CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We've already had our first sign-ups!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 6/9, 7/14, 8/25, 10/6, 11/3, 12/8.
3. We have new forums in Portuguese and German (see below).
4. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
5. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-30
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 223
lammbo has an average reputation (10+)
Default Web Intelligence Licensing?

Distributed environment: SmartCenter is HA and all gateways are Active/Passive HA. R60/HFA_04 all the way *except R63 Eventia*

Hopefully, this will be an easy one for someone who already had this issue.

I tried to deploy some WI features a few nights ago. When I tried to verify my policy, it hung on verification and never would finish (waited for a while and tried multiple times with same result).

I have 2 ea. CPMP-WIT-U-NGX and 2 ea. CPMP-HWIT-U-NGX. What I do know is that I wanted 2 sites to be able to have unlimited web servers and the gateways are HA - and so are the licenses. But when they are imported using centralized management via SmartUpdate, they attach directly to SmartCenter, with nothing in the repository to attach to gateways themselves.

So... Where from here? Well, how about the good old CP knowledgebase!
_________________________________________
Solution ID: #sk31381

Product: Web Intelligence
Version: NG AI R55W, NGX
Last Modified: 06-Jun-2007
Solution
VPN-1 Pro NGX R60A

When activated, Web Intelligence generates one license. The license should be installed on the SmartCenter Server. This license is not additive, and a SmartDefense contract is needed to obtain Web Intelligence updates.

An NGX Security gateway or gateway cluster requires a Web Intelligence license if it enforces one or more of the following protections:

* Malicious Code Protector
* LDAP Injection
* SQL Injection
* Command Injection

* Directory Listing
* Error Concealment
* ASCII Only Request
* Header Spoofing
* HTTP Methods
_____________________________________________

Well, that's as clear as mud!!! If it generates one license and auto-attaches to the SmartCenter, how can I apply any part of the 4 licenses to the gateways/cluster? Those 4 items in blue are exactly what I'm trying to enforce.

AAAAARRRRRRRRGGGGGGGHHHHHHHH!
__________________
There's no place like 127.0.0.1
Reply With Quote
  #2 (permalink)  
Old 2007-07-30
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 223
lammbo has an average reputation (10+)
Default Re: Web Intelligence Licensing?

Opened a case with my VAR, who opened one with CP... This is what I now know.

My SmartCenter is HA
WIT license applies to Primary SmartCenter
WIT-HA license applies to Secondary (HA) SmartCenter (and just like with HA SmartCenter Licenses, must be assigned to the IP for this server and cannot be centrally managed)

WIT is NEVER applied to a gateway (?unless it's also your SmartCenter?)

The other 2 I have - well, let's just say I NEVER needed them and will be having a nice chat about 100% trade-in credit for the licenses and some other concession for paying support and maintenance for 2 years when they told me what I needed to buy - nuff said!

Anyway, my issue is still an issue and I'm sending in my DB to go in the CP test lab now. Will update this post once I know the cause and cure.
__________________
There's no place like 127.0.0.1

Last edited by lammbo : 2007-07-30 at 12:19.
Reply With Quote
  #3 (permalink)  
Old 3 Weeks Ago
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 223
lammbo has an average reputation (10+)
Default Re: Web Intelligence Licensing?

Just correcting this misinformation I was given back then...

Web Intelligence is licensed per gateway. An HA cluster is 2 nodes and therefore requires 2 licenses. I was sold what I needed and not extra. The license for the HA node is discounted with a 20% price break. CP's Price list clearly states this information (now).
__________________
There's no place like 127.0.0.1
Reply With Quote
  #4 (permalink)  
Old 3 Weeks Ago
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,463
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Web Intelligence Licensing?

On this topic, this is the list I received yesterday for what requires a WI license

As for licensing, the following defenses require WI license:
malicious code protector
sql injection
command injection
ldap injection
header spoofing
http methods
directory listing
error concealment
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 22:59.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0