PDA

View Full Version : HFA on Nokia or Windows



dj_berkine
2006-02-09, 05:05
Hi All

I have my enforcement module running on Nokia IPSO3.8 and my smartcenter running on windows 2000, I need to apply new HFA but i don't know if we need to apply them on the smartserver or the Nokia or both,

Thanks a lot

Regards

Berkine

kva.kva
2006-02-09, 08:11
First update your SmartCenter, and then update Enforcement Module.
I always update in this order.

And notes that HFA for CP on Windows platform is not applicable for NOKIA.

dj_berkine
2006-02-09, 10:40
Thanks dude

Regards

Berkine

Lackie
2006-02-10, 11:26
And IPSO 3.8 has a different build of Check Point, R55 for IPSO 3.8 aka as R55p. There is a different series of hotfixes for this. HFA_R55p_06 is the most current and should have all of the fixes that HFA_R55_17 has.

dj_berkine
2006-02-11, 05:53
Hi Lackie

but on my nokia IPSO3.8 i haven't upgrade the R55 to R55p. do i need to do it ? and if yes how

I got IPSO3.7 on R55 and then i upgrade it to 3.8 but still working with the R55

Thanks
Berkine

Lackie
2006-02-11, 13:50
Hi Lackie

but on my nokia IPSO3.8 i haven't upgrade the R55 to R55p. do i need to do it ? and if yes how

I got IPSO3.7 on R55 and then i upgrade it to 3.8 but still working with the R55

Thanks
BerkineR55 isn't a supported package for IPSO 3.8. R55p was made for it specially. R55 may work fine but there may be some problems in the future. If you call Nokia for any help, they will have you upgrade to R55p. There is no physical difference between R55 and R55p, just how it works on the OS.

Upgrading is pretty easy if you wanted to do that.

Youngy
2006-02-12, 19:29
Hi,

I did this upgrade just recently. The pdf with the release:

http://www.checkpoint.com/downloads/latest/hfa.html

was helpful in that it listed the install procedure (I can email it to you if you like (pm me your email). It basically says this:

General Installation Considerations
• It is possible to install R55 PLUS HFA via SmartUpdate. The R55P HFA package,
from R55P HFA_04 and above, should be added to the repository of the R55
SmartCenter server, after which it can be installed using SmartUpdate.
Component Build Number Comment
SVN Foundation 541624002 The output of cpshared_ver
should be:
This is Check Point SVN
Foundation (R) NG with
Application Intelligence (R55)
HFA_06 for IPSO 3.8 (or 3.9),
Hotfix 624- Build 002
Firewall & Kernel 541624004 The output of fw ver -k should
be:
This is Check Point VPN-1(TM)
& FireWall-1 (R) NG with
Application Intelligence (R55)
HFA_06 for IPSO 3.8 (or 3.9),
Hotfix 624 – Build 004 Kernel:
NG with Application
Intelligence (R55) HFA_06 for
IPSO 3.8 (or 3.9), Hotfix 624–
Build 004
HFA/Component SVN Foundation FireWall-1 & Kernel
HFA_R55P_06 (Current) 541624002 541624004
HFA_R55P_05 541560004 541560004
HFA_R55P_04 541480003 541480004
HFAR_R55P_03 541388004 541388003
HFA_R55P_02 541298003 541298011
HFA_R55P_01 541194006 541194003
Check Point NG with Application Intelligence R55 HFA_06 for IPSO 3.8 and IPSO 3.9 Release Notes. Last Update — September 14, 2005 6
• HFA_R55P_06 can safely be installed on:
• Security Gateways that are managed by SmartCenter Server or Provider-1 of version
NG with Application Intelligence R55 General Availability (GA) and up.
• SmartCenter Servers of version NG with Application Intelligence R55 for IPSO 3.8
and IPSO 3.9 General Availability (GA) or previous HFAs.
• Fixes that are relevant for Enforcement Modules only, can be installed on the
Enforcement Module only.
• Before installing HFA_R55P_06, make sure that version NG with Application
Intelligence (R55) for IPSO 3.8 and/or IPS0 3.9 is installed and configured on your
machine.
• Installing HFA_R55P_06 overrides any current support Hotfix that has been applied to
version NG with Application Intelligence (R55) for IPSO 3.8 and/or IPSO 3.9.
• It is recommended to read the ClusterXL Guide prior to applying the HFA in a cluster
environment.
• It is recommended to manually backup the FWDIR and CPDIR directories of the SVN
Foundation and Firewall products before installing HFA_R55P_06.
The directories can be accessed:
• cd $FWDIR and cd $CPDIR
Installation Instructions for IPSO 3.8 and IPSO 3.9
The package SHF_HFA_R55P_06.tgz format consists of the following components:
• install_hfa.
• uninstall_hfa
• files/cpshared_HOTFIX_HFA_R55P_06_541624002
• files/fw1_HOTFIX_HFA_R55P_06_541624004
• files/others…(specific OS files)
1 Extract the package to a temporary directory.
2 Stop the Firewall processes by executing cpstop. In a cluster configuration, execute
cphastop, as well.
3 Execute the install_hfa script in order to start the installation.
4 When the installation is complete, reboot the machine.
5 Install the Security Policy.

The only thing I had to do was change the file properties (chmod 777 etc) in the temp directory on the IPSO that I transfered the files to. I hope I have helped in some way.