CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-15
JohnMH JohnMH is offline
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Be careful with NGX-R65

I have two distributed environments

Both management servers upgraded to R65. (enforcement modules all NGX pre R65: NGX-R61 HFA 01, NGX-R60 HFA03 and NGX-R62)
On the first install of policy smartdefense is broken with many non http traffic being blocked with SD anouncing it as "WSE0020001 illegal header format detected: Malformed HTTP version in request"

This does not happen when the enforcement module is at the same release as management R65, tested with one of the gateways.

I had to disable SD for gateway that had policy push and SD broken.

Ticket opened..
I am upgrading all my gateways in the next few days, can't wait for a fix.

Seems the new backward compatibility in R65 is broken for SD.

John
Reply With Quote
  #2 (permalink)  
Old 2007-05-16
ngxadmin ngxadmin is offline
Junior Member
 
Join Date: 2007-03-26
Posts: 24
Rep Power: 0
ngxadmin has an average reputation (10+)
Default Re: Be careful with NGX-R65

Thanks for the insight/caution on R65. I have a similiar environment (distributed/SPLAT/NGX_R62/Sun_V20Z's). I presume your suggesting upgrading the managment and enforcement nodes to R65 prior to any policy push?
Reply With Quote
  #3 (permalink)  
Old 2007-05-17
JohnMH JohnMH is offline
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Re: Be careful with NGX-R65

That is what allows smartdefense to keep working in my setup.

John
Reply With Quote
  #4 (permalink)  
Old 2007-05-18
ngxadmin ngxadmin is offline
Junior Member
 
Join Date: 2007-03-26
Posts: 24
Rep Power: 0
ngxadmin has an average reputation (10+)
Default Re: Be careful with NGX-R65

End result, you upgraded your nodes, reenalbled Smartdefense and alls well?
Reply With Quote
  #5 (permalink)  
Old 2007-05-19
JohnMH JohnMH is offline
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Re: Be careful with NGX-R65

Yes, I am still in the process of upgrading.

The ones I upgraded smartdefense works fine. The ones that have not been upgraded yet I have to disable smartdefense or it blocks non http traffic complaining about it does not have proper http headers.

Since it is not http it shouldn't have http headers..

John
Reply With Quote
  #6 (permalink)  
Old 2007-05-19
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Be careful with NGX-R65

Actually, I would suggest one be careful with any/all versions...

The rule of thumb repeated by some of the experts at the CPUG 2007 conference in Las Vegas is:

You always want to stay one or two minor versions behind the latest and greatest, *unless* you have a genuine need (i.e. it includes a fix that you absolutely need). Make sure there's a good reason for the sanguine pain that accompanies the delights of bleeding edge.

There are always exceptions, and a rule like this should never replace judicious cost/benefit analysis. I would also add that sometimes it's tempting to upgrade to get some new whiz-bang feature. But, the new features should be weighed against the risk.
Reply With Quote
  #7 (permalink)  
Old 2007-05-20
JohnMH JohnMH is offline
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Re: Be careful with NGX-R65

It seems this is related to ClusterXL
Any box I have NG-R65 and Cluster XL (windows or SPLAT) Smartdefense is blocking things (things other than HTTP) with "WSE0020001 illegal header format detected: Malformed HTTP version in request". The only work around for now is disable smartdefense.

John

I understand what you are saying about staying one or two minor releases behind, but with the way hotfixes are not coming out equally for each release it doesn't leave much choice. (I am speaking about voice fixes and hotfixes for R60-R61-R62) The scheme until recently hasn't supported distributed environments very well. You couldn't apply a hotfix for R61 on a R62 management box, meaning the R61 hotfix you need to apply on the enforcement point wouldn't mean much (for things that need .def file replacement). Also, when you only have very limited times for upgrade/patch it pays to stay at the more recent releases.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:09.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0