- CheckMates
- :
- Products
- :
- General Topics
- :
- Jumbo HFA before First Time Wizard (FTW) Impacts?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Jumbo HFA before First Time Wizard (FTW) Impacts?
Recently on a client system HealthCheck Point (hcp) flagged that on their SMS a Jumbo HFA was installed before the First Time Wizard was run. I'm well aware that the FTW should always be run to declare what type of Check Point system it will be prior to application of a Jumbo HFA. However what are the ramifications of this? Their SMS appears to be fine otherwise. I can't seem to find anything about this other than what order of operations should be followed.
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I imagine installing a JHF before running FTW would be equivalent to a Blink image (version + JHF integrated) being used as a fresh install.
In other words, I don’t believe there is a specific issue with this, though it is interesting that HCP flagged it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the days before blink I recall seeing issues around this on the odd occasion during standalone installations used as security checkup appliances where things were trying to be done in a hurry. I can't recall the specific failure scenario but the ramifications then were always to start over before the box was fit to go live.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The problem with installing a Jumbo prior to running the FTW is indeed that the machine role wasn't determined yet. Once the machine role is set, some RPMs are being installed by the FTW. Therefore, there is a risk that once FTW is executed after the Jumbo installation, files with fixes can be overwritten by older files that came with the vanilla version.
I'd say that if their system is fine, and if a newer Jumbo was installed successfully since, this can be ignored. But I would recommend installing a newer Jumbo after the execution of the FTW, to make sure the latest versions of all files is indeed deployed on the machine.
BTW - there is a chance that the installation of the newer Jumbo would fail. If it didn't/doesn't, I'd say this issue can be considered as a non issue, and future Jumbos would be installed successfully.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know customer who did this back in R76 (good old days lol) and was fine, but never seen anyone do it in newer versions. I may actually test it in brand new R81.20 lab.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In my past experience, it mostly mattered for firewalls. For example, if you installed R60, installed an HFA, then set it up as a firewall, you would end up with unpatched SecureXL.
