Nokia Network Security Solutions Handbook

Get licenses ahead of time and read the release notes.
Make sure Host Address Assignment is configured along with proper networking (interfaces, routes, and IP forwarding).
Verify IPSO compatibility with the version of FireWall-1 you are installing.
If you're installing NG FP1, you must start with the SVN Foundation and then install the VPN-1/FireWall-1 package.
If you're installing NG FP2 or FP3, use the bundled wrapper install files.
Use newpkg i to install packages.
Ensure that the packages are enabled in the Manage Installed Packages configuration screen.
Run cpconfig to finish the Check Point FireWall-1 configuration. This will prompt you for the type of installation (management and/or firewall module), license key, administrators, management client IP addresses, and ICA/SIC initialization.
Reboot your Nokia after running cpconfig for the first time, before attempting to start FireWall-1.
Log into the management server running on your Nokia via the SmartDashboard (a.k.a. Policy Editor)
Push a policy to your Nokia.
Fetch a policy from your Nokia.
Use the upgrade verifier utilities provided by Check Point to check your configuration for possible problems upgrading from 4.1 to NG.
Upgrade your IPSO image before upgrading the Check Point FireWall-1 software.
The recommended upgrade path is to go from 4.1 SP-6 to NG FP2 via the wrapper package (which installs FP1 also) to NG FP3.
Backing out of an upgrade is as easy as disabling the new packages, enabling the old...