Somewhere on CP's site you'll find a 118-page doc named "Cross_Protections.pdf" which lays out precisely how an NGX management station will react with non-NGX enforcement modules for SD and WI stuff. I don't remember where I found it, though.

Overview and Purpose
This guide is divided into a number of sections and chapters that provide an overview
of how NGX R60 SmartDefense and Web Intelligence protections work with the
following previous versions:
• NG FP3
• NG With Application Intelligence R54
• NG With Application Intelligence R55 (including R55P)
• NG With Application Intelligence R55W
The intention of this guide is to provide system administrators with an understanding about the implication of each protection when installing a policy on previous releases
(in other words, backwards compatibility)

FWIW,

Ray


From: Thorsten Behrens <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1 <[email protected]>
To: [email protected]
Subject: Re: [FW-1] NGX upgrade
Date: Wed, 17 Aug 2005 10:35:46 -0400

>>
your mgmt should be at least FP3 to be upgraded to NG X.

you can manage any NG-module (NG FCS to NG AI R55) with NG X management.
>>

Actually, FP3 is the lowest version that is of any use with NGX. Contrary to what the release notes say, you cannot manage anything prior to FP3, or not reliably so, and you cannot upgrade from releases prior to FP3.

There's a couple more caveats, like some VPN settings not being preserved through the upgrade - and we've seen some funkyness with DCE/RPC traffic through an FP3 firewall managed by a non-FP3 mgmt station. Since the mgmt station upgrade is the hardest bit, I'd recommend bringing the modules up to NGX too as soon as possible.

Regards

Thorsten Behrens
Senior Security Engineer
CCMSE CCSE+ CCNA CNE

INTEGRALIS
Your Trusted Security Partner

111 Founders Plaza
13th Floor
East Hartford, CT 06108
USA
Tel: +1 860 291 0851 x 2244
Fax: +1 860 291 0847
[EMAIL PROTECTED]

www.integralis.com




Please note that:

1. This e-mail may constitute privileged information. If you are not the intended recipient, you have received this confidential email and any attachments transmitted with it in error and you must not disclose, copy, circulate or in any other way use or rely on this information. 2. E-mails to and from the company are monitored for operational reasons and in accordance with lawful business practices. 3. The contents of this email are those of the individual and do not necessarily represent the views of the company. 4. The company does not conclude contracts by email and all negotiations are subject to contract. 5. The company accepts no responsibility once an e-mail and any attachments is sent.

http://www.integralis.com

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to