CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-04
pjscott13 pjscott13 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 19
Rep Power: 0
pjscott13 has an average reputation (10+)
Default VPN-1 Edge X Firmware Upgrade

Hi All,

I have realised that our Checkpoint device is extremely out of date and have a few questions in regards to upgrading the Device.

We have a VPN-1 Edge X Device with Embedded NGX running Firmware 6.0.57x. Hardware Type is SBox-200 and Hardware Version is 1.0T.

We have just renewed our Software Subscription with Checkpoint and I notice that there are much newer firmware available. We are also having some issues with a particular VPN tunnel that I believe VPN-1/FireWall-1 NG FP3 HF2 will fix. I logged a case with Checkpoint support nearly 2 weeks ago and the response has been extremely poor so I am hoping I might get a faster response here.

Can I upgrade to 6.5 or 7.0 or do I need to stay in the 6.0 range of firmware? I believe the latest is 6.0.83x. Also, how do I install this FP3 HF2?

I have never upgraded the firmware on a checkpoint device. I assume it is relatively painless and everything should work fine afterwards. Is there something I should prepare myself for before doing the upgrade?

Thanks for all your help!
Reply With Quote
  #2 (permalink)  
Old 2007-06-04
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 875
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

NG FP3 went off support on June 1, 2007. Check Point will not help you with anything that is end of life.

Check Point Software: Check Point Products and Enterprise Support Periods

Versions of the SmartCenter prior to R55 required a SofaWare Connector add-on to be manually installed in order to manage an Edge device. If you don't have it installed, you can use any Edge firmware you want because it will be considered an Interoperable Device, not a managed firewall.

It is painless and just works. Usually. Occasionally you have to do it twice in a row for it to take for some reason.

HTH,

Ray

Last edited by RayPesek; 2007-06-04 at 16:30.
Reply With Quote
  #3 (permalink)  
Old 2007-06-04
pjscott13 pjscott13 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 19
Rep Power: 0
pjscott13 has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

ok. I'm still a bit confused! Looking at the link, the FP3 is not part of our device... it belongs to the Provider-1 device. So I am guessing the Checkpoint article I found is out of date.

Next, I see all these articles etc refer to R60, R61 etc etc. I don't understand what this means. How do I know what Rxx version I am running? All I know is that our firmware is 6.0.57x.

You say that I could upgrade to version 7.0 if I wanted to? And it should all work fine?

Next question is, that we have some Safe@Office devices connect via VPN and a few odd users connect via SecureRemote. If I upgraded the firmware would this cause problems with them until they were upgraded also?

Thanks for your help!
Reply With Quote
  #4 (permalink)  
Old 2007-06-05
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: VPN-1 Edge X Firmware Upgrade

You will need to perform an upgrade of the libsw on the Provider-1 environment and the firmware on the sofaware box itself. The libsw files are constantly updated with new protections etc and are always backwards compatible, ie 7.0 libsw will work with 5.0 firmware etc, however version 7.0 firmware wont work with a 5.0 libsw.

Download the latest available libsw from: https://downloads.checkpoint.com/dc/...&os=&x=12&y=12.

Login to your Provider-1 MDS and copy the libsw*.tar file to somewhere where you can access it.

cd to the libsw location. For example if your CMA is called CMA1
$MDSDIR/customers/CMA1/CPfwbc-41/libsw

Stop your CMA

Backup the contents of this directory.

Untar the libsw*.tar file into this directory and check that version.txt contains the correct version number.

Check Point also recommend doing a "Dos2Unix *" on all the files in this directory if you are running on Solaris or Secureplatform.

If your Provider-1 environment is earlier than NGAI R55 with HFA17, you need to modify the $MDSDIR/customers/CMA1/CPfwbc-41/libsw/SofawareLoader.ini

vi the file and change the PolicyUpdateVersion to 505 (for version 7.0 firmware) or 405 (for version 6.5) or 305 (for version 6.0).

Start your CMA.

Next update the firmware. The latest firmware can also be downloaded from the link above. Download it to your local hard disk.

Login to the sofaware box and click on Setup > Firmware > Firmware Update.
  1. Click Browse... and select the new firmware file.
  2. Click Upload
The Sofaware Appliance will upload the firmware and reboot.

