of concurrent clients; MAB even has five grace clients, so the maximum number of concurrent clients is the number of licenses plus five.&lt;/P&gt;
&lt;P&gt;Still, you can use the “Client type” filter on SVMonitor&amp;gt;User&amp;gt;All users, in order to filter according the type of the connection of the users. But there is no "&lt;EM&gt;dtps lic&lt;/EM&gt;" for new endpoint client, MAB has its own CLI command, see &lt;EM&gt;Mobile Access Administration Guide R77 Versions pp. 188&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;listusers&lt;/EM&gt; - Shows a list of end-users connected to the gateway, along with their source IP addresses.&lt;/P&gt;
&lt;P&gt;But that is not all as we can even take a look into the kernel tables &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;:&lt;/P&gt;
&lt;P&gt;From &lt;EM&gt;&lt;A style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39034&amp;amp;partition=General&amp;amp;product=IPSec" target="_blank"&gt;sk39034: How to check the number of currently connected Remote Access users &lt;/A&gt;&lt;/EM&gt;and &lt;EM&gt;&lt;A style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk14496&amp;amp;partition=General&amp;amp;product=IPSec" target="_blank"&gt;sk14496: How to check the names of remote access users that have sent traffic through the Security Gateway in the last 15 minutes:&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;To see the number of currently connected Remote Access users, run this command (in Expert mode) on the VPN Security Gateway:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[Expert@HostName]# fw tab -t userc_users -s&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;To see the username of each "connected" remote access user (in the last 15 minutes), run this command (in Expert mode) on VPN Security Gateway:&lt;/P&gt;
&lt;P&gt;[Expert@HostName]# fw tab -t userc_rules -f&lt;/P&gt;
&lt;P&gt;You can also run the following command on the gateway, in order to see the number of OM IPs which are currently assigned by the gateway:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# fw tab -t om_assigned_ips -s&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;HOST NAME ID #VALS #PEAK #SLINKS localhost om_assigned_ips 372 1 1 0&lt;/P&gt;
&lt;P&gt;The above output (#VALS=1 ) means currently one client is assigned an OM IP. This includes SNX users with OM IPs as well, who take up from a different license (MAB). In order to find out how many there are of those and subtract them to leave only IPsec VPN clients (i.e. SecureClient, Endpoint Security VPN, Endpoint Connect), check the following table:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# fw tab -t sslt_om_ip_params -s&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;HOST NAME ID #VALS #PEAK #SLINKS localhost sslt_om_ip_params 372 1 1 0&lt;/P&gt;</description>
    <pubDate>Wed, 21 Aug 2019 07:23:33 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-08-21T07:23:33Z</dc:date>
    <item>
      <title>Remote Access Users license + count</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/39181#M13945</link>
      <description>&lt;P&gt;I have already used the following lines in a reply, but now decided to make it a document &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;.&lt;/P&gt;
&lt;P&gt;The "old" RA VPN client licensing worked by counting client IPs (called "seats", CLI "&lt;EM&gt;dtps lic&lt;/EM&gt;" on policy server), and the used licenses count showed the number of clients that did connect during the last 30 days. This is different with MAB licenses, they are defined as the number of concurrent clients; MAB even has five grace clients, so the maximum number of concurrent clients is the number of licenses plus five.&lt;/P&gt;
&lt;P&gt;Still, you can use the “Client type” filter on SVMonitor&amp;gt;User&amp;gt;All users, in order to filter according the type of the connection of the users. But there is no "&lt;EM&gt;dtps lic&lt;/EM&gt;" for new endpoint client, MAB has its own CLI command, see &lt;EM&gt;Mobile Access Administration Guide R77 Versions pp. 188&lt;/EM&gt;:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;listusers&lt;/EM&gt; - Shows a list of end-users connected to the gateway, along with their source IP addresses.&lt;/P&gt;
&lt;P&gt;But that is not all as we can even take a look into the kernel tables &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;:&lt;/P&gt;
&lt;P&gt;From &lt;EM&gt;&lt;A style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk39034&amp;amp;partition=General&amp;amp;product=IPSec" target="_blank"&gt;sk39034: How to check the number of currently connected Remote Access users &lt;/A&gt;&lt;/EM&gt;and &lt;EM&gt;&lt;A style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk14496&amp;amp;partition=General&amp;amp;product=IPSec" target="_blank"&gt;sk14496: How to check the names of remote access users that have sent traffic through the Security Gateway in the last 15 minutes:&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;To see the number of currently connected Remote Access users, run this command (in Expert mode) on the VPN Security Gateway:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[Expert@HostName]# fw tab -t userc_users -s&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;To see the username of each "connected" remote access user (in the last 15 minutes), run this command (in Expert mode) on VPN Security Gateway:&lt;/P&gt;
&lt;P&gt;[Expert@HostName]# fw tab -t userc_rules -f&lt;/P&gt;
&lt;P&gt;You can also run the following command on the gateway, in order to see the number of OM IPs which are currently assigned by the gateway:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# fw tab -t om_assigned_ips -s&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;HOST NAME ID #VALS #PEAK #SLINKS localhost om_assigned_ips 372 1 1 0&lt;/P&gt;
