Check Point NG Licensing Guide
|
Product
Description |
SKU
prefix |
Is
licensing additive1? |
Number of strings
generated by User Center |
License applied
to
|
Additional
licenses required for gateway or management
HA2
implementations | |||||
|
SmartCenters | ||||||||||
|
SmartCenter Pro -
Centralized
management of policies which can be deployed to an unlimited number of
Check Point clustered gateways, each protecting an unlimited number of
nodes |
CPMP-SCP |
No |
1 |
Management
station |
Management
HA: ·
SmartCenterPro licenses as
required | |||||
|
SmartCenter
-
Centralized
management of policies that can be deployed to an unlimited number of
Check Point clustered gateways, each protecting an unlimited number of
nodes.
|
CPMP-SCT |
No |
1 |
Management
station |
Management
HA: ·
SmartCenters licenses as
required ·
1
MGM-HA Or ·
Upgrade to Smart Center to
SmartCenter Pro. ·
Add SmartCenter Pro as
required | |||||
|
SmartCenter -
Centralized
management of policies that are deployed to a single Check Point gateway.
|
CPMP-SMC |
No |
1 |
Management
station |
Management
HA: ·
SmartCenters as
required ·
1
MGM-HA Or ·
Upgrade to Smart Center to
SmartCenter Pro. ·
Add SmartCenter Pro as
required | |||||
|
SmartDefense | ||||||||||
|
SmartDefense
Subscription for Annual Security Updates - Provides a
single, centralized console delivering real-time information on attacks as
well as attack detection, blocking, logging, auditing and alerting.
SmartDefense actively protects organizations from network attacks using
intelligent security technology. |
SU-SMRD |
Yes |
1 |
The enforcement
point |
·
Additional Subscription
Contracts (licenses) as required | |||||
|
Enterprise
Bundles of Gateways plus SmartCenter or SmartCenter
Pro | ||||||||||
|
FireWall-1 Enterprise
Center - FireWall-1
unlimited gateway and SmartCenter for an unlimited number or security
enforcement points. |
CPVP-EPC |
No |
2 |
Distributed Applied
to the respective machines Standalone Applied
to the management |
Management
HA: ·
SmartCenters as
required ·
1
Management HA Gateway
HA: ·
1
ClusterXL ·
FireWall-1 Gateways as
required | |||||
|
VPN-1 Enterprise
Center - VPN-1 Pro
unlimited gateway and SmartCenter for an unlimited number or security
enforcement points. |
CPVP-VEE |
No |
2 |
Distributed Applied
to the respective machines Standalone Applied
to the management |
Management
HA: ·
1
Management HA ·
SmartCenters as
required For Gateway
HA ·
1
ClusterXL ·
VPN-1 Pro Gateways as
required | |||||
|
SVN Smart Enterprise
Bundle - VPN-1 Pro
and FloodGate-1 unlimited gateway and SmartCenter Pro for an unlimited
number or security enforcement points. |
CPVP-VFE |
No |
2 |
Distributed Applied
to the respective machines Standalone Applied
to the management |
Management
HA: ·
SmartCenter Pro as
required For Gateway
HA: ·
1
ClusterXL ·
SVN Gateways as
required | |||||
|
Security
Gateways | ||||||||||
|
FireWall-1 Module
FireWall-1
security enforcement point that protects a specified number of IP
addresses. |
CPFW-FM |
No |
1 |
The enforcement
point |
In
NG: For Gateway
HA: ·
1
ClusterXL ·
FireWall-1 Gateways as
required In
V41: ·
1
HA-DUAL ·
FireWall-1 Gateways as
required ·
HA-ADDL for every additional
gateway after the second one. | |||||
|
VPN-1 Pro
VPN-1 Pro
enforcement point that protects a specified number of IP
addresses. |
CPFW-VFM |
No |
1 |
The enforcement
point |
In
NG: For Gateway
HA: ·
1
ClusterXL ·
VPN-1 Pro Gateways as
required In
V41: ·
1
HA-DUAL ·
VPN-1 Pro Gateways as
required ·
HA-ADDL for every additional
gateway after the second one. | |||||
|
VPN-1 &
FloodGate-1 Module - VPN-1 Pro
& FloodGate-1 Modules that protect a specified number of IP
addresses. |
CPMP-VFF |
No |
1 |
The enforcement
point |
In
NG: For Gateway
HA: ·
1
ClusterXL ·
SVN Gateways as
required In
V41: ·
1
HA-DUAL ·
SVN Gateways as
required ·
HA-ADDL for every additional
gateway after the second one. | |||||
|
Bundles of
Security Gateway plus SmartCenter | ||||||||||
|
FireWall-1 Internet
Gateway - FireWall-1
gateway and SmartCenter for a single security enforcement point that
protects a specified number of IP addresses |
CPFW-FIG |
No |
1 |
A single machine that
serves both as the management station and as the enforcement
point. |
An HA configuration is
not available for this product | |||||
|
VPN-1 Internet Gateway
- VPN-1 Pro and
SmartCenter for a single security enforcement point that protects a
specified number of IP addresses |
CPVP-VIG |
No |
1 |
