CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > High-End Security > VPN-1 VSX
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-04
dr-spoof dr-spoof is offline
Junior Member
 
Join Date: 2006-03-10
Location: Detroit Michigan USA
Posts: 15
Rep Power: 0
dr-spoof has an average reputation (10+)
Default NGAI to NGX VSX Upgrade

Has anyone upgraded VSX from NGAI to NGX? If so what was your experience. Having played with NGX in the lab it is very different from the NGAI version and I have not installed the NGAI version. My lab is to primative to try a test upgrade with in the lab. Any thoughts or experience on this would be appreciated.
Reply With Quote
  #2 (permalink)  
Old 2006-07-17
tedesco tedesco is offline
Junior Member
 
Join Date: 2005-09-27
Posts: 5
Rep Power: 0
tedesco has an average reputation (10+)
Default Re: NGAI to NGX VSX Upgrade

Sorry for the late answer, but it might still help someone:

Ugrading has been very difficult but now I have managed to upgrade 3 of my VSXs.

Problems:

on MDS - P-1 for VSX
- Upgrade process on MDS broken due to some soft link loop. See sk31372
- we had problem with vsx_util on some large VSX. (fwm times up on a request from the vsx_util.) Got a fixe for libCmaForwardingLayer.so at /opt/CPsuite-R60/fw1/lib/

- cpd seems to dies periodically, and I did not find yet the exact reason.


On VSX:
- We had a dbedit script to automatically create users under NGAI. After upgrade users got corrupted. (some fields set to NULL and can not be edited. user has to be deleted.
- under NGAI, we had gotten some driver for intel quad card e1000 and had to modif. /etc/modules to use for example e1000.5.2.30.1 under NGX, the last driver is e1000 so
- under ngai, we used the driver tg3 for the onboard card BROADCOM Corporation NetXtreme BCM5703X Gigabit Ethernet. Under NGX, the driver that should be use seems to be bcm5700 (Could not find the tg3 and the bcm5700 seems to work)

- VSX froze/overloaded when usering secureXL. + whould not come fully up after reboot. (stoped on some VS) I had to disable secureXL.
- License for upgraded VSX are automatically detached. After upgrade, do not forget to re-attache the license or the demo lic. will expire after 15 days... and secure client users will get blocked...
- fw stat <VS> does not work for VS on VSX upgraded to NGX. Checkpoint has a fixe that works for this. (Does not work yet for clustered VS)
- if you use radius server to auth. users, take care to modify the parameter "shared_external_servers" to false (CP has modified the default behavior here, it is documented, poorly, but documented.)
- we had modified the Max concurrent connection for a VS to 99000, the values got lost after upgrade, and set back to 15000.
- get the patch refered in sk31358
- install VSX NGX HFA_V30_01: It fixes some serious problem for secure client (after upgrading to NGX, return packet from Secureclient not sent in tunnel)
- if you have some site-to-site vpn that implement some "hub mode" routing (the remote vpn boxe route all traffic toward the VS, including traffci to default route) then you might get some problem. We got a fix for a file called /opt/CPvsxngxcmp-R60/bin/fw_loader (located on mds)

- Seems that /bin/backup_start is wrong again: it uses cpwd_admin start -name CPD -path \"$CPDIR/bin/cpd_admin\" -command \"cpd_admin start
But cpd_admin does not have "start" as a possible parameter (only stop, list, ver and debug...) So the correct way to start cpd after backup is probably: cpwd_admin start -name CPD -path \"$CPDIR/bin/cpd\" -command \"cpd\"
(Note that cpwd_admin is also badly initialised after reboot... I did not have time yet to fix this)

Otherwise, NGX requires 3 time more disk space during the upgrade on the MDS. ( NGAI/R55 is duplicated to backware comp. under NGX disk space and NGX/R60 takes more place the NGAI)
It also requires more memory...

Good luck!!!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:47.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0