CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-21
osterber osterber is offline
Junior Member
 
Join Date: 2007-10-02
Posts: 10
Rep Power: 0
osterber has an average reputation (10+)
Default Help with demo -> nondemo license

OK - I'm a bit stuck. I'm trying to migrate a setup with a demo license to a non-demo license, and it's not working correctly.

My setup is as follows -- single server with three interfaces running SecurePlatform. I'll call my IP addresses <internal>, <dmz> and <external>. I have my SmartCenter and Firewall installed on the same host.

I had a demo license that contained:

Code:
Sign {
LICENSE <internal IP> 07Nov2007 CPMP-EVAL-1-NGX CK-<keystring>
}= Az8yWh8m-hDHxAu7xi-2vXYPGwUJ-SkQVfRMxf Index=3 Version=0
Sign {
LICENSE <internal IP> 07Nov2007 CPMP-EVAL-1-NGX CK-<keystring>
}= vM29yoX4-xkZde2ZZT-khowgoegv-iA56kdk9d Index=0 Version=0
I loaded this into SmartUpdate, and attached it to my server, and everything worked great. The gateway was working, SmartCenter was working, etc., etc., etc.

So I just got my full offiical license. It's license file is:

Code:
Sign {
LICENSE <internal IP> never CPXP-CI-VPX-100-NGX CK-<keystring>
}= dvXaWrRh-nXzg4TTph-CnD5VLQrw-6GFKYYALb Index=3 Version=0
Sign {
LICENSE <internal IP> never CPMP-SCT-3-NGX CK-<keystring>
}= FNfv3V2j-ik7t4uYuQ-nRPdyWvar-ery5roZkz Index=0 Version=0
When I try to load this file into my SmartUpdate, I get:

Code:
Cannot save the license 'CPMP-SCT-3-NGX@.....'
Mismatch between IP address of CheckPoint Gateway and local license
So in my license respository, I have the demo license, and just the 'CPXP-CI-VPX-100-NGX' license. If I attach the CPXP-CI-VPX-100-NGX license to my server, then the gateway continues to work, but SmartCenter doesn't work.... if I try to connect with SmartTracker or SmartDashboard, I'm told that there are no valid licenses.

What am I doing wrong?

One thing, perhaps it helps, in my SmartUpdate display, my 'License Management' page looks like:

Code:
 -  <internal IP>
   -  <firewall name>       <external IP>    NGX
      - CPMP-EVAL-1-NGX                       NGX
What am I doing wrong?

-Rick
Reply With Quote
  #2 (permalink)  
Old 2007-10-22
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 160
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: Help with demo -> nondemo license

Quick question....

Is the Licence you created a Local or central license?

As this could be the issue if you attaching you local license to your external IP address.

just a thought.....
Reply With Quote
  #3 (permalink)  
Old 2007-10-22
osterber osterber is offline
Junior Member
 
Join Date: 2007-10-02
Posts: 10
Rep Power: 0
osterber has an average reputation (10+)
Default Re: Help with demo -> nondemo license

Both my demo and non-demo license are central.

-Rick
Reply With Quote
  #4 (permalink)  
Old 2007-10-22
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Help with demo -> nondemo license

Do you have your topology set?

Try to add the license from the command line and see what it tells you.
Reply With Quote
  #5 (permalink)  
Old 2007-10-22
osterber osterber is offline
Junior Member
 
Join Date: 2007-10-02
Posts: 10
Rep Power: 0
osterber has an average reputation (10+)
Default Re: Help with demo -> nondemo license

Topology is set. Set enough such that everything works (including VPN stuff) with my demo license.

Checkpoint licensing said that the solution is to license with my external IP address. Huh? Everything I've read suggests that I should be licensing against my internal IP which is my SmartCenter IP. (Though SmartCenter is on the same host... so SmartCenter technically has all three IPs on it, too.)

-Rick
Reply With Quote
  #6 (permalink)  
Old 2007-10-22
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 139
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Help with demo -> nondemo license

mystery checkpoint...

take a look into /etc/hosts
I had simmilar problems with tricky split dns zones and Splat adjusts the settings without telling.
Reply With Quote
  #7 (permalink)  
Old 2007-10-23
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Help with demo -> nondemo license

If you have an all in one box with gateway and management on 1 box then yes I would recommend that you license on the external address. It just makes life a lot easier where the license address in question matches the external address, which is what will be VPN connections to. Just makes life easier in terms of VPN.

If in a split environment then yes I would use the internal ip of the smartcenter which is what you will read in the docs etc.

I take it that the object definition for the gateway/module box shows the external ip address, and that is what is in /etc/hosts hence why Check Point say to license on the external.
Reply With Quote
  #8 (permalink)  
Old 2007-10-24
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 691
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: Help with demo -> nondemo license

I think there is a bug with the SmartUpdate GUI. To make sure that is
NOT the case you can do the following:

1) download the licensce to your SmartCenter /tmp directory. Make
sure you use binary and NOT ASCII file transfer,

2) on the SmartCenter do the following:
cplic put -l /tmp/license.lic

If the license is not corrupted and correct, it will work.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:12.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0