CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Versions Of Firewall-1/VPN-1
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-29
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 255
Rep Power: 2
dantro has an average reputation (10+)
Default Upgrade no more > When recreating a rulebase from scratch

Hello,

when would you recommend recreating a rulebase from scratch? I mean, a customer who upgraded from 4.0 > FP2 > FP3 > R55 > R60 > R61 should not really be upgraded yet another time to R65. You know, in the old days Check Point recommended a lot of manual changes directly inside of the object.C files. Experience shows that now sometimes you need to manually adjust some values via guidbedit because an upgrade to the newest version failed due to a database inconsistency. How long do you wait for reviewing, consolidating, recreating a rulebase completely? Two version steps, five years or until an error appears?

I've seen situations where Check Point clearly stated a rulebase not to be "Check Point conform" after all the years. So the customer didn't receive support until everything had been recreated with Check Point technicians. Where is this conformity defined? I'm looking especially for any official documents about upgrading from version to version (not the general upgrade guide itself) and any official Check Point recommendations or advisories. I won't just tell the client that our experience shows that after ten years a policy should be completely renewed. Clients want to see something more real to spend money for such a process. Something like: "Check Point recommends to update only within an Engine, not between them." Like from NG FP3 to NG AI (R55). It's within the NG engine. Or from R60 to R62 which would be within the NGX engine. I think you got the point of what I am looking for.

Last edited by dantro; 2007-10-29 at 10:50.
Reply With Quote
  #2 (permalink)  
Old 2007-10-30
Senior Member
 
Join Date: 2007-06-04
Posts: 1,070
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Upgrade no more > When recreating a rulebase from scratch

I think the last time I recommended starting from scratch was from 4.1 to NG pre FP3.

The only times I think these days that I would start from scratch are if I there were a lot of rules in there that the manager wasn't sure what they were there for, and so would start from scratch to try and bring under control.

Generally these days I tend to upgrade_export to another machine rather then upgrade in place just in case there are any issues with the upgrade if any of the files have been manually modified.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:09.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0