A single machine that
serves both as the management station and as the enforcement
point. |
An HA configuration is
not available for this product | |||||
|
VPN-1 &
FloodGate-1 Internet Gateway - VPN-1 Pro
& FloodGate-1 Modules plus SmartCenter for a single security
enforcement point that protects a specified number of IP
addresses |
CPMP-VFG |
No |
1 |
A single machine that
serves both as the management station and as the enforcement
point. |
An HA configuration is
not available for this product | |||||
|
Virtual Systems
Extension (VSX) | ||||||||||
|
VSX - Enforces VPN-1
and FireWall-1 security policies for up to 100 discrete customers on a
single machine. |
CPVP-VSX |
Yes |
1 |
The enforcement
point. |
For Gateway
HA: ·
1
ClusterXL ·
VSX Gateways as
required | |||||
|
High Availability
Security Gateways | ||||||||||
|
FireWall-1 Module
High Availability Bundle - Two
FireWall-1 gateways for High Availability
implementations |
CPFW-HFM |
No |
2 |
Two
gateways |
For Gateway
HA: ·
1
ClusterXL ·
Additional FireWall-1 Gateways
as required | |||||
|
VPN-1 Module High
Availability Bundle - Two VPN-1
gateways for High Availability implementations |
CPVP-HVM |
No |
2 |
Two
gateways |
For Gateway
HA: ·
1
ClusterXL ·
Additional VPN-1 Pro Gateways
as required | |||||
|
VPN-1 &
FloodGate-1 Module High Availability Bundle - Two VPN-1 Pro
and FloodGate-1 gateways for High Availability implementations |
CPMP-HVG |
No |
2 |
Two
gateways |
For Gateway HA:
·
1
ClusterXL ·
Additional SVN Gateways as
required | |||||
|
SmallOffice
Gateways | ||||||||||
|
VPN-1/FireWall-1
SmallOffice - FireWall-1
or VPN-1 SmallOffice Module that protects a specified number of IP
addresses. |
CPVP-VSO, CPFW-FSO |
No |
1, when a SmartCenter manages
the enforcement point from remote or when managed by the Web User
Interface. |
When managed by a SmartCenter from the
Enterprise or locally by a Web User Interface, only the module license
should be applied to its machine. When managed locally, each license
should be applied to its respective machine |
·
Not available
| |||||
|
VPN-1
Net | ||||||||||
|
VPN-1 Net - Provides a
complete Virtual Private Network gateway solution, and contains all
NG-based VPN features. Licensed by number of concurrent VPN
tunnels. |
CPVP-VNT |
Yes |
1 |
Encrypting machine
that can be either locally managed or managed from a SmartCenter
management for a stand-alone box |
·
Not
available | |||||
|
Client
Licenses | ||||||||||
|
VPN-1 SecureClient
-
Network security protection, consisting of access controls and security
configuration verification, for client desktops. |
CPVP-VSC |
Yes |
1 |
The management
station. |
In
NG: Management
HA: ·
VSC license on every management
station in the cluster For Gateway
HA: ·
No additional license is
required. In
V41: For Management HA:
·
Not
available For Gateway HA:
A VSC license is
required on every gateway in the cluster | |||||
|
VPN-1 SecuRemote
-
Transparently encrypts and authenticates critical data from mobile clients
to protect against eavesdropping and malicious data tampering. Note:
Product is provided at no charge but must be ordered and licensed to
obtain functionality. |
CPVP-VSR |
No |
1 |
Applied to where the topology server resides |
In
NG: For Management HA:
·
1
VSR on the management station Gateway
HA: ·
Additional VSR on the gateway
or on the management In
V41: For Management HA:
·
Not available
Gateway
HA: ·
Additional VSR on the gateway
or on the management | |||||
|
VPN-1 Client for
Macintosh - Provides
secure VPN access for Macintosh |
CPVP-VMC |
No |
1 |
Applied to where the topology server resides |
For Management HA:
·
1
VMC on the management station Gateway
HA: ·
1
VSR on the gateway | |||||
|
UserAuthority User
License - Provides
Authentication and Authorization (WebAccess) services for LAN and REMOTE
users using SR/SC, Windows Clients, Browsers (incl. SSL). |
CPUA-UAU |
Yes |
1 |
Applied to the
Management Station |
NG
FP0/FP1: For Management HA:
·
1
UAS on the management station ·
1
UAU on the management station NG FP2 and
higher: For Management HA:
·
1
UAU | |||||
|
Management Tools,
Reporting and Monitoring Modules and Gateway
Add-ons | ||||||||||
|
Motif GUI - GUI
for Solaris for Management Consoles or gateway bundles |
CPMP-MOTIF |
No |
1 |
The Management
Station |
For Management
HA: ·
MOTIF for every management
station in the cluster | |||||
|
SmartView Monitor -
Provides
traffic and performance monitoring per VPN-1/FireWall-1 gateway.
