Hi All,

 

There are currently about 15 IP 40's deployed in a star VPN community
configuration managed by a R55 SmartServer and SmartLSM. At the time when
some of them were being deployed, there was no SmartLSM involved and hence
they have been all configured to use shared secret instead of default cert
in the VPN community. With the change in our environment from a regular
management server to Provider-1, we are planning to migrate all these IP 40
sites to a new CMA. We plan on converting each IP 40 to use default cert
instead of shared secret. The process will involve some downtime but we are
planning on changing to defaultCerts because our understanding is that
'shared secret' is to be used only when the GW happens to be externally
managed but since all these sites are otherwise working OK w/ shared secret,
there is a hesitancy to make the changes that obviously involve some
downtime. There are two questions:

 

1.      Is it OK to use 'shared secret' the way they are currently being
used in our new CMA configured to use SmartLSM to manage these IP 40's also?
Are there any potential issues with shared secret usage even though they are
ostensibly internally managed? 
2.      Has anyone fallen into this trap before and if so, any suggestions
from experience that can help a painless migration?

 

Any input will be highly appreciated.

 

Thanks in advance,

 

 

Rajeev

 

 


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to