You're right. My reply was concerning updates in general. What I meant was that if you update from a version that is the lastest version before the update. Then the hotfix you apply has most certainly been tested on the latest version before the update than it has on prior versions.
/Simon -----Original Message----- From: Schiller, Mark [mailto:[EMAIL PROTECTED] Sent: 11. august 2004 15:15 To: [EMAIL PROTECTED] Subject: Re: [FW-1] Approach to hot fixes? They better have tested HFA08 with upgrading from HFA04 at least as much, since HFA05-07 were never publically released, so most people, even if upgrading evey HFA they can, will be going HFA04 to HFA08. -----Original Message----- From: Simon �stengaard [mailto:[EMAIL PROTECTED] Sent: 11 August 2004 09:44 To: [EMAIL PROTECTED] Subject: Re: [FW-1] Approach to hot fixes? You should confsider the fact that if you don't update to the lastest hotfix: 1. You will have to go through all the release notes for unapplied hotfixes if you change the way you use your firewall. 2. It is always better to be fully patched than "patched if the vulnerability applies to my situation". Maybe the vulnerability is not exploitable from the internet in your setup. But an attacker might be able to exploit it from an already compromised server in your network. You can almost be certain that the proccess of applying HFA-08 to a HFA-07 installation is more tested by checkpoint QA than the proccess of applying HFA-08 to a HFA-04 installation or any version prior to HFA-07. Staying up to date with security patches often breaks functionality. But i'll guess we'll have to live with that. /Simon -----Original Message----- From: Tom Stala [mailto:[EMAIL PROTECTED] Sent: 10. august 2004 17:02 To: [EMAIL PROTECTED] Subject: Re: [FW-1] Approach to hot fixes? Best practice in my opinion about anything, if it ai'nt broke don't fix it. If you upgrade to version 8 from 4 you might be braking something that was working fine. ----- Original Message ----- From: "Shane Presley" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, August 10, 2004 10:20 AM Subject: [FW-1] Approach to hot fixes? > Just curious... > > Do you regularly keep your firewalls up to date with the Check Point > hot fixes? Or do you wait for the need? For example I'm currently on > HFA-04, but HFA-08 is out. I've read the release notes on HFA-08 and > don't see anything that would immediately impact me, so I don't think > there's a pressing need to put HFA-08 on it. > > But is it a "best practice" to always apply the latest HFA? > > Shane > > ================================================= > To set vacation, Out-Of-Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= This e-mail has been scanned for viruses by the Cable & Wireless e-mail security system - powered by MessageLabs. For more information on a proactive managed e-mail security service, visit http://www.cw.com The information contained in this e-mail is confidential and may also be subject to legal privilege. It is intended only for the recipient(s) named above. If you are not named above as a recipient, you must not read, copy, disclose, forward or otherwise use the information contained in this email. If you have received this e-mail in error, please notify the sender (whose contact details are above) immediately by reply e-mail and delete the message and any attachments without retaining any copies. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
