Hello gurus,

I am going to start a new job on Monday and
one of the first tasks that I will be
doing is to map out a plan to migrate about
25 pairs of firewalls.  They are SPLAT firewalls
NG-AI R55 with HFA_014.  They are being managed
by a single CMA on a Provider-1 NG-AI R55 with
HFA_14.  These SPLAT firewalls are running
clusterXL Active/Active Unicast mode with Floodgate.
They are not being managed by me but by a third party.
We outsource the daily operation to them.

The job at hand is to migrate NG-AI to NGx R61 
with HFA_02.

I guess I can migrate the CMA from NG-AI R55 to NGx
R61 and still manage the R55 enforcement modules.
Are there any caveats that I should be aware of?
In other words, will there be any issues in this
configuration that I should be aware of?

I can migrate both the CMA and the enforcement
modules from NG-AI R55 to NGx R61.  Again,
are there any caveats that I should be aware of?
Like applications that are working in NG-AI that
will stop working in NGx R61?

I found out that in NGx R61 and R65, NAT stops
working if I perform "cpstop;cpstart" on the SPLAT
enforcement module.  I am looking for issues like that.

I am sure there are lot of people that have done
migration/upgrade from NG-AI R55 to NGx and please
tell me the problems that you've encountered,
OS, network, IDS, smartdefense, web intelligence, etc...
I would love to hear from your experiences.

Thank you.
 
       
---------------------------------
Building a website is a piece of cake. 
Yahoo! Small Business gives you all the tools to get online.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to