CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-17
BoogyWoogy BoogyWoogy is offline
Junior Member
 
Join Date: 2007-02-20
Posts: 1
Rep Power: 0
BoogyWoogy has an average reputation (10+)
Default DR Questions

Hi, I have some DR questions and I'm hoping to get some insight.

We currently three Nokia's all running NGX R60. One is an IP350 facing the Internet, and the other two are clustered (VRRP) IP380’s in front of production equipment. All three are managed by me using a Provider-1 interface loaded on a machine at a remote location. I RDP to the remote machine, launch P-1, yada, yada, yada. I wasn't involved in the initial setup and don't know much about Provider-1 other than some obvious things. At some point this year, I will be clawing back management of these and I’ll have some questions about that then, but for now my questions are about DR.

In the event of a disaster, or a DR test (one upcoming in August), how do I recover these devices at a DR site? I will have the following hardware waiting for me at the DR site:

• An IP350 with the same memory/CPU and Interfaces as the one in production.
• A single IP380 with the same memory/CPU and Interfaces as the one in production. No plan on recovering the cluster in a DR scenario.


Should I be using a full Nokia backup/restore since I will have same hardware or is rebuilding the Nokia boxes manually and using upgrade_export/import the way to go?

Are there things I should do ahead of time to the production configurations to prepare for this? I’m thinking of things like how do I prepare my management station at the DR site since it won’t be a P-1 station and won’t have the same IP as the P-1 station currently in production.

Will I run into licensing issues after restoring?

Any other insight would be appreciated.
Reply With Quote
  #2 (permalink)  
Old 2007-04-17
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: DR Questions

The Nokia backup/restore works fairly well for the device settings in my experience, but I'll issue this warning: DO NOT restore a Nokia config to a different build of IPSO. If you're not running the exact build of IPSO on the DR equipment, it could cause you serious stress, just when you don't need it. It is my understanding that the Nokia tool is primarily for when you need to replace a box of the same build. I have experienced this abnormal behavior myself not knowing better - it wasn't fun.

Now, understand that this was several builds back (3.8, build ???) so maybe Nokia has fixed this since then. Anyone else feel free to correct if you can varify Nokia has fixed this.

Where is your management? Is it on any of those gateways or do you have a separate box for it? Upgrade_export/import should be fine in any case, but it has been my experience that a separate MGMT server (Win 2003) makes it much easier to do.

1 more note for DR - Make sure that all of your CP installs are at the exact level of your current equipment before starting restores of anything. Apply the HFA before restoring (if it will even work without them).

Licenses will be restored with your database. You may have to 'remove' and then re-attach the licenses again to enforcement gateways. Your SmartCewnter will think that they are already applied following the restore.
__________________
There's no place like 127.0.0.1

Last edited by lammbo; 2007-04-17 at 13:36.
Reply With Quote
  #3 (permalink)  
Old 2007-05-12
NickBrandson NickBrandson is offline
Member
 
Join Date: 2006-12-20
Posts: 83
Rep Power: 2
NickBrandson has an average reputation (10+)
Default Re: DR Questions

Have to stress that you need the exact built & HF on the DR box. Because the DR box will "think" those HF has been applied after the restoration, which is not, and would not allow you to apply the HFA again and it would cause some of the problems.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:28.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0