LICENSEWARE

Check Point Quantum and Cloud Firewall licensing

This article is about licensing Check Point network security gateways (Quantum appliances, Spark Firewall, Cloud Firewall, formerly CloudGuard Network) and their management (Security Management Server, Smart-1 Cloud). For endpoint, email and SASE services see Check Point workspace security licensing.

On This Page

Check Point Quantum and Cloud Firewall licensing covers the network security gateways and management servers that Check Point sells as appliances, as software for open servers and virtual machines, and as cloud gateways. Licences for gateways and management servers are added and viewed in SmartConsole.[3] They are licensed under the Software License Agreement, which ties use to a License Key and a Licensed Configuration. That configuration states the features, the number of users, devices or nodes, the number of cores or the maximum throughput on which the fee was based.[1] Licences are issued in the Check Point User Center to an IP address. Gateway feature sets are built from Software Blades, whose licence state SmartConsole reports for each gateway and management server.[3] Commercial and support context is in Check Point licensing.

Editions

Gateway entitlements combine three layers. The first is the appliance or software licence for the gateway. The second is a set of Software Blades or blade packages. The third is the contracts that give each subscription blade its validity period.[3][4] The Cloud Firewall Central License Tool groups licences by blade content into two pool types. NGTP covers Anti-Bot, Anti-Virus, Application Control, URL Filtering, Anti-Spam, Email Security or IPS. NGTX adds Threat Emulation or Threat Extraction. A licence that includes Data Loss Prevention has “+DLP” appended to its pool type.[4] The 2017 CloudGuard IaaS note describes the same two packages. It lists firewall, VPN, IPS, application control, URL filtering, anti-virus, anti-bot, network policy management and logging in both, and adds Threat Emulation and Threat Extraction only in NGTX.[5]

Product line Typical deployment Licence form 
Quantum Security Gateways / Quantum Force Appliances and open servers managed by a Security Management Server Central or Local licence; blade contracts[2] 
Spark Firewall (Quantum Spark) Small-office appliances, locally or cloud managed Licence activated from the User Center; optional PAYG[6] 
Cloud Firewall (CloudGuard Network) AWS, Azure, GCP, VMware ESXi, NSX-T, Hyper-V, OpenStack, KVM Central licence pool of cores (BYOL) or marketplace PAYG[4][5] 
Security Management / Multi-Domain On-premises or virtual management Licence on the management server IP[2] 
Smart-1 Cloud Management as a service Licence defines log ingestion and retention[7] 

Historic BYOL bundle SKUs were sold per vCore with NGTP or NGTX blades and Standard support, for one, two or three years. An example is CPSG-VSEC-AWS-BUN-NGTX-1Y.[5]

Metrics

Unit Catalog row Notes 
Licensed Configuration Licensed Configuration Features plus users, devices or nodes, cores or throughput, as printed on the License Key.[1] 
vCore vCore (Cloud Firewall central licence pool) Pool cores consumed by each subscribed Cloud Firewall Gateway.[4] 
Hourly usage Hourly usage (marketplace PAYG) Marketplace-billed cloud gateways.[5] 
Active device-day Spark PAYG active device-day Spark Firewalls under MSSP Pay-As-You-Go.[6] 
Daily log ingestion Smart-1 Cloud daily log ingestion Smart-1 Cloud management service.[7] 

Counting / floors

Central and Local licences. A Central licence is attached to the IP address of the Management Server. A Local licence is tied to the IP address of a specific Security Gateway and can be used only on a gateway or server with that address.[2] Detaching a Central licence from a gateway returns it to the Licenses & Contracts Repository for use by other managed gateways.[2] The cplic put command installs Local licences, and its check option verifies that the licence IP matches the server.[9] When a gateway’s address changes, a Local licence therefore has to be reissued in the User Center. A Central licence follows the management server. Catalog: Central licences attach to the Management Server IP; Local licences to the gateway IP.

