CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 3/8, 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Windows
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2009-06-01
Member
 
Join Date: 2008-08-07
Posts: 97
Rep Power: 2
vbavbalist has an average reputation (10+)
Default Windows 2003/R65 OS patch management

Hi,
I have 2 hardware which on both Windows 2003 Server and R65 is installed. Also DNS server on both systems are working on to host the companies domains.

For a long time the main firewall is working online. But this weekend i need to make the backup fw the same as the main one. I have exported the CP configuration and imported to the backup one, thats ok. But I need also the check the DNS entries and the patch of the OS itself. So for this time and generally what do you offer for the patch management of the OS firewall running on?

Regards
Reply With Quote
  #2 (permalink)  
Old 2009-06-02
Senior Member
 
Join Date: 2007-06-04
Posts: 1,459
Rep Power: 4
mcnallym has an average reputation (10+)
Default Re: Windows 2003/R65 OS patch management

Any old Windows Patch Management Software would do.

If you are going to run your Check Point on Windows (and I wouldn't personally) then there are lots of existing Windows Patch Management products available ranging from Microsoft WSUS right the way upto Microsoft System Center.

I can't imagine a Microsoft environment not having some form of existing Windows Patch management, especially as WSUS is free.

I take it that as you have exported the cp config from one to the other that the 2nd box is an offline backup ready to go if the live firewall breaks.

Also if you MUST keep your check point on Windows at least move the DNS Server off the box. Your firewall really should be a single purpose box.

Is there a reason, other then the DNS Server running on the box that you don't use Secure Platform as you really don't have to be a linux expert to use it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 12:47.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2