[Date Prev][Date Next][Thread Prev][Thread Next][Thread Index]
RE: [fw1-gurus] r55 upgrade
Stopping the firewall management server has no real effect on the module other than (if configured as log server too) the module will not log during the down time. Of course you wont be able to manage the box either and remote access may be effected too. The logs will update once the box is back on line.
In other words, you "should" be safe enough to upgrade during working hours but if things go a bit Pete Tong you should schedule a freeze on any Firewall rule changes.
Regards
-----Original Message-----
From: Ed Dotorg [mailto:edudotorg@xxxxxxxxxxxxx]
Sent: 21 December 2004 21:38
To: fw1-gurus@xxxxxxxxxxxxxxxxxx
Subject: [fw1-gurus] r55 upgrade
Hello all,
I'm planning to upgrade from r54 -> r55 (solaris).
The environment is two boxes, one management server
and one enforcement module.
Beginning with the management server I ran the pre
upgrade verifier (with no errors reported) and was
ready to continue with the upgrade. After starting
the UnixInstallScript I was instructed to exit, then
run cpstop -fwflag -proc, then restart
UnixInstallScript.
Question... Does running cpstop on the management
server have any effect on the enforcement module or
does it stop only the Checkpoint services that are
running on the management server?
I saw nothing mentioned in the r55 upgrade guide about
running cpstop. I hoped I could upgrade the
management server during business hours and not shut
down the enforcement module. I planned on upgrading
the enforcement module as an after hours project.
Thanks,
Ed
---------------------------------------------------------------------
FireWall-1 Gurus Mailing List (http://www.phoneboy.com/gurus)
To unsubscribe, mailto:fw1-gurus-unsubscribe@xxxxxxxxxxxxxxxxxx
For additional commands, mailto:fw1-gurus-help@xxxxxxxxxxxxxxxxxx
This mail has originated outside your organization,
either from an external partner or the Global Internet.
Keep this in mind if you answer this message.
This e-mail is intended only for the above addressee. It may contain
privileged information. If you are not the addressee you must not copy,
distribute, disclose or use any of the information in it. If you have
received it in error please delete it and immediately notify the sender.
Security Notice: all e-mail, sent to or from this address, may be
accessed by someone other than the recipient, for system management and
security reasons. This access is controlled under Regulation of
Investigatory Powers Act 2000, Lawful Business Practises.
---------------------------------------------------------------------
FireWall-1 Gurus Mailing List (http://www.phoneboy.com/gurus)
To unsubscribe, mailto:fw1-gurus-unsubscribe@xxxxxxxxxxxxxxxxxx
For additional commands, mailto:fw1-gurus-help@xxxxxxxxxxxxxxxxxx
|