CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-23
Junior Member
 
Join Date: 2006-05-30
Posts: 10
Rep Power: 0
bpreston has an average reputation (10+)
Default FP3 IPSO 3.6 upgrade

Hi

I have a single IP330 IPSO 3.6 Checkpoint FP3. I want to bring this more up to date so my plan is this.

Create a new management station
apply a new ipso
add checkpoint wrapper
configure the firewall policy

Will the fw export work between FP3 and NGX and will I need to upgrade the licence in Checkpiont user centre? Any advice on this?

I am planning no using IPSO 3.9 build 56 and Checkpoint NGR60 with a Windows management box on R61. I would apply all relevant HFAs. I don't normally like the latest a greatest builds I would rather use someing with HFA available etc. Having said that any advice on would be welcome.

Thanks Ben.
Reply With Quote
  #2 (permalink)  
Old 2007-02-23
Member
 
Join Date: 2005-09-08
Location: England
Posts: 37
Rep Power: 0
thefunkygibbon has an average reputation (10+)
Send a message via MSN to thefunkygibbon
Default Re: FP3 IPSO 3.6 upgrade

1) you could just use management on-box you know
2) why are you using different versions on management to gateway?
3) you will need to upgrade your license from within your user center.. its pretty straight forward, but you'll need a valid support/software subs to be able to do it.
4) unless you have an absolutely hideous rule base (and lets be honest, if you are on a single ip330 with on box management its doubtful you do) then i would really suggest you just recreate all your rules and objects. shouldnt take that long to do.
you could just do an upgrade export/import but doing so in my experience usually comes up with problems somewhere down the line when going from one version to another.
Reply With Quote
  #3 (permalink)  
Old 2007-02-23
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: FP3 IPSO 3.6 upgrade

Are you splitting the management away from the enforcement module? I'm not clear on this point.

The upgrade_export utility should work fine for you.

IPSO 3.9 is at build 65 as of yesterday.

Yes, you need to generate NGX licenses OR run on a 15-day eval license first.

Ray
Reply With Quote
  #4 (permalink)  
Old 2007-02-26
Junior Member
 
Join Date: 2006-05-30
Posts: 10
Rep Power: 0
bpreston has an average reputation (10+)
Default Re: FP3 IPSO 3.6 upgrade

Hi

I will run matching versions of NGX on the fw and management console, my mistake on explaining that.

I could use my old management station but I am not sure how to accociate it with the upgraded FW?

I wanted the management station seperate to the enforcement module so if the FW is replaced I just need to establish SIC and push the policy from what I have read.

What I also meant was is ipso 3.9 with NGX R60 a good combination on an ip330 with 256mb ram. The rule base is small and simple.

Is the licence upgrade purley a paper excercise int eh user centre it wont affect my current FW as I have tose lics backed up any way in notepad.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:07.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0