Frequently Asked Questions (FW-1 NG Operational Changes) (Check Point)

The following Frequently Asked Questions, answered by the authors of this topic, are designed to both measure your understanding of the concepts presented in this topic and to assist you with real-life implementation of these concepts.

Q: What does the option for Allow bidirectional NAT on the NAT Settings page of Global Properties do?

A: This setting allows for two different NAT rules to apply to a packet in cases in which both the source and destination IP addresses need to be changed.

Q: What are the default settings for NAT when I’m installing or upgrading to FP3?

A: On the NAT Settings page of Global Properties, all features are enabled for a new install, and an upgrade will leave the client side disabled for compatibility.

Q: If I am upgrading a system to FP3 and I have already configured ARP entries in the operating system, do I need to use the Automatic ARP feature?

A: No, but in some cases, manually configured ARP settings will not work unless you disable the Automatic ARP feature.

Q: Do I have to upgrade to an earlier Feature Pack of NG before upgrading to FP3? A: No, you can go directly from 4.1 to FP3.

Q: Can I just build a new FP3 management server and copy my 4.1 database files?

A: No, the whole architecture has been modified in NG. There have been modifications between the NG Feature Packs as well.


Q: If modifications are made to the $FWDIR/lib/base.def file prior to an upgrade, will this hold across a Feature Pack upgrade of NG?

A: No, you will need to make these changes to the new base.def file after upgrading.

Q: At the end of building a new NG management station from the FP3 CD, a window opens reminding me to remove the CD before rebooting. I remove the CD and click OK. Why do I get an error message looking for a file from the CD?

A: There is a bug with the CD.The installation script still needs access to files from the CD after the popup window tells you to remove the CD.You can either reinsert the CD or not remove it until the machine begins rebooting.

Next post:

Previous post: