Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Timothy_Hall
Champion
Champion

Jumbo HFA before First Time Wizard (FTW) Impacts?

Recently on a client system HealthCheck Point (hcp) flagged that on their SMS a Jumbo HFA was installed before the First Time Wizard was run.  I'm well aware that the FTW should always be run to declare what type of Check Point system it will be prior to application of a Jumbo HFA.  However what are the ramifications of this?  Their SMS appears to be fine otherwise.  I can't seem to find anything about this other than what order of operations should be followed.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
5 Replies
PhoneBoy
Admin
Admin

I imagine installing a JHF before running FTW would be equivalent to a Blink image (version + JHF integrated) being used as a fresh install.
In other words, I don’t believe there is a specific issue with this, though it is interesting that HCP flagged it.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

In the days before blink I recall seeing issues around this on the odd occasion during standalone installations used as security checkup appliances where things were trying to be done in a hurry. I can't recall the specific failure scenario but the ramifications then were always to start over before the box was fit to go live.

CCSM R77/R80/ELITE
0 Kudos
Tsahi_Etziony
Employee
Employee

The problem with installing a Jumbo prior to running the FTW is indeed that the machine role wasn't determined yet. Once the machine role is set, some RPMs are being installed by the FTW. Therefore, there is a risk that once FTW is executed after the Jumbo installation, files with fixes can be overwritten by older files that came with the vanilla version. 

I'd say that if their system is fine, and if a newer Jumbo was installed successfully since, this can be ignored. But I would recommend installing a newer Jumbo after the execution of the FTW, to make sure the latest versions of all files is indeed deployed on the machine. 

BTW - there is a chance that the installation of the newer Jumbo would fail. If it didn't/doesn't, I'd say this issue can be considered as a non issue, and future Jumbos would be installed successfully. 

the_rock
Legend
Legend

I know customer who did this back in R76 (good old days lol) and was fine, but never seen anyone do it in newer versions. I may actually test it in brand new R81.20 lab.

0 Kudos
Bob_Zimmerman
Authority
Authority

In my past experience, it mostly mattered for firewalls. For example, if you installed R60, installed an HFA, then set it up as a firewall, you would end up with unpatched SecureXL.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events