CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-14
Junior Member
 
Join Date: 2007-04-30
Posts: 5
Rep Power: 0
ultraming has an average reputation (10+)
Default Migration from Nokia R62 to SPLAT R65

Hello all,

I am new to this forum. Good forum.

I am planning to milgrate from a pair of Nokia IP530 running NGX R62 to a pair of SPLAT IBM appliance running NGX R65. What is the best way to perform the milgration? Thanks in advance.

ultraming
Reply With Quote
  #2 (permalink)  
Old 2007-08-14
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Milgration from Nokia R62 to SPLAT R65

Where is the SmartCenter? If it's not on the firewalls, it'll go easy. Upgrade the SmartCenter first. Build up each gateway complete with interface and routing configuration. Swap them out physically. You probably won't be able to establish SIC until you clear the ARP tables on the devices the old gateway was connected to, or just wait awhile. Establish SIC, push policy and away you go.

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-08-14
Junior Member
 
Join Date: 2007-04-30
Posts: 5
Rep Power: 0
ultraming has an average reputation (10+)
Default Re: Milgration from Nokia R62 to SPLAT R65

The SmartCenter is on a separate box. It is already running R65
Reply With Quote
  #4 (permalink)  
Old 2007-08-16
Senior Member
 
Join Date: 2007-06-04
Posts: 1,071
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Milgration from Nokia R62 to SPLAT R65

If already done the SMARTCenter then as Ray says, you just need to build two SPLAT boxes with interfaces and routing.

The thing that you will need to do is change the platform to be SPLAT, and enable ClusterXL on the general properties page of the Cluster Object. This is important as SPLAT does not have any built in HA, like VRRP on the Nokia and requires ClusterXL to provide the functionality.

I think that the topology should survive, so you shouldn't need to worry about that.
Reply With Quote
  #5 (permalink)  
Old 2007-08-16
Senior Member
 
Join Date: 2006-09-26
Posts: 821
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Milgration from Nokia R62 to SPLAT R65

the topology will survive BUT you may have to rename the interface.
For example, in SPLAT, you will have eth0, eth1, eth2, etc... while
in nokia, you will have something like eth-s1p1, eth-s1p2, etc...
so you may have to change it.

in Nokia, when you perform "cpstop;cpstart" on the enforcement
module, NAT will work after. Not so on SPLAT in NGx R61 and R65.
I have no idea why.
Reply With Quote
  #6 (permalink)  
Old 2007-09-20
Junior Member
 
Join Date: 2007-04-30
Posts: 5
Rep Power: 0
ultraming has an average reputation (10+)
Default Re: Migration from Nokia R62 to SPLAT R65

I did an upgrade export / upgrade import. The problem I am having right now is the clustering.

When I do cphaprob state, I got
Cluster Mode: Sync only (OPSEC), and the firewall state is Down.

When I do cphaprob -a if, all of my interfaces show non-sync (non secured)
Warning: Sync will not function since there aren't any sync (secured) interfaces.

How can I correct this? Thanks.

ultraming
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:37.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0