CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-26
lowfell lowfell is offline
Member
 
Join Date: 2006-06-06
Posts: 72
Rep Power: 3
lowfell has an average reputation (10+)
Default Upgrading from NG FP2

I have a customer who has the NGFP2 running a Nokia IP300
"Check Point VPN-1(TM) & FireWall-1(R) NG Feature Pack 2 Build 52284"

The Nokia is running
Ipsrd version ipsrd-IPSO-3.6-FCS3-08.01.2002-12:41:34

My questions are these

1. Given the versions the customer is currently running, what is the latest version they can upgrade to, can they go stright to NGX? Or can trhey only go to NG ???

2. Will the Nokia IPSO need uprading as well, or will the checkpoint run over the top of this version regardless ?

Thanks in advance, your input is greatly appreciated.
Reply With Quote
  #2 (permalink)  
Old 2008-03-26
chuachongchee chuachongchee is offline
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 157
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Upgrading from NG FP2

Quote:
Originally Posted by lowfell View Post
I have a customer who has the NGFP2 running a Nokia IP300
"Check Point VPN-1(TM) & FireWall-1(R) NG Feature Pack 2 Build 52284"

The Nokia is running
Ipsrd version ipsrd-IPSO-3.6-FCS3-08.01.2002-12:41:34

My questions are these

1. Given the versions the customer is currently running, what is the latest version they can upgrade to, can they go stright to NGX? Or can trhey only go to NG ???

2. Will the Nokia IPSO need uprading as well, or will the checkpoint run over the top of this version regardless ?

Thanks in advance, your input is greatly appreciated.

For qns 1, i would advise to migrate the config thru upgrade_export/upgrade_import, but you cannot upgrade the checkpoint app straight to NGX..

For qns 2, i'm not a nokia kinda guy.. so i'm not sure...
Reply With Quote
  #3 (permalink)  
Old 2008-03-26
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Upgrading from NG FP2

You would have to go to NG FP3 Hotfix 2. I think you can stay on IPSO 3.6.

Then you would have to go to R55 HFA20.

Then take IPSO to v3.9 for the first NGX-compatible version of IPSO.

Then go to R60

Then go to whatever version of CP and IPSO you need to.

What's the hardware? That's pretty old software and my guess is the hardware won't handle NGX.

Personally, I would build a brand new R65 system and recreate all of the objects and rules from scratch. You're going to hit some issues because you won't be able to adequately test each intermediate step and it will be a lot cleaner system after you're done.

Ray
Reply With Quote
  #4 (permalink)  
Old 2008-03-27
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,034
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Upgrading from NG FP2

I would say that as IPSO 3.6 then will be an IP330 as the IP350/380 were IPSO 3.5.1 then 3.7 etc, they don't run IPSO 3.6.

In my opinion the 330 is not suitable for NGX as too slow, also it goes EOL in September so will need to be replaced this year anyway.

As such I would suggest as Ray, and start again clean. I would also advise that migrates to a seperate management server as Nokia is wasted when used for Management. I would suggest a SPLAT Server for Mgmt and then either SPLAT for Gateways or a new Nokia.

I would also advise that they update more frequently in future.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:11.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0