CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Versions Of Firewall-1/VPN-1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #21 (permalink)  
Old 2007-10-29
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: R65 HFA02 released

other question about the dynamic ips with edges...is there a open issue?

thanks again!
__________________
misery is optional

Last edited by Porter; 2007-10-30 at 00:23.
Reply With Quote
  #22 (permalink)  
Old 2007-10-31
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: R65 HFA02 released

CP mentioned that the installation issue of the edges could be resolved if Smartdefense will be updated. I already have the 7.5.33 in use so I won't be able to find out if that will work, someone around who can confirm this?
__________________
misery is optional
Reply With Quote
  #23 (permalink)  
Old 2007-10-31
Senior Member
 
Join Date: 2007-07-16
Posts: 618
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: R65 HFA02 released

Quote:
Originally Posted by RayPesek View Post
>> VPN-1 Embedded Connector 7.0.1.2 starting


Personally I have no issues with requiring certs for managed Edge VPN's. They are far more secure than pre-shared keys and allow the use of DHCP Internet connections on the Edge's.

Ray
The problem comes when you need to use the Edge devices in a community that includes non-Check Point or externally managed devices that don't use a cert issued from your CA. It's a real pain....
Reply With Quote
  #24 (permalink)  
Old 2007-10-31
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: R65 HFA02 released

Quote:
Originally Posted by Porter View Post
CP mentioned that the installation issue of the edges could be resolved if Smartdefense will be updated. I already have the 7.5.33 in use so I won't be able to find out if that will work, someone around who can confirm this?
did a test in the lab, issues still exists, only difference is the error message itself
__________________
misery is optional
Reply With Quote
  #25 (permalink)  
Old 2007-10-31
Member
 
Join Date: 2005-12-16
Posts: 35
Rep Power: 0
joris has an average reputation (10+)
Default Re: R65 HFA02 released

We are having the same problems with our edge devices after installing HFA02
Don't have them with HFA01 though.

Porter, you say that installing libsw version 7.5.33 solved your problem?
I also can't find them, is it possible that you mail me those files?


thx.
----> problem solved, thx <-----

Last edited by joris; 2007-10-31 at 08:09.
Reply With Quote
  #26 (permalink)  
Old 2007-11-02
Junior Member
 
Join Date: 2006-08-10
Posts: 2
Rep Power: 0
Olivn has an average reputation (10+)
Default Re: R65 HFA02 released

upgrade_export does not work anymore after upgrade to HFA02.

upgrade_export -d /var/opt/tmp/fwconf
....
Building configuration file...
[ 21506 1]@[2 Nov 16:21:49] WriteToFile: Error >> Got NULL argument
[ 21506 1]@[2 Nov 16:21:49] BuildConfigurationFile: Error >> Failed to write 'Plugins' to configuration file
Error: Failed to read local configuration info
Reply With Quote
  #27 (permalink)  
Old 2007-11-04
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: R65 HFA02 released

Using it for a local customer.... no problems so far?
Reply With Quote
  #28 (permalink)  
Old 2007-11-07
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 255
Rep Power: 2
dantro has an average reputation (10+)
Default Re: R65 HFA02 released

The HFA_02 has been revised today. Please download it again. Sorry for any inconvenience this may cause you.
Reply With Quote
  #29 (permalink)  
Old 2007-11-08
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: R65 HFA02 released

for problems related to pushing policy to edge devices with hfa_02 check KB sk33821. There is a hotfix for this.
Reply With Quote
  #30 (permalink)  
Old 2007-11-08
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: R65 HFA02 released

Quote:
Originally Posted by abusharif View Post
for problems related to pushing policy to edge devices with hfa_02 check KB sk33821. There is a hotfix for this.
If I use the revised HFA will I also need to install this HF?
Reply With Quote
  #31 (permalink)  
Old 2007-11-08
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: R65 HFA02 released

Quote:
Originally Posted by melipla View Post
If I use the revised HFA will I also need to install this HF?
to be honest no idea, since checkpoint publish modified hfa packages without really explaining what they modified in them. RN for revised hfa still point to that kb article so I guess patch is still needed or they forgot to update RN :(
Reply With Quote
  #32 (permalink)  
Old 2007-11-08
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: R65 HFA02 released

And to answer my own question, the download for HFA2 has this notation below it:

Users of VPN-1 Edge/Embedded, please refer to sk33821

Given that it appears HFA2 does not include it. The HFA listed shows a date of Oct 21 which was the original release date, so I'm not sure what you mean by revised Dantro--it appears to be the same.

