CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-01
Junior Member
 
Join Date: 2006-02-01
Posts: 6
Rep Power: 0
murawai has an average reputation (10+)
Default NGAI R55 HFA17 stuffing HA

Hi There
I have checkpoint NG AI running on SPLAT in distibuted model. Have 2 firewall modules in Active/standby cluster. After I install HFA17 on the redundant firewall enforcement and reboot I can no longer run cphastat and see the status of the active firewall. When I run cphastat it only can see the local firewall which says its ready (with no load). Is this normal? Normally after a HF I can still run this command before I upgarde my other firewall and see the status of both.
Reply With Quote
  #2 (permalink)  
Old 2006-02-02
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: NGAI R55 HFA17 stuffing HA

I have seen this with my customers as well. HFA_17 appears to do this. If you use 'cphaprob state' it will show something about doing an upgrade. As far as I can see you have to upgrade the other appliance before they see each other.
Reply With Quote
  #3 (permalink)  
Old 2006-02-06
Junior Member
 
Join Date: 2006-02-01
Posts: 6
Rep Power: 0
murawai has an average reputation (10+)
Default Re: NGAI R55 HFA17 stuffing HA

Thanks for this. My only issue is that after I install the hotfix I lose connection to the enforcement module even though it is installing the correct firewall policy. I am hesitant to upgrade both as this seems very different from every other Hotfix. Did you hotfix both the active and standby modules? What was the outcome?
Reply With Quote
  #4 (permalink)  
Old 2006-02-06
Junior Member
 
Join Date: 2006-01-19
Posts: 3
Rep Power: 0
jamik has an average reputation (10+)
Default Re: NGAI R55 HFA17 stuffing HA

Which is why you run a mirror.. Upgrade it all.. If all goes tits up, then just pop the old disks back in and it's back to square one. :p
Reply With Quote
  #5 (permalink)  
Old 2006-02-07
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: NGAI R55 HFA17 stuffing HA

Quote:
Originally Posted by murawai
Thanks for this. My only issue is that after I install the hotfix I lose connection to the enforcement module even though it is installing the correct firewall policy.
You did upgrade your SmartCenter first, right?
Reply With Quote
  #6 (permalink)  
Old 2006-02-09
Junior Member
 
Join Date: 2006-02-01
Posts: 6
Rep Power: 0
murawai has an average reputation (10+)
Default Re: NGAI R55 HFA17 stuffing HA

Yeap - upgraded smartcenter first (after I install hfa17 on one of the enforcement module's and restart the system it installs the lastest policy successfully when it restarts). I have installed hotfixes many times and normally they run extremely smoothly. I have currently rolled back to HFA16 which operates as normal.
Obviolusly I could try and install the hotfix on both enforcement modules to see what happens however this means downtime if its not successful which I am concerned about. It seems very strange that after the hotfix is installed on the backup module it can no longer be managed from remote machines and no longer sees any cluster partner when I run cphaprob.
Is anyone running SPLAT in cluster environment installed HFA17 without the above issues? I am considering just waiting for HFA18 otherwise....
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:03.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0