Re: Upgrading from R55 to R60 - a few notes More from the front: I've decided to build a new FW, R55, on another system. I'll import the backup from the old system. That way I'll have a backup FW ready when I try to revert the production server ... if the PF really is corrupt I'm afraid it may not come online again. After moving the traffic to the new FW maybe it will be a good time to build a brand new policy. It's about 5 or more years old and is been part of a few upgrades. Anyone else had a possibly corrupt policy before? Any one else start over from scratch? And are we the only ones still using static manual nats and traditional mode VPN config? Andrew |