|
CPIN-RTM |
Yes |
1 |
To the enforcement
point. |
For Gateway
HA: ·
SmartView Monitor for every
management station in the cluster | |||||
|
SmartUpdate - Provides
centralized software management and licensing for Check Point products.
The installation of service packs and addition of new products can be
performed from a central GUI |
CPMP-SUP (note: included in
SmartCenter Pro and SVN Enterprise bundle) |
Yes |
1 |
To the Management
Station |
For Management
HA: ·
SmartUpdate for every
management station in the cluster | |||||
|
SmartMap Provides
visualization and editing of security policies and objects through an
automatically generated topological view of the network |
CPMP-VPE (note: included in
SmartCenter Pro and SVN Enterprise bundle) |
No |
1 |
To the Management
Station |
For Management HA:
·
SmartMap for every management
station in the cluster | |||||
|
Customer Log Module
-
Enables
real-time log accumulation, tracking and management |
CPMP-CLM |
No |
1 |
To the Management
Station |
For Gateway HA:
·
CLM for every gateway in the
cluster | |||||
|
Open Security
Extension - OSE manages
packet filters and access lists of third-party routers and security
devices. |
CPMP-OSE |
Yes |
1 |
To the Management
Station |
For Management
HA: ·
OSE for every gateway in the
cluster | |||||
|
SmartView Reporter -
Consolidate and
filter log entries from Check Point log files, generate textual and
graphical reports, and distribute reports automatically to various targets
such as email, web server, printer, etc |
CPIN-RM |
Yes |
1 |
To the Management
Station |
For Management HA:
·
SmartView Reporter for every
gateway in the cluster | |||||
|
Account Management
Module - Storage and
retrieval of VPN-1/FireWall-1 user attributes on LDAP server |
CPFW-AM |
Yes |
1 |
To the Management
Station |
For Management
HA: ·
Account Management for every
gateway in the cluster | |||||
|
Meta IP Manager
Service - Manages the
purchased number of Meta IP DNS and DHCP services for a specified IP
Address count |
CPMI-MSM |
No |
1 |
To the Management
Station |
For Management HA:
·
MSM as
required ·
DHCP and/or DNS server
license | |||||
|
Meta IP DNS and DHCP
DNS and DHCP engines |
CPMI-DNS, CPMI-DHCP |
Yes |
1 |
To the Management
Station |
For Management HA:
·
MSM as
required ·
DHCP and/or DNS server
license | |||||
|
Meta IP Client License
Client licenses
for DHCP and DNS services |
CPMI-IP |
Yes |
1 |
To the
gateway |
For Gateway HA:
·
CPMI-IP as
required | |||||
|
ConnectControl Module
- Enable
increased quality of service via automatic application server load
balancing |
CPFW-CC |
No |
1 |
To the
gateway |
For Gateway HA:
·
CC as
required | |||||
|
Multi CPU Support -
Enables
the use of VPN-1/FireWall-1 with multi processor systems |
CPMP-MPU (note: included with
every unlimited enforcement point) |
No |
1 |
To the gateway
enforcement point |
For Gateway
HA: ·
MPU as
required | |||||
|
ClusterXL (HA and Load
Sharing) - High
Availability software for VPN-1/FireWall-1. Enables load sharing
and transparent fail over across a series of modules in a
cluster |
In NG:
CPMP-CXL In V41: |
No |
NG FP2 and higher:
1 NG FP1 and lower: 2 |
NG FP2 and
higher: |
| |||||
|
Management Station
High Availability - Enables
automatic synchronization of backup management stations ensuring constant
availability |
CPMP-MGM-HA |
No |
1 |
Applied to the primary
Management Station |
| |||||