Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wei_Soon_Heng
Contributor

Security gateway license scheme

Jump to solution

Hi All,

Currently, I had customer who has a query on the purchased sku license : CPSG-C-2-500 which is 2 cores limited and 500 limited users. My question here is how is the 500 users count? Is it based on IP of internal users, gateway or router? Will the firewall let the traffic bypassed if the environment is exceed 500 users?

Thanks

1 Solution

Accepted Solutions
Timothy_Hall
Champion
Champion

At least at one point the gateway would count all unique source IP addresses that would show up inbound on all interfaces marked as Internal in the firewall/cluster topology.  When you went over the limit, a warning would be issued in the firewall traffic logs (and syslog as well) but firewall functionality would not be otherwise affected (usually, but see below).  I don't know if recent versions of gateway code still do this "counting" as I haven't seen this warning message in a very long time.

I'm intimately familiar with this mechanism, see the link below for a trip down memory lane for those of you that have used Check Point for more than 15 years...

https😕/seclists.org/bugtraq/2001/Jan/282

 

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

2 Replies
Timothy_Hall
Champion
Champion

At least at one point the gateway would count all unique source IP addresses that would show up inbound on all interfaces marked as Internal in the firewall/cluster topology.  When you went over the limit, a warning would be issued in the firewall traffic logs (and syslog as well) but firewall functionality would not be otherwise affected (usually, but see below).  I don't know if recent versions of gateway code still do this "counting" as I haven't seen this warning message in a very long time.

I'm intimately familiar with this mechanism, see the link below for a trip down memory lane for those of you that have used Check Point for more than 15 years...

https😕/seclists.org/bugtraq/2001/Jan/282

 

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com

View solution in original post

G_W_Albrecht
Legend
Legend