[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] Problem installing policy after 4.1 to NG upgrade



You can only install a policy on an object that is recognised as having
FW-1 or VPN-1 installed.
I would double check the London object has all the correct options
ticked.


-----Original Message-----
From: John Gesualdi [mailto:[email protected]]
Sent: 03 September 2002 15:05
To: [email protected]
Subject: [FW-1] Problem installing policy after 4.1 to NG upgrade


Hi,

I built a new management machine on solaris 8, installed NG FP2,  ran
the 4.1 to NG  upgrade script, connected to it via the NG GUI client.
This management station also has "Secure Server" and it's own firewall
policy. I opened up it's security policy and tried installing it on the
management station and it fails with this message:

"Security Policy cannot be installed because London  does not enforce
any part of the Security Policy"

The actual secuirty policy for the management station  has about 5
rules.  This is the same policy I used in FW1 4.1 SP5. Here's a line
from the policy:
"netadmin grp"    "London"   "telnet"    "permit"   "Install On London"

London is the management machine  with secure server.

Any Ideas??? Thanks.


--


John A. Gesualdi,    CCNP , CCDP, MCSE 2000
[email protected]
The Providence Journal Company
PhonePager=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



**********************************************************************
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager.

This footnote also confirms that this email message has been swept by
Dimension Data mail system for the presence of computer viruses.

www.uk.didata.com
**********************************************************************

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================