CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2009-04-02
Junior Member
 
Join Date: 2009-03-04
Posts: 13
Rep Power: 0
hotrod_952@hotmail.com has an average reputation (10+)
Default FW-1 Encryption Module

I tried to setup a VPN Remote user. Whenever the secure client tries to connect, they receive a gateway communication error. Also, I notice that the Smart Tracker shows, "No license for VPN" for packet. Does this mean that they customer needs to upgrade their license to VPN-1?
Reply With Quote
  #2 (permalink)  
Old 2009-04-02
Senior Member
 
Join Date: 2009-03-21
Posts: 183
Rep Power: 1
MrSnakey has an average reputation (10+)
Default Re: FW-1 Encryption Module

Quote:
Originally Posted by hotrod_952@hotmail.com View Post
I tried to setup a VPN Remote user. Whenever the secure client tries to connect, they receive a gateway communication error. Also, I notice that the Smart Tracker shows, "No license for VPN" for packet. Does this mean that they customer needs to upgrade their license to VPN-1?
Yes. Have them contact a competent Check Point reseller with their license ready.
__________________
--
Mr Snakey
Remember: Speculation does no-one any good.
Visit http://www.snakeoilresearch.com
Reply With Quote
  #3 (permalink)  
Old 2009-04-02
Senior Member
 
Join Date: 2007-07-16
Posts: 1,873
Rep Power: 4
Thorpuse has an average reputation (10+)
Default Re: FW-1 Encryption Module

Wow... they either have an extremely old license (pre-2001, when VPN became a standard offering) or an extremely new one (R70, when we went Back to the Future about VPN and other features....).
Reply With Quote
  #4 (permalink)  
Old 2009-04-03
Junior Member
 
Join Date: 2009-03-04
Posts: 13
Rep Power: 0
hotrod_952@hotmail.com has an average reputation (10+)
Default Re: FW-1 Encryption Module

I can no longer connect the Dashboard with the external IP address. Any reasoning this is occurring?
Reply With Quote
  #5 (permalink)  
Old 2009-04-03
Senior Member
 
Join Date: 2009-03-21
Posts: 183
Rep Power: 1
MrSnakey has an average reputation (10+)
Default Re: FW-1 Encryption Module

Quote:
Originally Posted by hotrod_952@hotmail.com View Post
I can no longer connect the Dashboard with the external IP address. Any reasoning this is occurring?
Are you connecting from a different IP address? The Management Server component has what's called a 'GUI Client' list configured with the 'cpconfig' command that lists the IP addresses that the SmartDashboard is allowed to connect from.

If you are not connecting from an IP that's not on that list, then being denied is normal behavior.

You might want to check the logs too, and the out put of 'cplic print' just incase the customer has been running off of 30 day evals for the last some many years.
__________________
--
Mr Snakey
Remember: Speculation does no-one any good.
Visit http://www.snakeoilresearch.com
Reply With Quote
  #6 (permalink)  
Old 2009-04-05
Junior Member
 
Join Date: 2009-03-04
Posts: 13
Rep Power: 0
hotrod_952@hotmail.com has an average reputation (10+)
Default Re: FW-1 Encryption Module

cplic print shows they have the external IP license with cpfw-enc-u-mgmt-ng which allows you to upgrade to the VPN-1 module.
Reply With Quote
  #7 (permalink)  
Old 2009-04-06
Senior Member
 
Join Date: 2007-07-16
Posts: 1,873
Rep Power: 4
Thorpuse has an average reputation (10+)
Default Re: FW-1 Encryption Module

Please provide a sanitised complete output of the cplic print command. Those licenses are very old, I think you're missing some.

Is it just me, or does anyone else find it extremely ironic that R70 goes back to the model of having to get a separate license for encryption? And that in both cases, CP claimed it was done to simplify the license system and provide better value? Hmmmm....
Reply With Quote
  #8 (permalink)  
Old 2009-04-06
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 2,344
Rep Power: 7
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: FW-1 Encryption Module

The "VPN" part is at customer request.

I want the equivalent of the old "Enterprise Encryption Center" license (All the features that were available in one SKU).
Reply With Quote
  #9 (permalink)  
Old 2009-04-06
Senior Member
 
Join Date: 2007-07-16
Posts: 1,873
Rep Power: 4
Thorpuse has an average reputation (10+)
Default Re: FW-1 Encryption Module

Quote:
Originally Posted by chillyjim View Post
The "VPN" part is at customer request.

I want the equivalent of the old "Enterprise Encryption Center" license (All the features that were available in one SKU).
Seems ironic that "customers" are requesting this, when years ago "customers" were responsible for getting FW-1 and VPN-1 consolidated into a single product. And that consolidation was universally accepted and appreciated too!

All features in one license! It still exists.... sadly, it only works for 30 days.... I agree with the sentiment though - bundling only gets you so far.
Reply With Quote
  #10 (permalink)  
Old 2009-04-08
Senior Member
 
Join Date: 2006-10-03
Location: Offenbach/ Germany
Posts: 148
Rep Power: 4
Yasushi Kono has an average reputation (10+)
Default Re: FW-1 Encryption Module

Hi to all,

before making thoughts about if the correct licensing is being installed or not, you should first of all check, if the license is bound to the system. For that, you should type the following command on the securiy gateway (not "cplic print"):

cpstat polsrv -f default


There, you can see how many clients are licensed and how many of them are connected.

Kind regards,
Yasushi
Reply With Quote
  #11 (permalink)  
Old 2009-04-08
Member
 
Join Date: 2006-04-07
Location: Penzberg, Germany
Posts: 89
Rep Power: 4
Izzio has an average reputation (10+)
Default Re: FW-1 Encryption Module

...ehm it looks like as our SC license is a little bit oversized ;-)

cpstat polsrv -f default

Status Full Description: Policy Server is up
Licensed users: 4294967294
Connected users: 39
Reply With Quote
  #12 (permalink)  
Old 2009-04-08
Senior Member
 
Join Date: 2007-07-16
Posts: 1,873
Rep Power: 4
Thorpuse has an average reputation (10+)
Default Re: FW-1 Encryption Module

LOL! Wow... at $50 a license....
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:57.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2