What SmartConsole shows. For each licence SmartConsole lists the IP address it was generated for, the expiry date of the support contract, the Certificate Key (CK) and the SKU (the User Center catalog ID).[3] For each blade it shows a status: Active, Available, No License, Expired, About to Expire, Quota Exceeded or Quota Warning. “Quota Exceeded” means the licence is valid but the quota of related objects is exceeded, such as gateways, files or Virtual Systems, depending on the blade.[3] “About to Expire” is raised 30 days before expiry by default, or 7 days for an evaluation licence.[3] These statuses are the closest thing to a built-in compliance report for gateways. Catalog: Expired licences stop the licensed features.

Grace on new gateways. A blade can show “Not Activated”, meaning no licence is installed, only during the first 15 days after Secure Internal Communication (SIC) is established with the Security Management Server.[3] Catalog: Blades run unlicensed only during the first 15 days after SIC.

Expiry. Licences expire on a set date or never. When a licence expires, the products and features it covers stop working on the computer it is attached to.[2] A perpetual gateway licence can therefore sit beside time-limited blade subscriptions on the same appliance.

Throughput and cores. Designing anything that alters the number of readable IP addresses, users or cores, or exceeds the throughput presented to the product, in order to get around the Licensed Configuration breaches the licence.[1] Catalog: Circumventing the Licensed Configuration is a breach.

Virtualization & partitioning

Cloud Firewall central licence pool. The Cloud Firewall Central License Tool runs on the Security Management Server or Multi-Domain Server. It organizes Cloud Firewall licences into a shared pool and distributes them automatically to subscribed gateways.[4] The Central licence is issued to the IP address of the management server, or of the Domain server when the tool runs in Domain mode.[4] The tool reports the total licensed cores, the available cores, and the cores each gateway consumes. It can also produce an hourly core usage report once data collection is enabled.[4] Distribution runs once a day, after policy installation, and when a gateway moves between pools. A change in a gateway’s vCore count therefore shows up after one day unless an administrator triggers distribution.[4] A gateway must have a policy installed to receive a licence.[4] Catalog: Cloud Firewall gateways draw vCores from a central pool.

Limitations that affect counting. The tool cannot license a standalone machine in a Full HA cluster. Each Full HA member needs its own non-central licence generated for its IP address.[4] It does not distribute licences to Cloud Firewall for NSX gateways, and it does not support ElasticXL.[4] When an evaluation licence expires, it moves to a special EXPIRED pool and is removed from the gateways that used it.[4] Catalog: Full HA cluster members need their own non-central licence.

Moving cores. The 2017 licensing note presented the elastic model as a single global licence for as many gateways as needed. Cores could be moved from one gateway to another through the central pool, and MSPs could buy one pool of vCores and use it across tenants.[5] Licences can be moved between the customer’s own User Center accounts.[4]

VSX. SmartConsole reports an error when viewing licences of Virtual System or Virtual Router objects; licence information for VSX is read from the VSX Gateway or VSX Cluster object instead.[11] See virtualization and partitioning.

Cloud / BYOL

Cloud Firewall can be bought in two ways. Under BYOL, licences bought through the normal Check Point channels form the elastic vCore pool. The model applies to private clouds (VMware ESXi, Hyper-V, KVM) and public clouds (AWS, Azure and Azure Stack, GCP).[5] Under PAYG, an hourly licence is billed directly by the AWS, Azure or GCP marketplace. Its fee includes the Software Blades and Standard Support but not the virtual compute, which is paid to the cloud provider.[5] Catalog: BYOL is per vCore across all gateways; PAYG is hourly through the marketplace; program Cloud marketplace PAYG. The Cloud Terms list “Cloud Firewall-as-a-Service” as a separate Check Point-hosted Service with a 99.99% monthly availability target.[10] See cloud BYOL.

