Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sal_Previtera
Contributor
Jump to solution

VPN remote access licenses.

 

R81.10 HFA 83 

I do not seem to be able to get a correct answer on what is, the license on our FW mgmt or Firewall gateway cluster required for VPN remote access on Premises.

To clarify, these are NOT Endpoints managed by Endpoint management server ...but Capsule, IPSEC vpn, etc.

Any idea of license name I should look for?

Thanks,

 

 

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

If you're just looking for basic remote access with Office Mode support, get a Mobile Access Blade license for the number of concurrent users you expect to connect concurrently.
MAB licenses are sold in 50, 200, or Unlimited packs.
You don't have to enable Mobile Access Blade or otherwise change your existing configuration.
However, each gateway users will connect to need a MAB license.

Note that MAB does NOT offer Endpoint Firewall or Compliance features (except for SCV).
Your existing Endpoint licenses will probably work for that.

View solution in original post

0 Kudos
7 Replies
Chris_Atkinson
Employee Employee
Employee

Capsule typically is Mobile Access, however please refer sk67820 for a detailed answer based on the specific VPN client choice.

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

The following tool will help identify how many users (of what type) are licensed in your installation: https://community.checkpoint.com/t5/Scripts/Easy-Mobile-User-License-Tool-Replaces-quot-dtps-lic-quo...

0 Kudos
Danny
Champion Champion
Champion

Additionally you can verify your current licenses with this tool as recommended in sk166032.

Sal_Previtera
Contributor

Thank you, Danny and Phoneboy....

The enterprise where I work, has decide not to use the full-blown CP ENDPOINT(s) , just CP remote access VPN...

(Please, do not ask me why...LOL).

Would the VPN use the Secure-Remote licenses instead of Endpoint Connect licenses?

Thanks...

REMOTE ACCESS VPN STATS - Current
----------------------------------------------------------------------
Assigned OfficeMode IPs : 198 (Peak: 453)
Capsule/Endpoint VPN Users : 197 (Peak: 455) using Visitor Mode: 2
Capsule Workspace Users : 0 (Peak: 0)
MAB Portal Users : 0 (Peak: 0)
L2TP Users : 0 (Peak: 0)
SNX Users : 0 (Peak: 0)

LICENSES
----------------------------------------------------------------------
SecuRemote Users : 30000
Endpoint Connect Users : 1350
Mobile Access Users : 10
SNX Users :

0 Kudos
PhoneBoy
Admin
Admin

If users were using SecuRemote, they would not show up under "Assigned Office Mode" or "Capsule/Endpoint VPN Users" as SecuRemote does NOT support Office Mode.
Which means you clearly have the required licenses necessary for Remote Access.
To confirm exactly what kind of licenses you have, please provide a cplic print from your gateway.

0 Kudos
Sal_Previtera
Contributor

CPAP-SG2350X CPSB-FW CPSM-C-2 CPSB-VPN CPSB-NPM CPSB-LOGS CPSB-IA CPSB-SSLVPN-5 CPSB-ADNC CPSB-IPS CPSB-URLF CPSB-APCL CPSB-AV CPSB-ABOT-L CPSB-DLP CPSB-ASPM CPSB-CTNT

If I understand you correctly, since Secureremote  does not support OFFICE Mode, then we still need to carry over ENDPOINT license that we currently have 1350...maybe a lot less, since out peek was less 500..to be able to use Office Mode. Thanks

LICENSES
----------------------------------------------------------------------
SecuRemote Users : 30000
Endpoint Connect Users : 1350
Mobile Access Users : 10
SNX Users :

0 Kudos
PhoneBoy
Admin
Admin

If you're just looking for basic remote access with Office Mode support, get a Mobile Access Blade license for the number of concurrent users you expect to connect concurrently.
MAB licenses are sold in 50, 200, or Unlimited packs.
You don't have to enable Mobile Access Blade or otherwise change your existing configuration.
However, each gateway users will connect to need a MAB license.

Note that MAB does NOT offer Endpoint Firewall or Compliance features (except for SCV).
Your existing Endpoint licenses will probably work for that.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events