CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-27
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 152
Rep Power: 2
Danielpb has an average reputation (10+)
Default fw lichosts

Wonder if someone might she some light on the results I see when running this command.

The results are well over the limit of the Licence installed, how ever allot of the host's are from 2005 etc. any idea why this is.

Some results:

eth- 8/12/2005 15:57> host:192.168.200.244 src:192.168.200.244 dst:192.168.200.252 proto:icmp
eth- 8/12/2005 15:57> host:192.168.200.253 src:192.168.200.253 dst:224.0.0.18 proto:vrrp
eth- 8/12/2005 15:58> host:192.168.200.194 src:192.168.200.194 dst:192.168.14.10 proto:tcp sport:3874 dport:microsoft-ds
eth- 8/12/2005 15:58> host:192.168.200.215 src:192.168.200.215 dst:192.168.202.10 proto:tcp sport:vlsi-lm dport:loc-srv
eth- 8/12/2005 15:58> host:192.168.200.222 src:192.168.200.222 dst:192.168.245.82 proto:udp sport:3661 dport:snmp-read
Reply With Quote
  #2 (permalink)  
Old 2007-11-29
DoubleYou DoubleYou is offline
Junior Member
 
Join Date: 2007-11-28
Posts: 2
Rep Power: 0
DoubleYou has an average reputation (10+)
Default Re: fw lichosts

Quote:
Originally Posted by Danielpb View Post
Wonder if someone might she some light on the results I see when running this command.

The results are well over the limit of the Licence installed, how ever allot of the host's are from 2005 etc. any idea why this is.

This is a recurring issue in many CP related fora. The problem is that the firewall keeps track of all internal hosts (i.e. machines behind internal interfaces) in its hosts table, for an indefinite period of time. For one reason or another, this number keeps growing, even though there aren't that many different IPs in use, but over a longer period of time (like in your case, since 2005), this is of course an issue.

The explanation on how to clear the tables is give in another thread:
Clear LicHosts

There seems to be no other solution to this problem besides regularly clearing this table. I found that rebooting the firewalls in a cluster after clearing the tables is advisable - otherwise they seem to go beserk...

Good luck!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:47.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0