&lt;P&gt;The above output (#VALS=1 ) means currently one client is assigned an OM IP. This includes SNX users with OM IPs as well, who take up from a different license (MAB). In order to find out how many there are of those and subtract them to leave only IPsec VPN clients (i.e. SecureClient, Endpoint Security VPN, Endpoint Connect), check the following table:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# fw tab -t sslt_om_ip_params -s&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;HOST NAME ID #VALS #PEAK #SLINKS localhost sslt_om_ip_params 372 1 1 0&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2019 07:23:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/39181#M13945</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-08-21T07:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Users license + count</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/39182#M13946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gunther,&lt;/P&gt;&lt;P&gt;When we are runing Provider-1 with multiple CMAs, the remote access license gets placed on at MDS level.&lt;/P&gt;&lt;P&gt;Are there any known commands for checking the overall usage of remote access on the entire management server , or would we have to review each CMA for the max number of connections to work out if our license was sufficient.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Aug 2018 10:36:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/39182#M13946</guid>
      <dc:creator>Peter_Lyndley</dc:creator>
      <dc:date>2018-08-13T10:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Users license + count</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/39183#M13947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The old "&lt;EM&gt;dtps lic&lt;/EM&gt;" was issued on the policy server, and the new commands are all gateway-specific - so i get information for the gateway only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Aug 2018 14:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/39183#M13947</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-13T14:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Users license + count</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/77792#M13948</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;What that's mean number of seat ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 25, is this mean 25 connection VPN&amp;nbsp;&lt;SPAN&gt;simultaneously?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;What is the command cli to show me how much licence i have for VPN endpoind (not mobile) but for laptop?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 22:41:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/77792#M13948</guid>
      <dc:creator>Kimi</dc:creator>
      <dc:date>2020-03-09T22:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Users license + count</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/79144#M13949</link>
      <description>&lt;P&gt;&lt;SPAN&gt;In the past days I have been working on a CLI script that can display all Secure Client license information centrally. This script creates a new command on the management server to read the Secure Client licenses. It displays all Secure Client licenses in total (sum). Furthermore, it can read out the currently used licenses on the gateway. If a connection to the gateway can be established, the following values are read out: Currently used Secure Client licenses and the maximum used Secure Client licenses.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you execute the script via "copy and past" on the management server, a new CLI command "sclic" is created. Afterwards you can use this command to display all licenses in an overview. Please note that the execution of the new command may take a few seconds. This is a normal behaviour.&lt;BR /&gt;&lt;BR /&gt;Now for following:&lt;BR /&gt;- Secure Client licenses&lt;BR /&gt;- Mobile Access Portal licenses&lt;BR /&gt;- SSLVPN licenses&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;More read here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Secure-Client-License-Counter-Overview-replaces-quot-dtps/m-p/78974#M16069" target="_self"&gt;R80.x - Mobile User License Tool - replaces "dtps lic"&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Here an example:&lt;BR /&gt;#&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;sclic 10.0.0.1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Now all license parameters for Secure Client are displayed:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SC_Bild7.JPG" style="width: 845px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4990i62BD921223DD80A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="SC_Bild7.JPG" alt="SC_Bild7.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2020 19:28:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/79144#M13949</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-21T19:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Users license + count</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/82918#M13950</link>
      <description>&lt;P&gt;Thank you very much for your post&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt; i m using it and very helpful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 12:42:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Users-license-count/m-p/82918#M13950</guid>
      <dc:creator>Kimi</dc:creator>
      <dc:date>2020-04-23T12:42:56Z</dc:date>
    </item>
  </channel>
</rss>