*Edit* Dang Abusharif you're fast to respond...you bet me to it!
Reply With Quote
  #33 (permalink)  
Old 2007-11-08
Senior Member
 
Join Date: 2007-05-25
Posts: 124
Rep Power: 2
pat13b has an average reputation (10+)
Default Re: R65 HFA02 released

looks like this was revised. The release notes have a date of Nov. 7th

yet, same revision level and the file has a date of Oct 21st. What the hell is up with that ????


What’s New
• DCERPC traffic is enabled in Monitor-Only mode.
• Enhanced memory usage during automatic Anti-Virus updates.
• On SecurePlatform, monitoring system load by using the uptime command has been improved.
• VPN-1 Edge Firmware 7.5.29 is now supported.
Reply With Quote
  #34 (permalink)  
Old 2007-11-08
Senior Member
 
Join Date: 2007-07-16
Posts: 618
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: R65 HFA02 released

My spies advised me that a new HFA_02 was being published at the end of the week, to fix Edge installation problems and a few other issues. Why they don't call this HFA_03 and confuse us all with varying HFA_02 release numbers is beyond me, but not without precedent.

A post HFA_02 hotfix for people who have already installed HFA_02 and need the fix is supposed to be available - see sk33821 in SecureKnowledge.

I'm going to wait until a formal HFA_03 release - it seems like CP have been a bit too hasty on the QA process on this one. Reminds me a bit of NG FP2.... :P
Reply With Quote
  #35 (permalink)  
Old 2007-11-09
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: R65 HFA02 released

Quote:
Originally Posted by Thorpuse View Post
My spies advised me that a new HFA_02 was being published at the end of the week, to fix Edge installation problems and a few other issues. Why they don't call this HFA_03 and confuse us all with varying HFA_02 release numbers is beyond me, but not without precedent.

A post HFA_02 hotfix for people who have already installed HFA_02 and need the fix is supposed to be available - see sk33821 in SecureKnowledge.

I'm going to wait until a formal HFA_03 release - it seems like CP have been a bit too hasty on the QA process on this one. Reminds me a bit of NG FP2.... :P
you're right! typicall CP behavior of the last time...can't understand why they work in this manner
__________________
misery is optional
Reply With Quote
  #36 (permalink)  
Old 2007-11-10
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: R65 HFA02 released

Check Point recently revised the HFA02 release notes to add a note about a new article:

Installing VPN-1 Pro NGX R65 HFA_02 causes install policy failure on VPN-1 Edge device - Solution ID: #sk33821

There's a hotfix attached to it.

Ray
Reply With Quote
  #37 (permalink)  
Old 2007-11-12
Junior Member
 
Join Date: 2007-10-29
Posts: 1
Rep Power: 0
ennerr has an average reputation (10+)
Default Re: R65 HFA02 released

Has somebody gotten HFA02 (with hf229) to work with centrally managed Nokia IP60w edge devices? I´d like to know if somebody has managed to stabilize (ie policy install works every time without devices crashing randomly) this setup somehow.
Reply With Quote
  #38 (permalink)  
Old 2007-11-13
Junior Member
 
Join Date: 2007-02-23
Posts: 27
Rep Power: 0
Tommo has an average reputation (10+)
Default Re: R65 HFA02 released

Hi All,

Just for info, did an install on a customer site the other day. 2 things to be aware of (plus solutions ;-) )

Edge / Embedded gateway issues - you can break policy push to your Edges with R65 HFA02

CP mailed this to us:

Hi,

This Email is relevant to you only if you are using VPN-1 Edge/Embedded and installed R65 HFA02.

R65 HFA02 released recently includes a problem which may cause policy installation on VPN-1 Edge/Embedded devices to fail. The problem does not have any implications on users of other types of gateways.

For customers who already downloaded and deployed R65 HFA02, we have released a hotfix that can be installed on top of the R65 HFA02 installation. Instructions for installing the hotfix can be found in sk33821.

Next week we will release a replacement for HFA02 that will eliminate this problem.

We are sorry for the inconvenience created by this problem.



Secondly, there's the upgrade toolsthat may break too. I got a new copy of upgrade_import/export form one of the guys in Israel I'm working with at the mo, so if anyone else gets Error: Failed to read local configuration info., I've got an updated one if you need ;-)
Reply With Quote
  #39 (permalink)  
Old 2007-11-13
Senior Member
 
Join Date: 2007-06-05
Location: Canada
Posts: 188
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: R65 HFA02 released

Can anyone post a link as to where I can get the new upgrade_export tool?
Reply With Quote
  #40 (permalink)  
Old 2007-11-13
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: R65 HFA02 released

I'm using the one downloaded from the usercenter? Have tried to use that to upgrade_export/import without any problems? Tried on RHEL3.0 and SPLAT..

Also tried to import using the upgrade_import from the system itself.. ok soo far to..
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0