[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] AW: [FW-1] Fw: Provider-1 NG FP-1 Problem (Pls. Help)



Title: Nachricht

Hi Marco

 

Problem on migration

v4.1 -> P-1 CMA

  • Successful migrating the rules into cma, but cannot install the policy.
  • Error “ ….complied completed ……Failed to install the policy to module …… : resources temporarily unavailable”

 

NG FP-2 -> P-1 CMA

  • Successful migrating the rules into cma
  • Initiailized the SIC, but running the “test” fail

 

Could you give me more hints or step by step guide to resolve this problem ? Thanks

 

Regards,

Lawrence

 

 

 

 

-----Original Message-----
From: Mailing list for discussion of Firewall-1 [mailto:[email protected]] On Behalf Of fw1mail
Sent: Wednesday, June 19, 2002 10:33 PM
To: [email protected]
Subject: [FW-1] AW: [FW-1] Fw: Provider-1 NG FP-1 Problem (Pls. Help)

 

Hi All,

 

nice to see that I�m not the only one who runs into much problems with provider-1. Since last week I tried the P-1 FP2 Version (released) and

it seems better to work. I tried no update from the P-1 FP1 HF1 Version.

 

Here are some of my experiences:

1. cma_migrate

        create CMA

add the CMA license per cut and paste in the MDG while creating the cma 

1.       migrating the fw into CMA

2.      start CMA

3.       

4.       I migrated a very big 4.1 gateway (objects.C > 1,8 MB / 275 Rules). I�m wondering, but except the names of 4 networks objects I�ve

5.       had no problems.

6.        

2. secure update

7.      it seems to work - but only one time - at the moment I use eval licenses for the CMA and P-1 warns me that the license already has used...

8.      so I can�t say more to that ... perhaps in a few weeks  

9.       

3. logging

10.  the MLM/CLM Logging works now fine with the procedure I described earlier. PS: nobody from checkpoint could tell my this procedure (!!!)

11.  they opened a call three weeks ago. I found this informationen by a fluke under 5 subtrees in the online help of the P-1 FP2 MDG Version !!!

12.  At the moment anything works ... now I�m going to start with global objects. (we want to use global objects for our total enviroment) Has anybody

13.  experiences with migrating the network objects of an older management station or cma into global objects ??? I know that�s no buildin feature of provider-1,

14.  but perhaps are sciptings existing which can do that. (with using dbedit or directly manipulate of the objects_5_0.C file)

15.   

16.   

17.  Okay ... much stuff ... my suggestion: let�s make our own P-1 experience group ... ;-)

18.   

19.  Bye

20.  Marco

21.   

22.   

 -----Urspr�ngliche Nachricht-----
Von: Mailing list for discussion of Firewall-1 [mailto:[email protected]] Im Auftrag von Lawrence Tsui
Gesendet: Mittwoch, 19. Juni 2002 14:49
An: [email protected]
Betreff: Re: [FW-1] Fw: Provider-1 NG FP-1 Problem (Pls. Help)

Mike,

 

Thank for your useful info.

 

In my testing, the rule migrated also fine, only cannot install policy, error is “resources temporarily unavailable”.

 

How about your migration procedure ?

 

My procedure

23.   create CMA

24.   migrating the fw into CMA

25.   start CMA

26.   add the CMA license thru command line (Not SecureUpdate)

 

Remark: using SecureUpdate cannot add the CMA license.

 

Regards,

Lawrence

 

-----Original Message-----
From: Mailing list for discussion of Firewall-1 [mailto:[email protected]] On Behalf Of Mike Richards
Sent:
Wednesday, June 19, 2002 7:58 PM
To: [email protected]
Subject: [FW-1] Fw: Provider-1 NG FP-1 Problem (Pls. Help)

 

Lawrence,

 

  I had problems migrating P-1 4.1 -> P-1 FP1....the rules migrated fine, but the

 SIC stuff didn't initialize...here's what I did to fix that from my troubles, 1-331004310, I filed with Checkpoint; you can't migrate from P-1 FP1 to FP2 yet either for similar problems.  They've had that

problem for 3 weeks now.

 

>Jerry,
>  I've made more progress since my last update...

>

> I whacked my SIC stuff and did a "cp_conf ca init"
> which seemed to fix the SIC mess....

>

> My PC MDG client now connects to the MDS server...my
> 1st CMA license did not get installed correctly, so I
> used the GUI to add it...I'm not receiving any log info
> from the 2 FWM's it manages....

>

> Trying to add the 2nd CMA license fails via GUI for
> some unknown reason.....

 

> OS = Solaris 7
> cluster patch level = Generic_106541-18
> NG = FP1 from WWW site

 

>Jerry,

>

>  Finally got it working; I added /opt/CPfwbc-41/lib to
> the LD_LIBRARY_PATH before starting mds(mdsstart)

 

 

Mike

 

----- Original Message -----

Sent: Wednesday, June 19, 2002 7:10 AM

Subject: Re: [FW-1] Provider-1 NG FP-1 Problem (Pls. Help)

 

Torkel,

 

Thanks.

 

But I’m using the eval license with full feature.

 

Right now, I met so many many problem on P-1 NG FP-1, still cannot resolve !

 

Regards,

Lawrence

 

-----Original Message-----
From: Mailing list for discussion of Firewall-1 [mailto:[email protected]] On Behalf Of Torkel Mathisen
Sent:
Wednesday, June 19, 2002 6:47 PM
To: [email protected]
Subject: Re: [FW-1] Provider-1 NG FP-1 Problem (Pls. Help)

 

Adding the CMA license by command line or SecureUpdate ? By SecureUpdate doesn't work !!

Not helpful for you I am afraid, but is there a separate license for SecureUpdate?

 

Regards,

Torkel