Discussion:
Checkpoint Licensing
(too old to reply)
Chris
2003-08-01 16:35:48 UTC
Permalink
We are running a Windows 2000 Server with Firewall-1 NG FP3 which is the
management platform and the enforcement point for the central site. Now, we
were going to put a couple of Nokia IP130's at two remote sites using Small
Office. These firewalls would have been their own management modules, ie.
stand alone firewalls.

As Checkpoint have re-evaluated their licensing and no longer support
putting the management module on devices running Small Office, we are now
looking at using the existing firewall at the central site to manage the
remote IP130's which will just be enforcement points. So, my question is,
what do we have to change on the central firewall licence to be able to also
use it to manage two other firewalls? Also, can the remote IP130's run NG AI
even though the central firewall is NG FP3?

Any help would be appreciated.

Chris.
Pascal - ja nog een ja
2003-08-07 09:56:47 UTC
Permalink
Post by Chris
As Checkpoint have re-evaluated their licensing and no longer support
putting the management module on devices running Small Office, we are
now looking at using the existing firewall at the central site to
manage the remote IP130's which will just be enforcement points. So,
my question is, what do we have to change on the central firewall
licence to be able to also use it to manage two other firewalls? Also,
can the remote IP130's run NG AI even though the central firewall is
NG FP3?
Chris,

As far as I understood from my contacts within Checkpoint, the existing
SmallOffice licenses are kept in tact. That is, you have a Management
License with these licenses, and as long as you stay at "NG" level, you
will have these licenses.

If you want to manage you remote IP130's with your central firewall-
mamangent server, it is important to know what license you have on the
central location.

If (for instance) you already have a VEE-U license, you have a
SmartCenter which can manage "unlimited" firewalls. However, if you want
to do this, it is perhaps a good idea, to uncouple (don't know the
english word for this?) the management server and the firewall module.

If you have a "normal" VIG-xxx license at the central office, you either
have to upgrade you management server OR upgrade to a VEE-U license.

Contact your checkpoint reseller for more information, they should be
able to tell you :)

Good luck,
Pascal de Wild

Loading...