Extracted from our Firewall-1 FAQ http://www.tla.ch/TLA/FW/FW1FAQ.html
Management station separation ============================== The principle is the following: Prepare separate licenses Install a seperate management station in the same version as you have 4.1 SPx Transfer the configuration files from the 4.1 firewall with management station to the management station. $FWDIR/conf/objects.C (objects and properties) $FWDIR/conf/*.W (security policy) $FWDIR/conf/rulebases.fws (Combined rule bases for GUI clients) $FWDIR/conf/fwauth.NDB (User database) $FWDIR/conf/fwmusers Adminstrators $FWDIR/conf/gui-clients Allow GUI Adminstrative hosts Note: Any *.NDB files must be transferred in binary mode. All other files should be transferred in ASCII mode. Test your management station to see if it operates correctly From then on you are set with a seperate management station, but work is not finished. You will need to start to work with a distributed firewall module. This means that you need to re-install the firewall module. Perform the authentication between the console and the firewall module. Now you should be able to have exchanges between the management console and the firewall module. Adapte the security policy if required. Load the security policy. Bye for now, Christian ALT Telecom and Logistics Associates Network and Security Company Firewall-1 FAQ http://www.tla.ch/TLA/FW/FW1FAQ.html -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] Behalf Of Katsumi, Fred Sent: lundi, 26. janvier 2004 14:02 To: [EMAIL PROTECTED] Subject: Re: [FW-1] Having difficulty upgrading 4.1 to NG R55 That's correct. I looked everywhere but I can't find any doc that tells how to separate the management and enforcement modules either in 4.1 or NG. Can anyone give me point me the right direction? Thank you. Fred > -----Original Message----- > From: Mailing list for discussion of Firewall-1 > [mailto:[EMAIL PROTECTED] On Behalf > Of Christian ALT > Sent: Monday, January 26, 2004 5:25 AM > To: [EMAIL PROTECTED] > Subject: Re: [FW-1] Having difficulty upgrading 4.1 to NG R55 > > If I understood you right you have both firewall and > management module on an NT box in version 4.1. > > And you want to migrate to NG 55 with a seperate management > station on a specific win2003 box, as well as a seperate > firewall module on win2003. > > My suggestion is either migrate > > management and firewall module to NG and then seperate > > or > > seperate in version 4.1 and then perform the migration. This > is my prefered way to do. > > > > Christian ALT > > Telecom and Logistics Associates > Network and Security Company > > Firewall-1 FAQ http://www.tla.ch/TLA/FW/FW1FAQ.html > > > > > > > -----Original Message----- > From: Mailing list for discussion of Firewall-1 > [mailto:[EMAIL PROTECTED] Behalf > Of Katsumi, Fred > Sent: vendredi, 23. janvier 2004 01:59 > To: [EMAIL PROTECTED] > Subject: [FW-1] Having difficulty upgrading 4.1 to NG R55 > > > Hello everyone, > > I am trying to migrate from a single NT4 box running 4.1 SP5 > to a distributed NG R55 on two Win2003 boxes. My license is > VEE and not a single gateway license; I just have the two > modules in one NT box. I am following the advanced upgrade > method with spare hardware to try to pull this off. > > My problem is that when I export the existing 4.1 > configuration and try to import it during the installation of > R55 the install seems to go ok but the end result is a > standalone box with the VPN-1 and the SmartCenter together. > I think the install program sees the existing configuration > as standalone and installs both the enforcement module as > well as management station. I have no choice to separate the > two during the install. What steps can I take to accomplish this? > > Thank you. > > Fred > > ================================================= > To set vacation, Out-Of-Office, or away messages, send an > email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your subscription > options, email [EMAIL PROTECTED] > ================================================= > --- > Incoming mail is certified Virus Free. > Checked by AVG anti-virus system (http://www.grisoft.com). > Version: 6.0.564 / Virus Database: 356 - Release Date: 19.01.2004 > > --- > Outgoing mail is certified Virus Free. > Checked by AVG anti-virus system (http://www.grisoft.com). > Version: 6.0.564 / Virus Database: 356 - Release Date: 19.01.2004 > > ================================================= > To set vacation, Out-Of-Office, or away messages, send an > email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your subscription > options, email [EMAIL PROTECTED] > ================================================= > ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= --- Incoming mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.564 / Virus Database: 356 - Release Date: 19.01.2004 --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.564 / Virus Database: 356 - Release Date: 19.01.2004 ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