Push policy to test. Verify that the policy name in the Setup>Tools>Diagnostics page of the VPN-1 Edge gateway is the same as created in SmartDashboard. In addition, make sure the policy's date is correct.

Job done :)
Reply With Quote
  #5 (permalink)  
Old 2007-06-05
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 554
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: VPN-1 Edge X Firmware Upgrade

Quote:
Originally Posted by pjscott13 View Post
I logged a case with Checkpoint support nearly 2 weeks ago and the response has been extremely poor so I am hoping I might get a faster response here.
Welcome to our world.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #6 (permalink)  
Old 2007-06-05
pjscott13 pjscott13 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 19
Rep Power: 0
pjscott13 has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

Quote:
Originally Posted by munrog View Post
You will need to perform an upgrade of the libsw on the Provider-1 environment and the firmware on the sofaware box itself. The libsw files are constantly updated with new protections etc and are always backwards compatible, ie 7.0 libsw will work with 5.0 firmware etc, however version 7.0 firmware wont work with a 5.0 libsw.

Download the latest available libsw from: https://downloads.checkpoint.com/dc/...&os=&x=12&y=12.

Login to your Provider-1 MDS and copy the libsw*.tar file to somewhere where you can access it.

cd to the libsw location. For example if your CMA is called CMA1
$MDSDIR/customers/CMA1/CPfwbc-41/libsw

Stop your CMA

Backup the contents of this directory.

Untar the libsw*.tar file into this directory and check that version.txt contains the correct version number.

Check Point also recommend doing a "Dos2Unix *" on all the files in this directory if you are running on Solaris or Secureplatform.

If your Provider-1 environment is earlier than NGAI R55 with HFA17, you need to modify the $MDSDIR/customers/CMA1/CPfwbc-41/libsw/SofawareLoader.ini

vi the file and change the PolicyUpdateVersion to 505 (for version 7.0 firmware) or 405 (for version 6.5) or 305 (for version 6.0).

Start your CMA.

Next update the firmware. The latest firmware can also be downloaded from the link above. Download it to your local hard disk.

Login to the sofaware box and click on Setup > Firmware > Firmware Update.
  1. Click Browse... and select the new firmware file.
  2. Click Upload
The Sofaware Appliance will upload the firmware and reboot.

Push policy to test. Verify that the policy name in the Setup>Tools>Diagnostics page of the VPN-1 Edge gateway is the same as created in SmartDashboard. In addition, make sure the policy's date is correct.

Job done :)
I think I am even more confused now!

How do I login to my Provider-1 MDS? Do I use the command on the sofaware box? All we have is the sofaware box. Blue in colour. All the administration we have done on it is via the web interface. So I am confident in doing the firmware update of the sofaware box using the Setup > Firmware > Firmware Update bit. But I am totally lost with the libsw stuff. Can you please clarify?
Reply With Quote
  #7 (permalink)  
Old 2007-06-05
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: VPN-1 Edge X Firmware Upgrade

Sorry I read the part of your link which said "I'm still a bit confused! Looking at the link, the FP3 is not part of our device... it belongs to the Provider-1 device." and from that understood that you were using Edge/Sofaware managed by Provider-1.

To upgrade your embedded firewall, you simply install the latest firmware:

Download the firmware from from:
https://downloads.checkpoint.com/dc/...&os=&x=12&y=12.

to your local hard disk.

Login to the sofaware box and click on Setup > Firmware > Firmware Update.
  1. Click Browse... and select the new firmware file.
  2. Click Upload
The Sofaware Appliance will upload the firmware and reboot.

Greg
Reply With Quote
  #8 (permalink)  
Old 2007-06-06
pjscott13 pjscott13 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 19
Rep Power: 0
pjscott13 has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

Phew!

I was hoping it would be that easy! My only concern is making sure everything works once it is upgraded from 6.0.57 to 7.0.39.

