CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-25
intehnet intehnet is offline
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default R55 to NG X, Splitting management and Enforcement

All,

This is just a post to show the scenario I encountered during an upgrade.. I'd like to hear your comments on my experiences, perhaps there was another way I could have done this..

The existing set up was R55 SPLAT which had Enforcement and Management, and a Windows 2003 server for Logs and Eventia Reporter.
The plan was to introduce a new firewall (upgraded hardware) and run up NG X SPLAT on that, and move management to the windows 2003 box.

Upgrade export on the R55 SPLAT
Upgrade import that to 2003 fresh NG X Primary Smart Center installation - Failed; unable to switch platforms or something similar
Uninstalled everything on the Windows 2003 box and ran cpclean (fantastic utility!) - finally got the NGX import done (there's a big with a file in $FWDIR/conf/ having Read Only attributes, fixed that)
Now I had a config on 2003 in which I had to move management from the Splat box to the 2003 box... Impossible! it cant be done.. so I had to take the enforcement box out of all the rules and VPNs, remove the firewall object, detach all the licenses and rename it to the Windows 2003 box, and recreate the firewall object. This worked.. and SIC was established.. however.. Logs weren't going from the firewall to the enforcement/logserver... No matter what I tried it just wasn't quite right..

It was at this stage i blew everything on the Windows 2003 server away, and recreated the entire rule set and configuration by hand, which took time, but worked..

Was there another way I could've done this, has anyone experienced this before??

Thanks for your time and appreciate any responses

Jimmy
__________________
///M
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:43.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0