CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-06
Junior Member
 
Join Date: 2007-04-16
Posts: 1
Rep Power: 0
ideasunlmtd has an average reputation (10+)
Default migration of IP530 to IP560.

We are in the process of the migration of the F/W (Nokia) box from IP 530 to IP 560.



Activity



1) Need to migrate the F/W (Nokia) box from IP 530 to IP 560.

2) The existing configuration has to be uploaded to IP 560.

3) New management server has to be configured with NGX R60 (The existing SC is R55).

4) The Existing R55 configuration has to be uploaded to the new SC.



We have installed new SC with R60 and the R55 configuration has been uploaded successfully.

Installed the R60 Rapper in Nokia IP560 and the configuration has been uploaded successfully. The interface and the VRRP (Legacy, monitoring circuit) have been reconfigured as the physical interfaces for both IP560 and IP530 are different. In checkpoint SC both the gateways are the member of the Nokia cluster.



We are able to establish the SIC between SC and both the gateways (Even we are able to access the Voyager from SC). While pushing the policy (the local Default filters in both gateways are removed) for 1 F/W we are getting the error as Installation failed, Reason: Load on module failed remote connection closed (Kindly find the attachment). For the other F/W we are able to push the policy.



When we try to fetch the policy from the F/W it gives the error the error “SIC name doesn’t match-policy fetch failed”. The patches installed were VPN-1 Pro NGX R60 in both SC and the gateway. We have installed the HFA” VPN-1_R60_HFA_05_wrapper.ipso” in both the gateways (this is not installed in SC as this is giving some problem while installing)



As per some forum it was told to check the Policy Name/DB version/ Special characters has been taken care ( We have tried to install a new policy which has Implied rule and an any to any allowed rule) But still the error continues.



We have tried to install the HFA vpn1_HOTFIX1_R60_ipso in Gateways which says the SIS issue will be resolved but on nokia we are not able to install the same (We are able to install the same in windows). We have installed the demo mode for all these activity and now 7 more days to go in same setup.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:26.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0