CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-04
accesslimiter accesslimiter is offline
Junior Member
 
Join Date: 2006-12-11
Posts: 10
Rep Power: 0
accesslimiter has an average reputation (10+)
Default ssl extender license

Can anyone tell me how the SNX (ssl extender) license is counted? Better yet, how to clear this count once it is exceeded? Thanks,
Reply With Quote
  #2 (permalink)  
Old 2008-02-04
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,603
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ssl extender license

It depends.

On Connectra it is licensed for concurrent users
On firewalls (VPN-1 and VSX) it is licensed per user (named user).
Reply With Quote
  #3 (permalink)  
Old 2008-02-05
accesslimiter accesslimiter is offline
Junior Member
 
Join Date: 2006-12-11
Posts: 10
Rep Power: 0
accesslimiter has an average reputation (10+)
Default Re: ssl extender license

Thanks, but this is not what I see and I am getting conflicting information from Checkpoint. CP states the ssl extender license, for VPN-1, is based off the users IP once they connect and stored in a table that gets "refreshed" around 2-4 weeks and is con-current. Since a users IP can change constantly this will cause the ssl extender license count to get erroneously exceeded and the table containing this info needs to be cleared. I assume that a cpstop;cpstart would clear this, not an assumption I want to make, this would cause down time and still not clear this table AFAIK. Unlike secureclient with the policy server group I do not have an option to place licensed ssl extender users in a group. Not being able to restrict which users can and can not use ssl extender also presents a problem.
Reply With Quote
  #4 (permalink)  
Old 2008-02-06
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 135
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: ssl extender license

It wouldn't make sense that it counts different Client IPs...

The goal of SSL Extender being to allow users on the road to connect from numerous various remote sites...The table would fill up very quickly

I'd really like to know the real Checkpoint answer to this question though...
Reply With Quote
  #5 (permalink)  
Old 2008-02-06
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,603
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ssl extender license

Quote:
Originally Posted by accesslimiter View Post
Thanks, but this is not what I see and I am getting conflicting information from Checkpoint. CP states the ssl extender license, for VPN-1, is based off the users IP once they connect and stored in a table that gets "refreshed" around 2-4 weeks and is con-current.
I don't know who is telling you this, but it is wrong.
The license is based on users, not IP addresses.
The "refresh" should be 30 days.
A cpstop;cpstart will not (at least should not) clear the user list.

Unlike SecureClient there is no distinction between users. In SC the count is based on how many users can use the "Policy Server". This is an issue that has been talked about, but the low demand for limiting who can use SNX, leaves it on the back burner.

If this is a real issue for you, please raise it with your Check Point SE and file an RFE.
Reply With Quote
  #6 (permalink)  
Old 2008-02-07
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 135
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: ssl extender license

Quote:
Originally Posted by chillyjim View Post
I don't know who is telling you this, but it is wrong.
The license is based on users, not IP addresses.
The "refresh" should be 30 days.
A cpstop;cpstart will not (at least should not) clear the user list.

Unlike SecureClient there is no distinction between users. In SC the count is based on how many users can use the "Policy Server". This is an issue that has been talked about, but the low demand for limiting who can use SNX, leaves it on the back burner.

If this is a real issue for you, please raise it with your Check Point SE and file an RFE.
Interesting...I'll try to get confirmation from my SE about the 30 days thing

Thanks!
Reply With Quote
  #7 (permalink)  
Old 2008-02-07
accesslimiter accesslimiter is offline
Junior Member
 
Join Date: 2006-12-11
Posts: 10
Rep Power: 0
accesslimiter has an average reputation (10+)
Default Re: ssl extender license

This info came from the CP license group. I have already contacted our SE on this, waiting on reply. Regardless on user or IP I need to know how to clear this table without waiting 30 days.
Reply With Quote
  #8 (permalink)  
Old 2008-02-08
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 135
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: ssl extender license

Well the entries are located in the table sslt_om_ip_params but I can't seem to find it with the DB edit tool...

but then again, I'm not very experienced with that tool...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:31.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0