CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-16
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default moving to NGX : two questions

Hi,

I'am fairly new to NGX en checkpoint installations, I only have experience in administrating checkpoint. But now I have to do my first installation.

We're moving from CP NG on Nokia to NGX SPLAT.
So maybe someone can help me with these questions:

1) How can I export the rulebase from the Nokia and import in the new NGX installation.

2) What is an easy way to upgrade the NG license to NGX

Cheers,
Reply With Quote
  #2 (permalink)  
Old 2005-12-16
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: moving to NGX : two questions

Look for the upgrade_export command on your management station. This can be used to save all of your checkpoint information.

As for the license, you can get that upgraded at the CheckPoint usercenter (usercenter.checkpoint.com) or I belive there may be a utility that can do that as well but I would go to the usercenter to get the NGX license.
Reply With Quote
  #3 (permalink)  
Old 2005-12-16
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: moving to NGX : two questions

So upgrade_export must be run on the management stations not on the NOKIA ??

I allready found how to upgrade the license on the usercenter, thx for that.

cheers,
Reply With Quote
  #4 (permalink)  
Old 2005-12-17
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: moving to NGX : two questions

Right, upgrade_export is only needed to run on the management station. If you are still keeping the same management station and only changing the gateways, then there isn't a backup that you need to do on the gateways. Just be sure that you do the upgrade_export before you upgrade the management station.
Reply With Quote
  #5 (permalink)  
Old 2005-12-18
Peter Peter is offline
Junior Member
 
Join Date: 2005-12-02
Location: France
Posts: 27
Rep Power: 0
Peter has an average reputation (10+)
Default Re: moving to NGX : two questions

Just one thing to know - il would be better to use NGX version of upgrade_export. Maybe it works with the NG version but CheckPoint recommends to use the NGX one. You can download it from usercenter.checkpoint.com or use the one from your NGX CD.
Reply With Quote
  #6 (permalink)  
Old 2005-12-18
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: moving to NGX : two questions

If you are upgrading to NGX, then I would use the NGX version of upgrade_export.
Reply With Quote
  #7 (permalink)  
Old 2005-12-20
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: moving to NGX : two questions

So since everythings now runs on the nokia I've downloaded
upgrade_checker_B591000034_1.tgz.

- So I copy this file through tftp to the Nokia
- run upgrade_export
- copy the config-file received from the upgrade_export script to the tftp-server.
- Install SPLAT
- copy the config-file from the tftp-server to the SPLAT
- run the upgrade_export command with the config file
--- DONE ---

Are those steps correct or am I missing something?

Cheers,
Reply With Quote
  #8 (permalink)  
Old 2005-12-20
Westy Westy is offline
Junior Member
 
Join Date: 2005-12-20
Posts: 24
Rep Power: 0
Westy has an average reputation (10+)
Default Re: moving to NGX : two questions

we just upgraded from SPLAT R54 to SPLAT R60 (NGX) with the help of a consultant. the first thing he did was to upgrade our license at the user center. according to him it should always be the first step in the install routine. he did use the NGX version of the export tool.
Steps.
backup existing install.
export objects
ftp file that contains exported objects to a couple of different laptops.

run the verify upgrade routine.
upgrade the license at the user center.
install ngx
import exported objects.
backup new install
export objects from the new install
ftp them to the laptops again
Reply With Quote
  #9 (permalink)  
Old 2005-12-21
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: moving to NGX : two questions

damn, can't get upgrade_export to run on the nokia box.
first got a permission denied, did a chmod 777 on the file
and now I receive 'bad address'
Reply With Quote
  #10 (permalink)  
Old 2005-12-21
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: moving to NGX : two questions

OK, so the upgrade_export version I've downloaded from the checkpoint site for NGX did not work.
So I used the one allready on the nokia box (R55) and the export worked.
Imported on the new NGX SPLAT also went like a charm.

Upgrading the license on the site -> could not add the license through the web-interface, this only worked in the console with the 'cplic put' command.

logging in with smartdashboard -> everything seems fine
No I need to wait untill everyone is out off the office to switch the cables.

-> some odd thing : when I use 'shutdown' in the console the screen stays on 'Halting System' but the server doesn't shutdown.
When I use reboot I noticed no problem at all.

Cheers,
Reply With Quote
  #11 (permalink)  
Old 2005-12-21
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: moving to NGX : two questions

OK, migration is almost done except one problem that's need to be fixed.

For some reason a static nat on the nodes does not function.
I need to NAT a mailrelay to one of our public ip adressen, but that does not work.
Only hide behind gateway seems to work to access the internet.

Do I need to configure something more to get static and/or hide NAT to work?

cheers,
Reply With Quote
  #12 (permalink)  
Old 2005-12-21
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: moving to NGX : two questions

Quote:
Originally Posted by joris
OK, migration is almost done except one problem that's need to be fixed.

For some reason a static nat on the nodes does not function.
I need to NAT a mailrelay to one of our public ip adressen, but that does not work.
Only hide behind gateway seems to work to access the internet.

Do I need to configure something more to get static and/or hide NAT to work?

cheers,
Are you trying to do a manual NAT rule (NAT Tab) or an automatic rule (In the host object)?

Automatic rules do all of the ARP and routing magic for you. If you add manual NAT rules, you need to add the ARP entries and may need to add a host route.

-jlh
Reply With Quote
  #13 (permalink)  
Old 2005-12-22
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: moving to NGX : two questions

chillyjim,

I'am using automatic NAT rule.
I can only access the internet if I put the ip adress of the firewall in the Static Nat.
All other ip addressen in the range does not work.
Since I imported the config from the Nokia and everythings stills work fine on the Nokia, thats kinda strange to me.
Reply With Quote
  #14 (permalink)  
Old 2005-12-22
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: moving to NGX : two questions

Yeah that is strange, SPLAT handles NAT better than IPSO in general....

Have you opened a call with support yet?

-jlh
Reply With Quote
  #15 (permalink)  
Old 2005-12-22
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: moving to NGX : two questions

Put a proxy arp on the Nokia for the other IP's and you should be set. I never trust the autoarp in CheckPoint to work properly.
Reply With Quote
  #16 (permalink)  
Old 2005-12-22
joris joris is offline
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: moving to NGX : two questions

Ok, found the solution.
I had to do NAT like on previous version of splat/linux

First I actived proxy arp on the interfaces
Edit /etc/sysctl.conf with a text editor (such as vi).
Add the following:
net.ipv4.conf.all.proxy_arp = 1
net.ipv4.conf.default.proxy_arp = 1
reboot

and then I added a route for the static nat
route add -host "Static_nat_ip" gateway "internal_ip"
-> do this with sysconfig to add a persistent route !!

I thought NGX did all the arp/route magic for you if you used automatic nat rules ??

Maybe this is a consequence of the export_upgrade I did on the Nokia, I don't know.

Anyone other had static/hide NAT problems with NGX ?

cheers,

-> thx for all the replies guys !!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:03.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0