Programs

Spark Firewall Pay-As-You-Go. From R82.00.00, locally managed Spark Firewall gateways that are managed through Spark Management can use Pay-As-You-Go. Billing is daily, on actual gateway usage, through the Check Point Portal PAYG infrastructure.[6] The customer is charged only for days on which a device is in active use. Every gateway is still sold with a licence that must be installed by offline activation before PAYG can be used.[6] Disconnecting a gateway from Spark Management stops PAYG billing immediately. If the MSSP removes the contract, the gateway reverts to the subscription setting.[6] When a Spark licence expires, cloud-dependent services stop. These include cloud backup, cloud log storage, reports and Spark Management events.[6] Catalog: Spark PAYG bills only days a device is active.

Smart-1 Cloud. The Smart-1 Cloud licence sets the maximum daily log ingestion rate and the log retention period, which is 90 days as standard. Some SKUs offer longer retention.[7] Check Point advises buying a daily ingestion limit above the average ingestion rate to avoid losing data.[7] Smart-1 Cloud can manage up to 400 Security Gateways.[7] New accounts get a 30-day trial. Licences are additive and should all be allocated to the User Center account linked to the Portal account.[8] Catalog: Smart-1 Cloud licence sets log ingestion and retention.

Out of scope

  • Current Quantum Force appliance part numbers and blade package SKUs. Check Point’s product catalogue requires a User Center login, and appliance datasheets were not retrievable during research.
  • Maestro Hyperscale, ElasticXL and Scalable Platform licensing details.
  • Hardware specifications and appliance end-of-life dates.
  • Endpoint, email, SASE and other Check Point Portal services: see Check Point workspace security licensing.

References

  1. Check Point Software License Agreement and Limited Hardware WarrantyNo effective date stated. Catalog: Check Point Software License Agreement and Limited Hardware WarrantyRetrieved 2026-10-02.
  2. Licensing Terms for SmartUpdate (R82 Installation and Upgrade Guide)Page dated 17 June 2026. Catalog: Licensing Terms for SmartUpdate (R82 Installation and Upgrade Guide)Effective 2026-06-17. Retrieved 2026-10-02.
  3. Managing Licenses in SmartConsole (R82 Installation and Upgrade Guide)Page dated 17 June 2026. Catalog: Managing Licenses in SmartConsole (R82 Installation and Upgrade Guide)Effective 2026-06-17. Retrieved 2026-10-02.
  4. Cloud Firewall Central License Tool Administration GuideCover dated 24 August 2026. Catalog: Cloud Firewall Central License Tool Administration GuideEffective 2026-08-24. Retrieved 2026-10-02.
  5. Check Point CloudGuard IaaS Elastic LicensingPrice-list annex, copyright 2017; product and SKU names may be superseded. Catalog: Check Point CloudGuard IaaS Elastic LicensingRetrieved 2026-10-02.
  6. Managing Licenses (Quantum Spark R82.00.X Locally Managed Administration Guide)Page dated 15 September 2026. Catalog: Managing Licenses (Quantum Spark R82.00.X Locally Managed Administration Guide)Effective 2026-09-15. Retrieved 2026-10-02.
  7. Smart-1 Cloud Frequently Asked QuestionsPage dated 31 August 2026. Catalog: Smart-1 Cloud Frequently Asked QuestionsEffective 2026-08-31. Retrieved 2026-10-02.
  8. Smart-1 Cloud Best PracticesSection Smart-1 Cloud License; page dated 31 August 2026.Effective 2026-08-31. Retrieved 2026-10-02.
  9. cplic put (R82.10 Security Management Administration Guide)Command reference for installing Local licences.Retrieved 2026-10-02.
  10. Terms of Service - Cloud Services; Infinity PortalCloud End-user License Agreement. Catalog: Terms of Service - Cloud Services; Infinity PortalRetrieved 2026-10-02.
  11. Viewing Licenses in SmartConsole (R82 Security Management Administration Guide)Page dated 09 September 2026; includes viewing licence information for VSX.Effective 2026-09-09. Retrieved 2026-10-02.

See also

Catalog Rows Cited

1SKUs5Metrics9Rules1Programs

Esc