We just upgraded an NT4-based Firewall-1 4.0 SP5? to 4.1 SP3 today. The
upgrade, service pack, and license key install went OK. The machine
came back up and internet access worked fine after putkeys. However, we
could not install policy. I eventually found that I had to change an
option on the firewall object to reflect the fact it is now 4.1 vs.
4.0. I managed to install policy once after the change. Now, I can't
install policy at all. It says "connection timed out".
We tried putkeys again but had no success with policy install.
Interestingly, before I switched the firewall object to 4.1, I was
getting log info, after the successful policy install, logging broke.
I'm assuming the problem is the firewall doesn't recognize the
management station as such. The question is, how do I solve this?
HB
Rating: 0%, 0 votes
before. Be sure to issue an fwstop before issuing the putkey command, and
use this format:
fw putkey -p <password> <ip_of_mgmt/fw>
You should also try specifying ALL interface IP addresses on the firewall
when you issue the putkey from the mgmt server.
After an fwstart, on the firewall issue "fw unload localhost" then try "fw
fetch <ip_of_mgmt_server>. If this works try pushing a policy. If it
fails, do this over again using a DIFFERENT password.
Also verify that the correct IPs are listed in cpconfig (master/enforcement
module).
--
/ki
asi
Was this solution helpful? Show your Appreciation by rating it:
Post a New problem for Accusys Acuta -DESKRAID Combo
Email this problem

