CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-29
avilT avilT is offline
Member
 
Join Date: 2006-03-14
Posts: 71
Rep Power: 3
avilT has an average reputation (10+)
Default Nokia Device Change

I have checkpoint NGX on Nokia IP330 with smart center server on Windows, centralized license.
Due to EOL of IP330 I need to replace IP330 with IP390 with minimum downtime. I can use different management address on the new IP390 firewall as its not critical but other interface IP's should remain same as the old IP330 device. So can I setup this new IP390 device while IP330 online (but other interfaces will be disconnected from the network), install the policy, later quickly change to this new Ip390 device by moving the network cables from old device to new IP390. Only the management IP will be different on this new Nokia IP390 device.
Thanks
Reply With Quote
  #2 (permalink)  
Old 2008-04-30
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Nokia Device Change

Don't see a problem with that, but you will have to use a different name for the object, etc, so that will cause some things to break, like VPNs, etc.

To be honest I would just install it mirroring the existing box, set it to same versions and then switch. You can copy config, and then just push policy, or you can switch, reset and set sic and then push policy (you will have to assign license again too I think).
Reply With Quote
  #3 (permalink)  
Old 2008-05-02
donshoutarp donshoutarp is offline
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 3
donshoutarp has an average reputation (10+)
Default Re: Nokia Device Change

Quote:
Originally Posted by avilT View Post
I have checkpoint NGX on Nokia IP330 with smart center server on Windows, centralized license.
Due to EOL of IP330 I need to replace IP330 with IP390 with minimum downtime. I can use different management address on the new IP390 firewall as its not critical but other interface IP's should remain same as the old IP330 device. So can I setup this new IP390 device while IP330 online (but other interfaces will be disconnected from the network), install the policy, later quickly change to this new Ip390 device by moving the network cables from old device to new IP390. Only the management IP will be different on this new Nokia IP390 device.
Thanks
I've been going though this at several branch offices. I've been building the new IP390 like the IP330 (ip addresses, etc). CPconfig on the 390 and create sic. I let the 390 boot. After it is booted, in smart console I reset sic. I move the network cables to the new device. In smart console create sic, get interfaces, push policy. Our down time has been less that 3 minutes, but that would vary on on the size of your policy.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:07.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0