# Overview

Cloud Firewall Central Licensing tool (formerly known as CloudGuard Central Licensing tool) for Check Point Security Management Servers and Multi-Domain Servers enables simple and flexible license management on Cloud Firewall Gateways.

The Cloud Firewall [Central License](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#) tool is deployed on the [Security Management Server](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#) or Multi-Domain Security Management Server. It organizes Cloud Firewall licenses into a shared pool and automatically distributes them between subscribed [Cloud Firewall Gateway](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#).

Key features:

- **Scalability** - Supports scaling of [Security Gateway](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#) instances and virtual cores.
- **License Distribution** - Automatically distributes licenses to Security Gateways.
- **Centralized Management** - Streamlines license management.

## Supported Solutions

- All public and private cloud solutions of Check Point Security Management Servers and Multi-Domain Security Management Servers.
- All Security Gateways running on public and private cloud platforms with [Check Point Cloud Security Solutions](https://www.checkpoint.com/cloudguard/cloud-security-solutions/): Amazon Web Services ([AWS](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#)), [Microsoft Azure](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#), [Google Cloud Platform](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#), VMware ESXi, [VMware NSX-T](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#), Hyper-V, [OpenStack](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#), and KVM.
- For the list of supported versions, refer to the [Support Life Cycle Policy](https://www.checkpoint.com/support-services/support-life-cycle-policy/).

## Prerequisites

1. If you use the Central License tool in the **MDS (System) Mode** on a Multi-Domain Security Management Server (see [Multi-Domain Server Modes](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Multi-Domain-Server-Specifications.htm)), make sure each Domain has access to the Internet. Make sure that DNS and proxy settings are correct.
   - Proxy settings must be configured in [SmartConsole](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Central_License_Tool_Admin_Guide/Content/Topics-Central-License-Tool/Overview.htm#) for each Domain:
     1. Double-click the Domain object to open its properties.
     2. Go to **Network Management > Proxy** to configure proxy settings.

2. The Central License tool distributes licenses only to Security Gateways with the policy installed.

|     |     |
| --- | --- |
|  | Best Practice - The Management Server and Multi-Domain Security Management Server (in the **Domain Mode**) must have Internet access to get license contracts from the User Center automatically. If there is no Internet access, you must manually import license contracts.
