l just upgraded our CMA from R55 HFA09 to R62, and left the Cluster
XL enforcement servers on R55 HFA09 without any issues whatsoever. We
are not running Provider-1 though.
l was told to keep an eye on smart defense, as perhaps it could cause
issues. None have been found so far.
We're still fire fighting the new remote managed gateway though, but
that's unrelated to the upgrade itself.
We'll be upgrading the enforcement modules after the new data center
we're currently focusing on is fully deployed.
Al
At 09:40 AM 8/16/2007, cisco4ng wrote:
Hello gurus,
I am going to start a new job on Monday and
one of the first tasks that I will be
doing is to map out a plan to migrate about
25 pairs of firewalls. They are SPLAT firewalls
NG-AI R55 with HFA_014. They are being managed
by a single CMA on a Provider-1 NG-AI R55 with
HFA_14. These SPLAT firewalls are running
clusterXL Active/Active Unicast mode with Floodgate.
They are not being managed by me but by a third party.
We outsource the daily operation to them.
The job at hand is to migrate NG-AI to NGx R61
with HFA_02.
I guess I can migrate the CMA from NG-AI R55 to NGx
R61 and still manage the R55 enforcement modules.
Are there any caveats that I should be aware of?
In other words, will there be any issues in this
configuration that I should be aware of?
I can migrate both the CMA and the enforcement
modules from NG-AI R55 to NGx R61. Again,
are there any caveats that I should be aware of?
Like applications that are working in NG-AI that
will stop working in NGx R61?
I found out that in NGx R61 and R65, NAT stops
working if I perform "cpstop;cpstart" on the SPLAT
enforcement module. I am looking for issues like that.
I am sure there are lot of people that have done
migration/upgrade from NG-AI R55 to NGx and please
tell me the problems that you've encountered,
OS, network, IDS, smartdefense, web intelligence, etc...
I would love to hear from your experiences.
Thank you.
---------------------------------
Building a website is a piece of cake.
Yahoo! Small Business gives you all the tools to get online.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================