View Single Post
  #1 (permalink)  
Old 2007-01-10
devm69 devm69 is offline
Junior Member
 
Join Date: 2006-05-23
Posts: 5
Rep Power: 0
devm69 has an average reputation (10+)
Default Migrating from R55 TO R61

Doing a migration from a r55 standalone windows 2003 to a R61 standalone 2003 which will have a different external Iand internal ip as want to run both side by side to test out prior to moving over. the original although a stanalone is also managing a remote module and has numerous vpn tunnels

Have done below and all seems to go well with no errors

on 1st box,
copy of live ng lics
upgrade_export

on 2 box,

install r61 as new install ( not upgrade) using same ip etc as 1st
after install upgrade_import
edit topology to reflect diff nics
set os etc
push policy
update to latest hfa for r61

edit ip for external
push policy

edit ip for internal
push policy

change online lics to new ips and upgrade to ngx
add via smartupdate
push policy

modify and objects with nat etc from old ip range
reset sic for remote enforcement incase it has issues with 2 live fw's trying to communicate with it.
disabled all vpn tunnels rules, but communities still created.
push policy

issue i have seems to either be nat related or topology based. can ping fw from a laptop on dummy internal net ok. fw can browse web ok. laptop cant access web although im sure i could earlier in install.

Does this seem possible or should i be going down another route.......

things i intend trying are

Windows 2003 hardening done prior to install, remove and leave until after install
install r55 with same ip etc then upgrade to r61
install splat on second box using r61 and import config again
on second box during initial cp install use imported config instead of new install


any opinions would be very helpfull.
Cheers
Reply With Quote