- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello,
We are deploying some CP firewalls, 1 Multi domain management server and 1 multi domain Log server. I am a bit confused when getting licenses for the devices.
Multi Domain server: 10.1.1.1
Multi Domain Log server: 10.1.1.2
In Multi domain server, we created 2 domains:
- Domain1, with server = 10.1.1.11, log =10.1.1.12. gateway 1 will be in this domain.
- Domain 2, server = 10.1.1.21, log = 10.1.1.22, gateway 2 will be in this domain
In User center, we have 4 devices: CPSM-NGSM50-MD5 (multi domain server), CPSM-NGSM50-MLOG10 (multi domain log), and 2 gateways.
When registering licenses, which IP addresses should I use?
- for multi domain server: 10.1.1.1?
- for multi domain log server: should I use 10.1.1.1 or 10.1.1.2
- for gateway 1: should I use 10.1.1.1 (multi domain server) or 10.1.1.11 (Domain 1 server)
- for gateway 2: should I use 10.1.1.1 (multi domain server) or 10.1.1.21 (Domain 1 server)
do I have to do anything for Domain 1 server + log server, and Domain 2 server + log server?
I am trying to search in Checkpoint documents but have not found what I need and still confused. Please help to guide me or show me the documents I should look at.
Thanks,
Hiep.
The best practice is to license all management with the main IP address of MDS and assign central licenses to domains. Gateways will use central licensing with Domain IP address.
Hello Valeri,
Thanks for answering my question.
Just to confirm, in my example, I should use 10.1.1.1 for all licenses?
And how to assign central licenses to domains? I have not found out how to do that.
Thanks,
Hiep.
When licensing MDS and domains, you can use central IP for all or local IPs for domain. The process is self-explanatory when you generate the license. Either way will work. When licensing GWs, use Domain MGMT IP for central licensing.
MDSM licenses are described in the Admin Guides. Go to Multi-Domain Security Management Support - Solutions, Documentation, Downloads, Security Alerts , chose your product version and look for Licensing Overview chapter in the admin guide
Well, actually you don't assign central licenses to domains anymore.
The licensing scheme has changed.
You just need to order a CPSM-NGSM container with a CPSB-DMN blade attached like this:
Container | Description | Certificate Key | Support Type | Support Renewal | Services Renewal | |
---|---|---|---|---|---|---|
![]() | CPSM-NGSM50 Next Generation Security Management Software for 50 gateways |
Additional Blades | ||||||
![]() | 25 domains package for Multi-domain Security Management |
That's it. The domains (DMS/CMA) won't receive a license anymore. Just the MDS.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY