CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-19
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Upgrading from R55 to R62

Dears

i have two IP 710 with IPSO 4.1 and NG R55, i bought two IP 2450 with IPSO 4.2 and CP NGX R 62,
can someone have a checklist on how to migrate from the old boxes to the new one with minimal down time ?

thanks in advance
Reply With Quote
  #2 (permalink)  
Old 2008-01-20
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Upgrading from R55 to R62

Where is the SmartCenter?

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-01-21
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: Upgrading from R55 to R62

Quote:
Originally Posted by RayPesek View Post
Where is the SmartCenter?

Ray
the smartcenter is on a w2k server.
Reply With Quote
  #4 (permalink)  
Old 2008-01-21
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Upgrading from R55 to R62

The SmartCenter is already on R62 or R65, right? It must be on the same or a higher version of the firewalls.

Since the firewalls are on different versions of IPSO you can't use Nokia's backup and restore functions. Your best bet is to print off the System Configuration page from Voyager on the existing one and use it to manually configure the new one. Be certain to make the interfaces the same.

Once the new one is built up, print off its configuration and compare the two.

Build up a test SmartCenter on an old desktop using SPLAT. Use upgrade_export on the real SmartCenter to create a backup. Import it into the test SmartCenter with upgrade_import. Connect the test SmartCenter to the new firewall with a router or something to handle the different subnets (assuming the SmartCenter is on a different subnet than the internal interface of the firewall).

Establish SIC and do some test policy pushes. Once you're sure it's good, reset SIC on the firewall. It now has the current firewall policy and is ready to have SIC established with the real SmartCenter.

When you go to swap them out, remember you'll probably have a problem with ARP caching on the devices connected directly to the existing firewall. If you don't know how to flush their ARP caches, just reboot them. If you just let the ARP caches expire, you could have fifteen minutes or more of no traffic. Since the firewalls already have a policy that's very close to the current one, they should just start to work. Note: Certificate-based site-to-site VPNs may not start up until the SmartCenter comes online.

Establish SIC with the real firewall and check the gateway properties for FW-1 and OS versions.

Ray
Reply With Quote
  #5 (permalink)  
Old 2008-01-21
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: Upgrading from R55 to R62

Quote:
Originally Posted by RayPesek View Post
The SmartCenter is already on R62 or R65, right? It must be on the same or a higher version of the firewalls.

Since the firewalls are on different versions of IPSO you can't use Nokia's backup and restore functions. Your best bet is to print off the System Configuration page from Voyager on the existing one and use it to manually configure the new one. Be certain to make the interfaces the same.

Once the new one is built up, print off its configuration and compare the two.

Build up a test SmartCenter on an old desktop using SPLAT. Use upgrade_export on the real SmartCenter to create a backup. Import it into the test SmartCenter with upgrade_import. Connect the test SmartCenter to the new firewall with a router or something to handle the different subnets (assuming the SmartCenter is on a different subnet than the internal interface of the firewall).

Establish SIC and do some test policy pushes. Once you're sure it's good, reset SIC on the firewall. It now has the current firewall policy and is ready to have SIC established with the real SmartCenter.

When you go to swap them out, remember you'll probably have a problem with ARP caching on the devices connected directly to the existing firewall. If you don't know how to flush their ARP caches, just reboot them. If you just let the ARP caches expire, you could have fifteen minutes or more of no traffic. Since the firewalls already have a policy that's very close to the current one, they should just start to work. Note: Certificate-based site-to-site VPNs may not start up until the SmartCenter comes online.

Establish SIC with the real firewall and check the gateway properties for FW-1 and OS versions.

Ray
thanks ray for the information,

actually the smartcenter is on R55, but for sure i will make a temporary one , install the R62 or 65 and then switch to a permanent one
Reply With Quote
  #6 (permalink)  
Old 2008-01-22
Junior Member
 
Join Date: 2006-10-26
Posts: 9
Rep Power: 0
bolingoman has an average reputation (10+)
Default Re: Upgrading from R55 to R62

Hi,

I'd suggest upgrading to any NGX other than R62. From experience, it's the least stable version of all NGX family. Remember, you'll one day be obliged to change the version as there is no HFA / patch availble for R62.

so, go for R65 or R60.
Reply With Quote
  #7 (permalink)  
Old 2008-01-22
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: Upgrading from R55 to R62

I've heard about more issues with R65 than any other R6x version.

I have a couple of my Nokia's on R62, and have had no problems as of yet.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:10.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0