|
|
|
Clavister Firewall Changes from v7.0x to v8.00.00
Release date: 2002-11-14
[ISO]
Clavister Firewall 8.0 contains a large set of changes from 7.0x.
This document will not list all small changes, but rather concentrate
on the most notable ones, and describe the upgrade procedures
involved in moving from 7.0x to 8.00 firewalls and managers.
This document is primarily meant for users of previous version of
Clavister Firewall; new users are referred to the User's Guide.
For future reference: This document is stored in the "Docs"
sub-folder of your Firewall Manager install folder, e.g.
C:\Program Files\Clavister\Firewall Manager 8\Docs.
Change logs / release notes for earlier versions of Clavister Firewall
are available in the release notes section of
www.clavister.com/support.
|
| List of major changes from 7.0x |
|
| Upgrading the manager |
|
"Upgrading" the manager is not much of an issue, as it is not, strictly speaking, an upgrade. The v8 manager is named "FWMgr8.exe", and will not overwrite older managers, It is also, by default, installed in a completely separate directory, and we recommend that users not try to install it on top of older versions. There are substantial changes to the database format, file layouts, etc.
We do not recommend that you attempt to connect to old datasources
with the new manager. Rather, firewalls should be moved, one by one
as they are upgraded, from the old datasource to a v8 datasource.
Note that even though v8 managers can read v7 firewall configurations,
they cannot be used to manage v7 firewalls, as they generate configuration
files with new configuration directives that old firewalls will not understand.
|
| Upgrading firewalls via new boot media |
|
Preparations before upgrading: For the most reliable remote upgrade path, we recommend copying the firewall entry from the old management datasource to the new one.
Getting a license file for the firewall to use:
Upgrading the firewall itself:
After booting, the running firewall is a v8.00.00 firewall, but
it has not been activated with a license. It will be running in
2-hour evaluation mode.
Uploading the license file to the upgraded firewall:
|
| Upgrading firewalls remotely (all appliances) |
|
As Clavister Firewall v8 uses a completely new operating system, the upgrade procedure from earlier versions is not a straightforward as it usually is.
The remote upgrade procedure will work for all Clavister appliances. For maximum safety in upgrading non-appliance firewalls, we recommend doing a local upgrade (providing new boot media). Note that the upgrade procedure will wipe the filesystem clean in order to install the new operating system. Only files essential to the operation of the firewall are retained (e.g. encryption keys, configuration, etc.). Preparations before upgrading: For the most reliable remote upgrade path, we recommend copying the firewall entry from the old management datasource to the new one.
Getting a license file for the firewall to use:
Upgrading the firewall itself:
After the reboot, the running firewall is a v8.00.00 firewall, but
it has not been activated with a license. It will be running in
2-hour evaluation mode.
Uploading the license file to the upgraded firewall:
|
| HA upgrade procedure |
|
The state synchronization protocol in v8 is not compatible with the protocol used by v7. This means that you cannot upgrade your HA cluster without losing all open connections. Follow either one of the above upgrade procedures, but with the following changes:
|