Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wei_Soon_Heng
Contributor
Contributor
Jump to solution

Security gateway license scheme

Hi All,

Currently, I had customer who has a query on the purchased sku license : CPSG-C-2-500 which is 2 cores limited and 500 limited users. My question here is how is the 500 users count? Is it based on IP of internal users, gateway or router? Will the firewall let the traffic bypassed if the environment is exceed 500 users?

Thanks

1 Solution

Accepted Solutions
Timothy_Hall
Legend Legend
Legend

At least at one point the gateway would count all unique source IP addresses that would show up inbound on all interfaces marked as Internal in the firewall/cluster topology.  When you went over the limit, a warning would be issued in the firewall traffic logs (and syslog as well) but firewall functionality would not be otherwise affected (usually, but see below).  I don't know if recent versions of gateway code still do this "counting" as I haven't seen this warning message in a very long time.

I'm intimately familiar with this mechanism, see the link below for a trip down memory lane for those of you that have used Check Point for more than 15 years...

https😕/seclists.org/bugtraq/2001/Jan/282

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

2 Replies
Timothy_Hall
Legend Legend
Legend

At least at one point the gateway would count all unique source IP addresses that would show up inbound on all interfaces marked as Internal in the firewall/cluster topology.  When you went over the limit, a warning would be issued in the firewall traffic logs (and syslog as well) but firewall functionality would not be otherwise affected (usually, but see below).  I don't know if recent versions of gateway code still do this "counting" as I haven't seen this warning message in a very long time.

I'm intimately familiar with this mechanism, see the link below for a trip down memory lane for those of you that have used Check Point for more than 15 years...

https😕/seclists.org/bugtraq/2001/Jan/282

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
G_W_Albrecht
Legend Legend
Legend

Or sk10200: 'too many internal hosts' error in /var/log/messages on Security Gateway - Last Updated: 23-Jan-2018

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events