| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi all I have a pair of High Availability Management servers running XP and R55. I also have 6 seperate Nokia IP530 enforcement points, running R55 also. I need to upgrade, so I'm heading for R61 at the minute. Is the following plan sound ? 1) SYNC the HA management servers, then run an upgrade-export of the config - just in case ! 2) powerdown the backup management server (might need it later if I struggle) 3) add all my NGX licences to the repositry, this will automatically attach the management server licences to the management server, and the enforcement point licences will sit waiting for another day 4) check I can still push a policy. 5) do an upgrade to the management server to NGX R61 6) test I can still use "backward compatability" to administer my R55 Nokia Enforcement Points... Do the logs work ? Then , at a later date I can shut down the primary management server, bring up the old R55 secondary management server, then upgrade that (with no licences needed) to R61, then bring them both up and sync them - which will take the more up to date primary server rules and sync them to the secondary server...? Then, at a later date again , I can visit each Nokia and 1) turn off the firewall packages (retaining the IPSO interface settings 2) upgrade to IPSO 4.1 3) add NGX R61 packages 4) push the NGX licence to that Nokia 5) push the policy back to the nokias... Any good - is there a better way ?? Many Thanks, Rob |
![]() |
| Thread Tools | |
| Display Modes | |
| |