| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| We have a production Nokia 330 running:- CP FW-1 ver 4.1 SP4 build 41864 IPSO version is 3.4 I know this is pretty ancient but I have taken over from somebody else who never bothered to do any upgrades. My question is what are my best options in getting this to a respectable version say IPSO 4.0 and CP NGX R60, and what are some of the pitfalls I should be aware of? Cheers |
| |||
| Random things: * You might have to do a manual upgrade of the boot manager on your first upgrade from 3.4. Can't remember if it was 3.3 or 3.4 that removed the requirement to manually upgrade the boot manager. * That hardware is unsupported, and has been so for over a year. Your call if you want to keep running it. * It will be slow trying to run 4.0 and R60. Check you have 256MB of RAM, some 330s only had 64MB. If your management is also on the same box, I would probably not upgrade to NGX, it will just be too slow. If it's somewhere else, it might be OK. Note that your management will need to be upgraded to R55, then to NGX. You can't go straight to NGX. Read the release notes. If it was me, I'd be inclined to get some new hardware - either a new Nokia or just chuck in a SPLAT box. Note that you will need to upgrade your licenses, which requires that they are under support. |
| |||
| Hi Northlandboy, Thanks for the info. According to Nokia's website the 330 will only be EOL in 2008. We have a support contract with Vistorm for this kit. Dunno if you have heard of them? My management is on the same box. Wouldn't it be easier to install everything from scratch and re-create the policy objects and Voyager settings? Do you see any major issues with this approach? Thanks again for your help. |
| |||
| Yes, I know Vistorm - used to work with a few guys from there. I'm a little surprised you can still pay for it. Look closer at what you get for your IP330 support - no new IPSO versions will run on it - that's only guaranteed for 3 years after EOS, which was 9/03. That to me means no effective support, since they don't like fixing things on old software versions. You've got a slow box, which is going to struggle even more with NGX. For the amount of money you'll pay for support for the next couple of years (and the value you'll get for it), you would probably be better off putting in a SPLAT box. But anyway, if you've got a relatively simple policy, then yes, completely recreating everything would be a very good strategy - and probably my preferred option. That way you know you've got a pretty clean build, with no nasty stuff hanging around from various upgrades (e.g. xlate dst on client side disabled). Your only issue is doing this quickly, and being able to roll back if you've got problems - if this is your only Nokia box, it can be a little tricky to do. You'll have some downtime, but if you're running a 330, then it's probably not that big a deal for you. One thing to watch out for is doing the IPSO upgrade. If you do a straight upgrade, your box will probably continue to have 256MB of swap. You may need to upgrade it twice, from the bootmanager, to get the newer default of 1GB of swap. Check what you've got with swapinfo - I can't remember if it was 3.3 or 3.4 that changed to a 1GB default. It's caught me out in the past that just doing a normal upgrade, or upgrading only once from bootmanager, leaves it at 256MB swap. Perhaps you could get a loaner 330 from somewhere, and build that up, and see how it performs? Could make swapover easier. Hopefully you've got a slightly newer 330 too. Older ones had a 266MHz proc, newer ones had I think a 400MHz proc. |
![]() |
| Thread Tools | |
| Display Modes | |
| |