Check Point NG VPN-1/FireWall-1: Advanced Configuration and Troubleshooting

Installing FireWall-1 NG FP3

We start the practical side of our clustering discussion by running through installation of the Check Point enforcement modules that will form our cluster. This process is not exceptionally different from installing on an ordinary module, but we highlight the areas of the installation that are relevant to clustering. It s also a good refresher to make sure that you have not forgotten to do something important! We are assuming that we have a healthy management station already running.

Checking the Installation Prerequisites

Follow these steps to check the installation prerequisites:

  1. Ensure that your OS meets the requirements documented in the Check Point release notes. On the Windows 2000 platform, make sure that SP2 or SP3 is installed. On Solaris, make sure that the latest cluster patch its installed (e.g., solaris8_Recommended.zip about 80MB). Make sure that the SUNWter package is installed on Solaris. You need this package before you can run UnixInstallScript from the NG FP3 CD or wrapper.

  2. On the Nokia platform, download the latest version of IPSO that is compatible with NG FP3.

  3. It strongly recommended that you have all your interfaces configured and working on the firewall modules and your management server before you install FireWall-1 NG FP3. Make sure that you have tested that each interface is up and running.

  4. Make sure that the member clocks are synchronized; see the sidebar The Importance of Time.

  5. Carefully read the Check Point NG FP3 release notes before proceeding. This is important!

Tools & Traps The Importance...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Check Valves
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.