| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I need to install the latest HFA on my firewalls and management stations. Where can I find them and what are the commands to install them? Please help asap. Thanks. __________________ Systems Engineer |
| |||
| Latest HFAs are availible on Checkpoint site under software downloads. You will need S/W subscriptions to download them. Installation instructions are included in the download readme guide. |
| |||
| When i go to the Software Download section on the Checkpoint website, there is no HFA for NGX R60. I dont understand what this mean below? For my management station (which is separate from the firewall), do I need to install the SmartConsole HFA or SmartCenter HFA and what is the difference? Note - It is recommended that when installing SmartConsole R60_HFA_02 you have SmartCenter R60_HFA_03 or higher. And those of you who can, can you please provide me with instructions on "How to install" the HFAs. Thanks. __________________ Systems Engineer |
| |||
| not sure why you couldn't see the HFA's, but heres a link (you will need usercenter account to download) http://www.checkpoint.com/downloads/...vpn1power.html |
| |||
| What HFA do I need for my management server? Its SecurePlatform on linux? My firewall is running IPSO... --------------------- NGX R60 R60_HFA_03 Release Notes IPSO 42.9 MB, MD5: d5e7768d80a50e47e0b1070cddc3b3e6 SecurePlatform 74.4 MB, MD5: 9dfa47a6335e14113d7aaf554a591d8c __________________ Systems Engineer |
| |||
| Humayun, ok here goes:- Assuming you are running Secureplatform on Management Station use Comprehensive_R60_HFA_03.splat.tgz (http://www.checkpoint.com/downloads/...power.html#r60) For your IPSO FWs use Comprehensive_R60_HFA_03.ipso.tgz (http://www.checkpoint.com/downloads/...ower.html#r60). UNLESS you're using IP265 then there is a different package. Install HFA on management station 1st then FWs. You can install HFAs using either SmartUpdate or CLI. The instructions for install are in all the release notes and readmes included in the packages, so please read them.Quick steps as follows:- 1. Make a folder for the package (e.g. under /VAR - make sure you have enough space). 2. Transfer package to device. (Personally I use TFTP with binary ON) 3. Decompress / untar package (tar zxpfv (package name)) 4. Run installation - e.g. ./Secureplatform_Hotfixname etc (this will differ depending on the IPSO / SPLAT HFA) 5. Reboot. All this is explained in the release notes / readmes that are bundled in with the packages so please read. htp CLI |
| |||
| Question 1 I installed the SPLAT HFA_03 on my Mgmt server and it even said "Installation completed successfully." but when I do a fw ver, it does not show me the HFA verison at all, even after reboot of the box. [mgmtserver]# fw ver This is Check Point VPN-1(TM) & FireWall-1(R) NGX (R60) - Build 458 Question 2 Plus on my firewall I am trying to untar this file but have upload it to the ftp server about 10 times since yesterday in Binary mode but cannot get the untar to work. [firewalladmin]# gzip -dc Comprehensive_R60_HFA_03.ipso.tgz | tar -xvf - ./ NG_BC/ NG_BC/ng_bc_R55_BC_R60_HFA_03.ipso.tgz gzip: Comprehensive_R60_HFA_03.ipso.tgz: unexpected end of file tar: Unexpected EOF on archive file Need help fast. __________________ Systems Engineer |
| |||
| 1 - Desctibe steps - how do you install HFA? May be you don't install splat or fw1 patch? 2 - I don't use '|' in archive commands, so I don't sure that it is correct. Try to "tar -zvxf Comprehensive_R60_HFA_03.ipso.tgz" |
| |||
| I guess it was the problem with download. After downloading it several times and then ftp'ing it over to the firewall it finally worked. Arent' I glad thats over. Thanks for the help. __________________ Systems Engineer |
| |||
| Problem with the HFA install on my Management server. It was running NGX (R60) with HFA_01 on it. Noted below is what I installed on my Management Server (copy of the screen output). This is what the HFA_03 Release Notes says to install. Is there anything else I need to install? Because when I do a "fw ver" on my management server, it does not show me any HFAs, unlike when I do the same command on my firewall where it tells me that it has HFA_03 installed. Please help asap. Thanks. [MgmtServer]# ./SecurePlatform_HOTFIX_R60_03_591603003_1 Do you want to proceed with installation of Check Point SecurePlatform NGX R60 Hotfix R60_03 for Check Point SecurePlatform NGX R60 on this computer? If you choose to proceed, installation will perform CPSTOP. (y-yes, else no):y SmartView Monitor: Management stopped FloodGate-1 stopped Cannot find pid of vpnd VPN-1/FW-1 stopped SVN Foundation: cpd stopped SVN Foundation: cpWatchDog stopped SVN Foundation stopped Launching post-hotfix utility ************************************************** ************************* Check Point SecurePlatform NGX R60 Check Point SecurePlatform NGX R60 Hotfix R60_03 Installation completed successfully. ************************************************** ************************* Installation was successful. [MgmtServer]# rpm -q scis scis-1-591005001 __________________ Systems Engineer |
| |||
| what does smartupdate say about your mgmt station version ? also maybe silly question, but have you tryed rebooting your mgmt after HF installation? Last edited by abusharif; 2006-08-21 at 01:23. |
| |||
| Humayun, the output from rpm -q scis is ok and signifies you are running HFA03 on the mgmt server. You have only run the SPLAT O/S package as this is a management satation. You have not run the fw1_Hotfix_R60_03_591603 as it's not needed (because this box is management only). |
| |||
| ng_bc is the backward compatability patch, which I dont need. >>part2) Fw1 part of HF fw1_* This is for the firewall and I am only running the management server on this box. My firewalls are separate from the management server. So why should i need to run this, and even the release notes say just to run the SecurePlatform HFA. So I am not sure. If I install these two patches, will that screw something up or its harmless? There is too much at stake so I need to make sure. __________________ Systems Engineer |
| |||
| since it seems to be easier not to read RN and then question everything people that wanna help say i'll quote it for you here. Quote:
Quote:
Quote:
|
![]() |
| Thread Tools | |
| Display Modes | |
| |