I think this should be simple, but would folks let me know what I'm
missing with this plan. Unlike all the config documents I could find at
Checkpoint, I am not making a version change while doing this. Just
splitting the enforcement from the server into different boxes.
Current Config: firewall (NG_AI) on Win2k with all Checkpoint on same
box.
Target Config:
firewall (same hardware) using SecurePlatform
Management server on different box
The plan:
1. copy the conf off the current firewall. Save it for now.
2. install new copy of NG_AI and only do the management/log server
options.
3. get new license codes due to IP change. (How?? Just use SmartUpdate
center??)
4. stop new management server, copy saved conf over it, restart
management server.
5. enter the new license codes via the config tool.
6. install SecurePlatform on firewall box. It's a Compaq box. Should I
use their SmartStart or not?? And if so, how??
7. Establish SIC with the new management server.
8. Load policy.
Notes: At least I've got spare disks (all hot swap) so I can clone and
save at different steps to provide a fall back. What hints do people
have to make this as painless as possible?? And for those keeping score
the main reason is that the cost in licenses and time to keep Win2k on
the box is just getting too much pain!!
-ken cameron, CCP.
SkyDiver: Zoo-602, A-8596, D-11839.
Skier: down & cross. English Hunter Rider. Scuba: wet & dry
mailto: [EMAIL PROTECTED] Home DZ: FingerLakes Skydivers,
Ovid NY
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================