Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

What Checkpoint Licenses entitle me to

Status
Not open for further replies.

Finton

MIS
May 7, 2004
11
IE
What does a "Check Point Express - VPN-1 Express Gateway for 50 Users" license entitle me to. Does it mean that the firewall will protect 50 ip addresses behind it or does it relate to the total number of connections allowed through the firewall by the license. When I do the command "fw tab -t connections -s" the number of VALS is 1165 for example. My understanding of this is that there is currently 1165 connections through the firewall. I thought the number of connections was only limited by the spec of the firewall (memory etc) and not the license but I could be wrong. Any help/suggestions greatly appreciated...

--------------------------------------
Damien Allen CCNP,CCSE NG AI
--------------------------------------
 
50 user licence" is the number of hosts that it is licenced to protect. It's nothing to do with the number of active connections.

Chris.

**********************
Chris A.C, CCNA, CCSA
**********************
 
Thanks for getting back to me Chris that is what I thought. If I issue the command fw lichosts would I be right in saying this shows me the protected hosts. If protected hosts exceeds 50 what sort of problems would you expect to see.

--------------------------------------
Damien Allen CCNP,CCSE NG AI
--------------------------------------
 
Well, when the number of protected hosts exceeds the licence count, it doesn't actually stop any traffic or prevent new hosts from accessing resources across the firewall. What it does do is generate lots of logging and warning to the effect that you are exceeding your limit and this has a knock on effect on the performance of the firewall.

To be honest, we've had clients firewalls exceeding the licence limit for months without any real problems. That's not to say that you shouldn't have the correct licence of course.

Chris.

**********************
Chris A.C, CCNA, CCSA
**********************
 
My understanding of the licincing is you get about 10-20% leeway so you will get logging posted but as this number rises the logging becomes more pronounced until it will kill all performance
 
Exactly right. Best to have the correct licence.

Chris.

**********************
Chris A.C, CCNA, CCSA
**********************
 
Thanks for your help guys, much appreciated.

--------------------------------------
Damien Allen CCNP,CCSE NG AI
--------------------------------------
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top