At least at one point the gateway would count all unique source IP addresses that would show up inbound on all interfaces marked as Internal in the firewall/cluster topology. When you went over the limit, a warning would be issued in the firewall traffic logs (and syslog as well) but firewall functionality would not be otherwise affected (usually, but see below). I don't know if recent versions of gateway code still do this "counting" as I haven't seen this warning message in a very long time.
I'm intimately familiar with this mechanism, see the link below for a trip down memory lane for those of you that have used Check Point for more than 15 years...
https😕/seclists.org/bugtraq/2001/Jan/282
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm