Firewall-1 Licensing Counting Each Interface of Firewall as a Separate Host [Archive] - SpeedGuide.net Broadband Community

View Full Version : Firewall-1 Licensing Counting Each Interface of Firewall as a Separate Host


Will
02-13-08, 01:19 AM
I listed all of the known hosts in our Firewall-1 license with the command:

fw.exe tab -table host_table

This spits back IP addresses coded as an eight digit hex number. (Does
anyone know how to force the output to appear as a normal decimal system
IP?)

In translating these IPs, I was very disappointed to see that Firewall-1 is
counting its own internal interfaces as separate IPs toward the license, in
effect counting one host over and over and over. On a network with 10
subnets, you use up 10 host licenses just with an empty firewall and no
hosts behind it. That doesn't seem like very fair licensing since the
multiple interfaces on the firewall itself hardly constitute different
hosts. Is there any way to change that licensing behavior?

--
Will

Wolfgang Kueter
02-13-08, 06:27 AM
Will wrote:

> In translating these IPs, I was very disappointed to see that Firewall-1
> is counting its own internal interfaces as separate IPs toward the
> license, in effect counting one host over and over and over. [...]

May I kindly ask you to discuss this with Check Point Software Technologies
Ltd. You can find a list if their addresses at

http://www.checkpoint.com/corporate/contact_headquarters.html

Wolfgang