How to See a List of Hosts that Firewall-1 is Using in License?

Dec 19, 2006 3 Replies

With older versions of Firewall-1, is there a way to get a list of the IP addresses that Firewall-1 sees on the internal network that it is counting towards your license?



If the internal network is a class C network, will Firewall-1 count IPs on different class networks that are on the same ethernet?


"fw lichosts" See also #sk10200 in the Check Point knowledgebase.

Br. Robby

This command spits out human readable text for years worth of traffic on that firewall. It's not even in a form of unique IPs, but seems to create summary information for each unique IP encountered in a given time period.

Is there any way to get just a list of unique IPs without having to crawl through a 300K file?

What is the relevant time period that FW1 looks at for counting the number of unique IPs? Is it the last 24 hours, last hour, etc?

"fw lichosts" gives a detailed overview. For a more brief summary try: # fw tab -t host_table (eventually with the -f flag, "fw tab -t host_table -f") or # fw tab -t host_table -s PEAK is the maximum nr of host since the host_table was cleared

Since the last time the host_table was cleared.

Search the Check Point kb for sk10200. This article deals with license issues.

Br. Robby

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required