CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-30
Junior Member
 
Join Date: 2007-09-06
Posts: 5
Rep Power: 0
jackson_ku has an average reputation (10+)
Default software & license requirement for SecurePlatform with cluster

Hi,

We planned to design 2 Checkpoint SecurePlatform servers, our requirement are :

1. must running HA or load sharing mode
2. must support unlimited users
3. must support 5 site to site IPSec VPN tunnels
4. must support unlimited remote access IPSec VPN clients

Please give me advise which software & software license I need to purchased? And which software or software license is free?

We already have 2 Nokia IP650 installed and running. Is there any good methods to transfer all configurations from IP650 to SecurePlatform for both configuration in IPSO & Checkpoint? ( In my new network structure, all firewall configuration no change except one of Firewall interface IP address change to another IP subnet )

Best Regards,

Jackson Ku
Reply With Quote
  #2 (permalink)  
Old 2008-01-31
Senior Member
 
Join Date: 2007-06-04
Posts: 1,096
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: software & license requirement for SecurePlatform with cluster

You will need to manually transfer the network settings from IPSO to SPLAT. The security policy is on the management server so shouldn't be affected.

As you want unlimited then I would suggest as follows.

CPPWR-CKP-5-U VPN-1 Power Unlimited Gateways and SMARTCenter for 5 sites.

CPPWR-VPG-HA-U VPN-1 Power Unlimited Gatway for High Availability. WHen combined with above will give 1 pair of licenses for gateway cluster.


CPMP-CXLS-U Cluster XL for Unlimited Gateway IF you want Load Sharing / Active/Active. If you want High Availability / Active/passive then you don't need this.


You would need appropriate software subs etc however your reseller can get you that.



This will give you a SMARTCenter that can manage 5 sites. A site being a cluster or gateway, or edge box. They inlclude the licenses for Secure Remote connectivity for VPN CLient but does not inlclude SecureClient if you wanted that instead.

It will also give you a pair of gateways to make 1 cluster. The optional CLusterXL license is for if want Active/Active.





Alternatively then you could look at the new appliances that include the gateway licenses and just buy a Smartcenter license.
Reply With Quote
  #3 (permalink)  
Old 2008-01-31
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: software & license requirement for SecurePlatform with cluster

Quote:
Originally Posted by mcnallym View Post
Alternatively then you could look at the new appliances that include the gateway licenses and just buy a Smartcenter license.
2x UTM-1 (probably a 2050) may work for you as well depending on throughput requirements. UTM-1 includes a SmartCenter.
Reply With Quote
  #4 (permalink)  
Old 2008-01-31
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: software & license requirement for SecurePlatform with cluster

Quote:
Originally Posted by jackson_ku View Post
We already have 2 Nokia IP650 installed and running. Is there any good methods to transfer all configurations from IP650 to SecurePlatform for both configuration in IPSO & Checkpoint? ( In my new network structure, all firewall configuration no change except one of Firewall interface IP address change to another IP subnet )
For gateways, there really isn't anything from the checkpoint side to transfer, it will all get pushed from the SmartCenter.

As for the OS config, I've never seen anything. If you find something, please let us know.
Reply With Quote
  #5 (permalink)  
Old 2008-01-31
Junior Member
 
Join Date: 2007-09-06
Posts: 5
Rep Power: 0
jackson_ku has an average reputation (10+)
Default Re: software & license requirement for SecurePlatform with cluster

Hi,

Thanks for your kindly support.

Best Regards,

Jackson Ku
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:30.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0