Cybersecurity
Remote Access VPN Appliances
Concurrent-user count drives this decision more than anything on the datasheet. We size the appliance against real session load, quote the client license pack with it, and ship it pre-staged for your tunnel policy.

- Category
- Termination appliances, client licensing and branch or cellular endpoints
- What we quote
- Appliance, concurrent-user license pack and multi-year subscription
- Sizing
- Against peak concurrent sessions and encrypted throughput
- Boundary
- Tunnel policy and user provisioning stay with your network team
Sized for a normal Tuesday, tested on the day nobody comes in
Remote-access appliances are almost always specified against headcount, and headcount is the wrong number. What matters is peak concurrent sessions — which is a fraction of headcount on an ordinary day and approaches all of it during a weather event, a facility closure or an exercise. That is exactly when the appliance is load-bearing, and exactly when an undersized one refuses connections. The second trap is licensing: on most platforms the chassis includes a modest number of concurrent users and additional capacity is a separate license pack, so a correctly sized appliance can still be wrongly licensed. We size against peak concurrency and encrypted throughput, quote the client pack that matches, and stage the unit configured to your tunnel policy so the first connection attempt is not also the first configuration attempt.
What decides the appliance and the license pack
Two separate numbers, routinely conflated, and both belong on the quote.
- Peak concurrent sessions during an all-remote day, not average daily users
- Encrypted throughput required, which is where the chassis limit really binds
- Whether the appliance also terminates site-to-site tunnels alongside client sessions
- Client platform mix, since license packs and supported clients differ by vendor
- Whether a high-availability pair is required, and whether both units need entitlement
- Any branch or vehicle sites that need cellular failover rather than a fixed circuit
Termination, client licensing and the branch edge
Priced lines from the hub catalog across the firewall and branch-connectivity categories. Naming a manufacturer describes the market, not a Uniqcli partnership or endorsement.
SonicWall and WatchGuard
The TZ and NSa ranges and the Firebox line, both of which terminate client sessions alongside their firewall role. Quoted with the concurrent-user license pack sized to peak rather than to the included allowance.
Sophos and Check Point
Two further estates with priced depth, and the obvious pick where the endpoint or boundary estate already comes from the same vendor and the client is already deployed. Quoted per appliance with the subscription term attached.
Peplink for the branch edge
Where a site, a vehicle or a temporary location needs bonded or cellular connectivity behind the tunnel rather than a fixed circuit. Priced rows across the range, quoted with the antenna and mounting the deployment actually needs.
Staged for your tunnel policy
Interface addressing, base policy, client profile and high-availability pairing configured before shipping, to a design you provide — so the unit arrives ready for the rack instead of factory-default.
Remote access questions
How many concurrent users can an appliance handle?
Two limits apply and the lower one wins: the chassis capacity for concurrent tunnels, and the license pack you bought. Vendors publish maximum session counts that assume light traffic, so encrypted throughput usually binds first in practice. We size against your peak-day concurrency and state which limit we sized to.
Is remote access VPN still the right model?
For many agencies, yes — particularly where applications are on-premises and the boundary is well defined. Zero-trust network access approaches change the model to per-application rather than per-network, and where a program is heading that way we will say so plainly, including where we do not hold priced inventory for the product they have chosen.
Do client licenses renew separately from the appliance?
Often, yes. The chassis, the security subscription and the concurrent-user pack can all carry different terms and different anniversaries, which is how a site ends up with a supported appliance and expired client capacity. We track all three dates and quote them co-termed where the vendor allows it.
Can you configure the appliance before it ships?
Yes, against a design you provide — addressing, base policy, client profile and high-availability pairing, with firmware baselined. We configure to your tunnel policy; we do not author it, and we do not hold administrative access after handover.
The solutions atlas
Every solution, one accountable partner.
UniQ platforms
By technology
By customer
- TAA & NDAA-889 Compliance Screening
- CMMC & CUI Solutions
- Federal & DoD
- State, Local & Education
- Healthcare
- Enterprise
- Rapid Procurement & GPC Buys
- Multi-Vendor Integration Projects
- eProcurement & Custom Catalogs
- FISMA Modernization
- CJIS-Compliant Justice Cloud & Local AI
- Federal Storage Modernization
- Government ERP & Business Systems Infrastructure
- Managed Procurement
- Secure AV & Conferencing
- Fiber Network Infrastructure
- Satellite & Resilient Connectivity
- Wavelength & Optical Transport
- Decentralized Data Centers
- Data Center Design & Build
Size against your peak day
Send peak concurrent sessions, the throughput you need and whether a high-availability pair is in scope. We return an appliance and license-pack quote sized to the peak, with staging and configuration priced alongside it.