CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-02
Junior Member
 
Join Date: 2006-06-12
Posts: 11
Rep Power: 0
raggy has an average reputation (10+)
Default R55 to R62 Upgrade Help

Im currently running.

Nokia IPSO 3.9 on 2 firewalls using VRRP and R55
Management is SPLAT also on R55

We have decided to make the move to NGX so i attempted the management upgrade 1st. (using new hardware)

Basically this is what i did:

Upgrade_Export original box.
Build new box from scratch to R55 with same hostname and ip address and apply same HFA as original.
Upgrade_Import my exported config.
connect to new box and everything worked great.
On new box do a patch add cd using original R62 disc and everything completed successfully.
Attach NGX licences using SmartUpdate.
Connect to dashboard and push policy.

This is where I had my 2 problems.

1) Nothing was being logged.
2) None of my site to site VPN's would connect (mixture of edge devices and cisco interoperable devices).

I have been through every SK for the logging issue i could find. I have even re-established SIC.

Just wondered if im missing something here. Any help or ideas would be most welcome!

TIA
Reply With Quote
  #2 (permalink)  
Old 2007-04-02
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: R55 to R62 Upgrade Help

Well the first step would be to try to identify why the log functionality isn't working. Can you verify that logs are being sent to the managment server w/fw monitor or tcpdump?

If the logs are being received but not recorded then there could be issues w/files (or directories) in $FWDIR/log--did you do any of the procedures in the SK's that referred to cleaning out that directory?

If the logs are not being sent: Does the new management server use the same IP as the old server? If it's not using the same IP, have you tried updating each object's log master and log server? If it's using the same IP, are you able to route to it from other hosts / does the switch's arp tables only have the "new" MAC addr?

Can you give the output of this splat command on the management server: "fw unloadlocal"?
Reply With Quote
  #3 (permalink)  
Old 2007-04-03
Junior Member
 
Join Date: 2006-06-12
Posts: 11
Rep Power: 0
raggy has an average reputation (10+)
Default Re: R55 to R62 Upgrade Help

Thanks for the reply.

I did clean out the /log directory as the SK suggested but it didnt work.

I will attempt your questions this coming weekend as I have to do any work out of business hours.
One thing i did try was a telnet on port 257 from the firewall to the management and i was getting no response. I understood this should have been opened by implied rules? Anyway i added the rule manually but still no response.
The ip address is exactly the same but obviously the mac address will be different. Could that really be an issue?
Reply With Quote
  #4 (permalink)  
Old 2007-04-04
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: R55 to R62 Upgrade Help

Quote:
Originally Posted by raggy View Post
One thing i did try was a telnet on port 257 from the firewall to the management and i was getting no response. I understood this should have been opened by implied rules?
You have Telnet? Ah to be running IPSO... Did you see the corresponding log entry for your telnet attempt? For this, I would turn on implied logging (Policy -> Global Properties -> Firewall -> Implied checkbox at bottom) and see if you get any additional info. Running "netstat -an" would also show if someone's connected at least too.

Quote:
Originally Posted by raggy View Post
Anyway i added the rule manually but still no response.
The ip address is exactly the same but obviously the mac address will be different. Could that really be an issue?
I was more concerned for short-term as I've seen cisco retain MAC arp data for longer then necessary. I don't think its an issue if the old server is no longer running. Especially if you can route to the new server from internal / connect with smart center etc.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:30.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0