Should I maybe upgrade in gradual steps instead?
Reply With Quote
  #9 (permalink)  
Old 2007-06-06
jkeffer jkeffer is offline
Junior Member
 
Join Date: 2007-03-11
Location: Atlanta
Posts: 1
Rep Power: 0
jkeffer has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

Use the backup utility for your current configuration, document your settings and then perform the firmware upgrade.
__________________
Joe Keffer
PM, CCSA
Luminare Technologies, Inc
404-644-1939
Reply With Quote
  #10 (permalink)  
Old 2007-06-07
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 875
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

You shouldn't have any issues going right to 7.0.39. I took three Edge X's from 6.0.something straight to 7.0.33 without any problems.

Ray
Reply With Quote
  #11 (permalink)  
Old 2007-06-12
ascssmith ascssmith is offline
Member
 
Join Date: 2006-03-20
Posts: 32
Rep Power: 0
ascssmith has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

anybody try upgrading the firmware for the adsl modem on the xg32-adsl device?

I've upgraded libsw on mgnmt and device to 7.0.39, then tried to upgrade modem firmware to SW2.0.6ab_pri.firm, which i got from CP. But it fails every time: INTERNAL ERROR... nothing more???

AL
Reply With Quote
  #12 (permalink)  
Old 2007-06-13
ascssmith ascssmith is offline
Member
 
Join Date: 2006-03-20
Posts: 32
Rep Power: 0
ascssmith has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

found out after working with sofaware techs, CP's version is not valid. they sent me the correct firmware. have tried to zip it and upload, no go. i guess it's too big..

AL

Last edited by ascssmith; 2007-06-28 at 05:32.
Reply With Quote
  #13 (permalink)  
Old 2007-06-19
efdsa efdsa is offline
Junior Member
 
Join Date: 2006-06-13
Location: Netherlands
Posts: 26
Rep Power: 0
efdsa has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

Don't understand why you can't download the working version from sofaware support site.
Reply With Quote
  #14 (permalink)  
Old 2007-06-19
ascssmith ascssmith is offline
Member
 
Join Date: 2006-03-20
Posts: 32
Rep Power: 0
ascssmith has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

Don't know either, i think it has to do with "checkpoint" is supposed to handle this. As all edge devices that are managed by FW-1 are CP's responsibility.

I had opened a ticket with CP, and when they finally contacted me, i filled them in and sent them the (2) versions for them to put on their website...

AL
Reply With Quote
  #15 (permalink)  
Old 2007-07-01
efdsa efdsa is offline
Junior Member
 
Join Date: 2006-06-13
Location: Netherlands
Posts: 26
Rep Power: 0
efdsa has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

According to sofaware, there is nothing wrong with the ADSL firmware upgrade on the checkpoint site. I still get this internal error. Anyone got this working?
Reply With Quote
  #16 (permalink)  
Old 2007-07-01
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: VPN-1 Edge X Firmware Upgrade

Check the Annex Version of the DSL hardware. Usually it is Annex A or Annex C. If you are trying to load up the DSL firmware for Annex A on Annex C it will produce this error.
Hope this helps
Greg
Reply With Quote
  #17 (permalink)  
Old 2007-07-01
efdsa efdsa is offline
Junior Member
 
Join Date: 2006-06-13
Location: Netherlands
Posts: 26
Rep Power: 0
efdsa has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

Thanks Munrog, but there is only one upgrade on the checkpoint site for ADSL. Annexes are not mentioned. (A or B).
Reply With Quote
  #18 (permalink)  
Old 2007-07-03
ascssmith ascssmith is offline
Member
 
Join Date: 2006-03-20
Posts: 32
Rep Power: 0
ascssmith has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

send me a PM with your email and I'll email you the version you need. as CP's version is bad. a = dsl, b = isdn..

AL
Reply With Quote
  #19 (permalink)  
Old 2007-07-05
efdsa efdsa is offline
Junior Member
 
Join Date: 2006-06-13
Location: Netherlands
Posts: 26
Rep Power: 0
efdsa has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

Thanks all for offering the right versions. One of the packages indeed work, however when I wanted to upgrade another Edge I received the same error again. Weird.
Reply With Quote
  #20 (permalink)  
Old 2007-07-06
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: VPN-1 Edge X Firmware Upgrade

Idd thx for the package, but strangly I only needed this for one edge device.
The 5 others accepted the package that I downloaded from the CheckPoint site. Those where 6 equal edges, DSL annex A etc ...

strang thing ... ;)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:03.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0