| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| All, This is just a post to show the scenario I encountered during an upgrade.. I'd like to hear your comments on my experiences, perhaps there was another way I could have done this.. The existing set up was R55 SPLAT which had Enforcement and Management, and a Windows 2003 server for Logs and Eventia Reporter. The plan was to introduce a new firewall (upgraded hardware) and run up NG X SPLAT on that, and move management to the windows 2003 box. Upgrade export on the R55 SPLAT Upgrade import that to 2003 fresh NG X Primary Smart Center installation - Failed; unable to switch platforms or something similar Uninstalled everything on the Windows 2003 box and ran cpclean (fantastic utility!) - finally got the NGX import done (there's a big with a file in $FWDIR/conf/ having Read Only attributes, fixed that) Now I had a config on 2003 in which I had to move management from the Splat box to the 2003 box... Impossible! it cant be done.. so I had to take the enforcement box out of all the rules and VPNs, remove the firewall object, detach all the licenses and rename it to the Windows 2003 box, and recreate the firewall object. This worked.. and SIC was established.. however.. Logs weren't going from the firewall to the enforcement/logserver... No matter what I tried it just wasn't quite right.. It was at this stage i blew everything on the Windows 2003 server away, and recreated the entire rule set and configuration by hand, which took time, but worked.. Was there another way I could've done this, has anyone experienced this before?? Thanks for your time and appreciate any responses Jimmy __________________ ///M |
![]() |
| Thread Tools | |
| Display Modes | |
| |