CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-04
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default Hotfix Help!

I'm still learning these Checkpoint firewalls. Here is what I have done:

- Installed NGX R60 on one box, and enabled it as a FW
- Installed NGX R60 (from same CD) and enabled it as SmartCenter

When I do a FW VER -K it says:

This is Check Point VPN-1(TM) & Firewall-1(R) NGX (R60) - Build 458

It says this on both the firewall and the manager. It says nothing about HFA's or Hot Fixes. How do I know if I need an HFA (hotfix)? Do I need one on both the firewall and the manager?
Reply With Quote
  #2 (permalink)  
Old 2007-11-04
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Hotfix Help!

Hi Scrif,

The current hotfix is HFA06 for R60: Check Point Software: VPN-1 Power/UTM HFAs

You ALWAYS install the hotfix on the SmartCenter first, no exceptions.

Look into the upgrade_export utility. You will need to use it to save a copy of your SmartCenter configuration before you install any hotfixes. You can rebuild the entire SmartCenter from that backup.

HTH,

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-11-04
Junior Member
 
Join Date: 2007-06-14
Posts: 26
Rep Power: 0
Scrif has an average reputation (10+)
Default Re: Hotfix Help!

Thanks for the reply. When you say 'you always install on Manager first', does this mean I do install the Hotfix on both devices? Is the Hotfix the same? Or Do I download 2 separate HFA's form CP.com?

Thanks again.
Reply With Quote
  #4 (permalink)  
Old 2007-11-05
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Hotfix Help!

Quote:
Originally Posted by Scrif View Post
Thanks for the reply. When you say 'you always install on Manager first', does this mean I do install the Hotfix on both devices? Is the Hotfix the same? Or Do I download 2 separate HFA's form CP.com?

Thanks again.
depends on the operating system. If you firewall module is on nokia and smartcenter/management windows, then its 2 separate HFA's you download, one for each OS as platform.

If we assume you run secureplatform on both firewall and smartcenter then its the same hotfix you use for both. As mentioned above, always upgrade your smartcenter/management first, before upgrading firewall module. (since higher patch level on management can work with lower versions for firewall modules, not vice versa)
Reply With Quote
  #5 (permalink)  
Old 2007-11-05
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 255
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Hotfix Help!

fw ver; fw stat

is what I always do to check what is installed on a firewall module.

fwm ver

is the command for a smartcenter server (firewall management)
Reply With Quote
  #6 (permalink)  
Old 2007-11-15
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: Hotfix Help!

Hello guys,

I'm going to install last HFA06 on Checkpoint Splat.

scenario:

1 cluster with 2 nodes ( A active B passive )NGX HFA_05
2 MGMT ( management Active + Standby) NGX_HFA_05

ClusterXL : HA NewMode

MGMT-A ---->FwA + FwB
|
MGMT-B----->FwA + FwB

Could you check if sound good for you this procedure under HA New Mode?

1) ./UnixInstallscript on MGMT A + B

2) Node B smartupdate with 3 reboots each for packages installed ( or can I do only one reboot to the end ?)

3) Node A the same of Node B


Is necessary before to start perform "set_ccp broadcast" and when all is ended "cphaconf set_ccp multicast" ? I suppose no because my scenario is with HA New mode so it works with unicast packets.


Thank you
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:04.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0