CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-15
Junior Member
 
Join Date: 2006-11-15
Posts: 2
Rep Power: 0
Screemingblue has an average reputation (10+)
Default Nokia 330 IPSO 3.4 upgrade question

We have a production Nokia 330 running:-
CP FW-1 ver 4.1 SP4 build 41864
IPSO version is 3.4

I know this is pretty ancient but I have taken over from somebody else who never bothered to do any upgrades.
My question is what are my best options in getting this to a respectable version say IPSO 4.0 and CP NGX R60, and what are some of the pitfalls I should be aware of?

Cheers
Reply With Quote
  #2 (permalink)  
Old 2006-11-15
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 853
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Nokia 330 IPSO 3.4 upgrade question

Random things:
* You might have to do a manual upgrade of the boot manager on your first upgrade from 3.4. Can't remember if it was 3.3 or 3.4 that removed the requirement to manually upgrade the boot manager.
* That hardware is unsupported, and has been so for over a year. Your call if you want to keep running it.
* It will be slow trying to run 4.0 and R60. Check you have 256MB of RAM, some 330s only had 64MB.

If your management is also on the same box, I would probably not upgrade to NGX, it will just be too slow. If it's somewhere else, it might be OK. Note that your management will need to be upgraded to R55, then to NGX. You can't go straight to NGX. Read the release notes.

If it was me, I'd be inclined to get some new hardware - either a new Nokia or just chuck in a SPLAT box.

Note that you will need to upgrade your licenses, which requires that they are under support.
Reply With Quote
  #3 (permalink)  
Old 2006-11-16
Junior Member
 
Join Date: 2006-11-15
Posts: 2
Rep Power: 0
Screemingblue has an average reputation (10+)
Default Re: Nokia 330 IPSO 3.4 upgrade question

Hi Northlandboy,

Thanks for the info.
According to Nokia's website the 330 will only be EOL in 2008. We have a support contract with Vistorm for this kit. Dunno if you have heard of them?

My management is on the same box. Wouldn't it be easier to install everything from scratch and re-create the policy objects and Voyager settings? Do you see any major issues with this approach?

Thanks again for your help.
Reply With Quote
  #4 (permalink)  
Old 2006-11-16
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 853
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Nokia 330 IPSO 3.4 upgrade question

Yes, I know Vistorm - used to work with a few guys from there.

I'm a little surprised you can still pay for it. Look closer at what you get for your IP330 support - no new IPSO versions will run on it - that's only guaranteed for 3 years after EOS, which was 9/03. That to me means no effective support, since they don't like fixing things on old software versions.

You've got a slow box, which is going to struggle even more with NGX.

For the amount of money you'll pay for support for the next couple of years (and the value you'll get for it), you would probably be better off putting in a SPLAT box.

But anyway, if you've got a relatively simple policy, then yes, completely recreating everything would be a very good strategy - and probably my preferred option. That way you know you've got a pretty clean build, with no nasty stuff hanging around from various upgrades (e.g. xlate dst on client side disabled).

Your only issue is doing this quickly, and being able to roll back if you've got problems - if this is your only Nokia box, it can be a little tricky to do. You'll have some downtime, but if you're running a 330, then it's probably not that big a deal for you.

One thing to watch out for is doing the IPSO upgrade. If you do a straight upgrade, your box will probably continue to have 256MB of swap. You may need to upgrade it twice, from the bootmanager, to get the newer default of 1GB of swap. Check what you've got with swapinfo - I can't remember if it was 3.3 or 3.4 that changed to a 1GB default. It's caught me out in the past that just doing a normal upgrade, or upgrading only once from bootmanager, leaves it at 256MB swap.

Perhaps you could get a loaner 330 from somewhere, and build that up, and see how it performs? Could make swapover easier.

Hopefully you've got a slightly newer 330 too. Older ones had a 266MHz proc, newer ones had I think a 400MHz proc.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:44.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0