CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-05
Junior Member
 
Join Date: 2006-10-16
Posts: 23
Rep Power: 0
buulam has an average reputation (10+)
Default Migrating gateways (R62 splat -> R62 splat)

Hello,

For various reasons, I need to migrate my R62 splat gateway to another server. I plan to use upgrade_export/import and cut over one evening. I'll use the same sysconfig everywhere possible.

My question is with regards to VPN. With this method, shouldn't the certificate be moved over? I want to avoid having the users re-create their VPN site. When I migrated from R55 standalone to R62 distributed, my users all had to re-create their VPN site, which became a pain because I had to do most of this work.

Many thanks
Reply With Quote
  #2 (permalink)  
Old 2007-02-05
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Re: Migrating gateways (R62 splat -> R62 splat)

In a distributed environment.

If you are just upgrading hardware for enforcement points (replacement: IPs names the same) then nothing changes. Nobody will know anything changed but you, except for the downtime.

I have swapped out hardware many times this way, but you don't need upgrade_export for enforcement points. All you need is the TFTP backup file restored to the replacement hardware.

I just replaced two management servers (distributed environment, one 3 days ago and one tonight) and used upgrade export upgrade import with no problems. Maybe 20 minute downtime for each.

John
Reply With Quote
  #3 (permalink)  
Old 2007-02-06
Junior Member
 
Join Date: 2006-10-16
Posts: 23
Rep Power: 0
buulam has an average reputation (10+)
Default Re: Migrating gateways (R62 splat -> R62 splat)

Thanks for that John.

The only thing that might change is the interface topology. There will be more NICs but I'm going to try and keep them in the same order.
Reply With Quote
  #4 (permalink)  
Old 2007-02-06
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Re: Migrating gateways (R62 splat -> R62 splat)

Just watch out with SPLAT on enforcement points... I remember someone say the order is determined (SPLAT) by MAC. So with new hardware the interface order physical order of ports may be different.

Just test the box to determine if the ports are the same as the box you will be replacing.

While the new box is disconnected from the network... connect each interface to a standalone switch and see what interface comes up using the console commands.

John
Reply With Quote
  #5 (permalink)  
Old 2007-02-07
Junior Member
 
Join Date: 2006-10-16
Posts: 23
Rep Power: 0
buulam has an average reputation (10+)
Default Re: Migrating gateways (R62 splat -> R62 splat)

If the topology is in a different order, will that make a difference when swapping the gateways? Difference being my concern in the first question, of whether the users will feel the affect or not...

Thanks!
Reply With Quote
  #6 (permalink)  
Old 2007-02-07
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Migrating gateways (R62 splat -> R62 splat)

Which interface assigned to which network doesn't matter to clients only to the anti-spoofing on the gateway itself. All the client cares about is what IP address it talks to and what is in the VPN domain.
Reply With Quote
  #7 (permalink)  
Old 2007-02-07
Junior Member
 
Join Date: 2006-10-16
Posts: 23
Rep Power: 0
buulam has an average reputation (10+)
Default Re: Migrating gateways (R62 splat -> R62 splat)

Thanks Jim.

So do you guys know how I could have avoided the SecureClient reconfiguration when I migrated from R55 standalone -> R62 distributed? I actually used the steps that are on an FAQ on this site. The standalone was turned into the pri. SC server and a new gateway was put into place
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:51.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0