Peter,

> From: "Ro�manith, Peter" [SMTP:[EMAIL PROTECTED]]
> Subject:      [FW1] Securemote 4118 DES   and    FW-1 SP2 3DES
> 
> 
> Hi World,
> i want to upgrade my fw1 4.1 SP2 DES to 3DES SP2.
> most of my Securmote clients are 4118 DES.
> 
> is there a problem with this combination ?
> i want to upgrade my clients one after the other.
> 
You will have problems if you change the Rulebase to use 3DES before the
SecuRemote clients are upgraded.  The reason for this is that 3DES-capable
software can encrypt or decrypt using DES, but DES-only software will NEVER
decrypt 3DES-encrypted data.

Thus, you should do the upgrades in the  following order:
1: Upgrade the firewall software to 3DES, without changing the encryption
algorithms from DES to 3DES.
2: Install/upgrade SecuRemote to 3DES-capable version
3: Change the encryption properties in rules to use 3DES.

Note that you may not be able to specify 3DES unless the license features in
the management station include strong encryption.


Tim

-- 
Timothy Frost                   mailto:[EMAIL PROTECTED]
EDS New Zealand                 Fax: +64-4-495-0473
8 Gilmer Terrace                        Phone: +64-4-495-0504
P O Box 3647
Wellington
New Zealand


> Mit freundlichem Gru�
> Peter Ro�manith       
> EDV Abteilung
> Fa. Stetter GmbH              
> Dr.-Karl-Lenz-Str. 70         
> 87700 Memmingen               
> Phone +49 (0)8331-78-202
> Fax +49 (0)8331-78-275
> mailto:[EMAIL PROTECTED]
> http://www.stetter.de
> 
> 
> 
> 
> 
> ==========================================================================
> ======
>      To unsubscribe from this mailing list, please see the instructions at
>                http://www.checkpoint.com/services/mailing.html
> ==========================================================================
> ======


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to