Firewall-1

[FW-1] "Safely" rebuilding a management station?

Subject: [FW-1] "Safely" rebuilding a management station?
From: "Morhous, John" <morhous AT TERI DOT ORG>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Mon, 25 Aug 2003 11:31:05 -0400
FW's: Checkpoint FP3 on Nokia IP330 IPSO 3.6 (cluster)
Mgmt: Windows 2000 Pro SP3

Ran into a problem where our management server configuration has become
"bad". Working through support @ Checkpoint, they are saying that there
is something screwing up the policy which is causing the FW daemon not
to load on the management station. To make a long story short, after
searching around for a fix and working with Checkpoint, they are telling
us to rebuild the management station.

My question: Does anyone have a guide (so-to-speak) of a safe method for
rebuilding the management station WITHOUT taking down the FW's (or at
least minimizing FW down-time as much as possible)?

I realize I'm going to have to rebuild, re-setup central licensing, redo
the SIC's, reload the policies, etc, which will require (at least all
that I can think of) a cpstop/start on the FW's to take the new SIC, but
are there any other "gotchas" out there I'm forgetting?

Thanks,
-JTM

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>