CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-13
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default ClusterXL license question

Does the 15 eval license come with ClusterXL
Active/Active license? I seem to recall that the
answer is NO because when I setup a pair
of SPLAT NGx R65 in Active/Active with 15
days eval license and a SmartCenter with
15 eval license as well, I can not get Active/Active
to work, only in High Availability (H/A).

Can someone confirm this? Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-10-13
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ClusterXL license question

If the SmartCenter and the two gateways are in the plug-and-play eval you should have cxl as well as just about everything else.
Reply With Quote
  #3 (permalink)  
Old 2007-10-13
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL license question

Well, Active/Active did not work for me and I have the Provider-1
NGx R65 with HFA_01 and pair of SPLAT box with 15 days eval license
and Active/Active did NOT work. It only works in HA mode.

I tried both Multicast and Unicast mode and neither work in Active/Active.

Problem is that the upstream router did not pick up the Virtual ip address.


I have another identical setup in R55 and it works fine in Active/Active
except that I have valid clusterXL license in the R55 environment.
Reply With Quote
  #4 (permalink)  
Old 2007-10-14
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ClusterXL license question

Is it giving you a license error?

Your Check Point SE and/or reseller can generate you some eval licenses.
Reply With Quote
  #5 (permalink)  
Old 2007-10-14
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL license question

Chillyjim,

"Your Check Point SE and/or reseller can generate you some eval licenses."

I can do that myself but that is besides the point. I would like to know
if the 15 days eval come with Active/Active since I am testing new features
on my cluster and it will run for about a week. If the active/active
license is included in the 15 days eval, I don't have to generate license.
Reply With Quote
  #6 (permalink)  
Old 2007-10-15
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ClusterXL license question

The Plug-in-play license is suppose to be a full eval licenses that includes all features for the gateway and SmartCenter.
Reply With Quote
  #7 (permalink)  
Old 2007-10-15
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL license question

ChillyJim,

I think you're correct. The 15 days eval has everything
including clusterXL active/active license. I just rebuilt
my enforcement module with R65 (NO hfa_01) and
it works fine. As soon as I applied hfa01, clusterXL stopped
working. I have to "uncheck ClusterXL" in the gateway cluster
properties, push policy, then "check clusterXL" again, push
policy again then clusterXL works again.

Must be a bug in HFA_01.

Thanks again ChillyJim.
Reply With Quote
  #8 (permalink)  
Old 2007-10-17
willr willr is offline
Junior Member
 
Join Date: 2007-10-09
Posts: 18
Rep Power: 0
willr has an average reputation (10+)
Default Re: ClusterXL license question

Maybe your problem is not the license?

I had a problem where the switch would not register the firewall VIP mac address in the arp tables. Doing a static ARP entry in the switch, for the VIP IP/mac of the firewall cluster solved the problem.
Reply With Quote
  #9 (permalink)  
Old 2007-10-17
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL license question

In your case, you must be doing "multicast" instead "unicast".

With ClusterXL in "unicast", you do NOT need static ARP entry on the
switch or upstream device. My problem remains even with a HUB.

The fix is what I described previously.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:42.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0