Hi,

We have a few firewalls in a distributed Checkpoint environment with a
management station
controlling the firewalls across the Internet.

Since upgrading to NGAI we are seeing problem when firewalls modules
boot.

In NG if the module would boot with the last installed policy.

Since moving to NGAI in the boot process we see a message
reverting to initialpolicy

The box then installs the initial policy and tries to pull the policy
from the management station.   If the management station is down
or uncontactable the module is stuck.

Since our management station is behind a NAT the module cannot see the
module and fails until someone does a fw fetch to the real address or
the policy is pushed.

Has anyone else seen this and found a workaround?

Thanks

John

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to