CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-08
ChrisA ChrisA is offline
Senior Member
 
Join Date: 2006-02-18
Posts: 101
Rep Power: 3
ChrisA has an average reputation (10+)
Default Upgrade R60 to R62 - no lea, no https to mgtstn

We upgraded our SPLat management station and our two clustered (VRRP) Nokias from R60 HFA04 to R62. Now, we can't do https to our management station. I tried "webui enable 443" and it looked successful, but I still get "Page cannot be displayed". I also see FW1_lea from our external logging device to the management station but no data is being retrieved. Any ideas what the problem could be or where I can look? We can open SmartDashboard/SmartView Tracker but can't https, so it isn't a connectivity issue. Also, from our logging device we can ping and traceroute to the management station. Thanks for your help/advice.
Reply With Quote
  #2 (permalink)  
Old 2007-05-14
ChrisA ChrisA is offline
Senior Member
 
Join Date: 2006-02-18
Posts: 101
Rep Power: 3
ChrisA has an average reputation (10+)
Default Re: Upgrade R60 to R62 - no lea, no https to mgtstn

This problem is resolved.
The management station originally had one default gateway pointing to the primary Nokia firewall. During the upgrade, the primary was down and the secondary was up on the new release. We couldn't access the management station in this scenario, so the vendor doing the upgrade added a second default gateway pointing to the secondary Nokia. This worked fine until the primary Nokia was upgraded and brought back online. I'm guessing we had an asymmetric routing issue where we'd connect through the primary Nokia to the mgt stn, but the mgt stn would try to route back through the secondary Nokia. When the vendor removed the second default gw, everything worked again.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:20.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0