l followed our support providers recommendations regarding upgrading our IP440 from IPSO 3.5FCS10 & 4.1 SP6 to IPSO 3.7 & NG FP3, and our objects and policies did not migrate to NG.
l will give you a slightly detailed description of what l have done so far, so you could see if potentially l have done something incorrect.
l started from scratch on our backup stand alone IP440 by installing IPSO 3.5FCS10 and FW1 4.1 SP6 to emulate our current production box.
l then copied a voyager backup of our IPSO and 4.1 SP6 directories to the backup FW and successfully restored it. At this point we had a mirror of our current production box, which l could check with voyager and the Policy GUI to ensure that all settings, objects and policies had been successfully migrated.
Ran "pre_upgrade_verifier" and there were no show stoppers (only showed "generic user" and "log short and long" messages with no action required).
l then installed IPSO 3.7 using "newimage", and then installed NG packages cpshared_NG_FP3_53267_2_Nokia.tgz & fw1_NG_FP3_53225_5_Nokia.tgz, ensuring to use the upgrade option for the fw1 package which identified the 4.1 SP6 install and seemed to have no issues in processing it.
However, after the reboot, and selecting the new packages via voyager, it was obvious from the NG FP3 GUI that neither the objects, nor policies were actually migrated/merged.
Did l do anything incorrectly? Or perhaps were the instructions l was given incorrect? Is it because the IP440 is stand alone with no separate management station?
Looking in the Checkpoint upgrade to NG utilities l found cpmi_tools_B53032_1_ipso.tgz which l assume could allow me to merge my 4.1 SP6 objects and policies into NG FP3. The PDF document that came with it does not detail which FW1 versions are compatible.
l imagine l need to copy more than just the object and Policy files to the NG FP3 conf directory. Is this so?
Has anyone had much experience with this cpmerge tool? Will it work with 4.1 objects and Policies? Are there any gotcha's with it?
Thanks in advance.
Alan.
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
