Installation guide

5
Table of Contents
UPGRADING
CHAPTER 12
Upgrading . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
Getting Started With Upgrading . . . . . . . . . . . . 114
Configuration Overview . . . . . . . . . . . . . . . . . 115
Obtaining Installation Files . . . . . . . . . . . . . . 115
Upgrading or Generating Licenses . . . . . . . . . . 117
Upgrading Licenses Under One Proof Code . . . 117
Upgrading Licenses Under Multiple Proof
Codes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117
Installing Licenses . . . . . . . . . . . . . . . . . . . . 118
Checking the Licenses . . . . . . . . . . . . . . . . . 118
Upgrading Engines Remotely . . . . . . . . . . . . . . 119
Upgrading Legacy IPS Engines . . . . . . . . . . . . . 120
Upgrading Sensors and Sensor Clusters . . . . 120
Upgrading a Legacy Sensor-Analyzer to a
Single IPS Engine . . . . . . . . . . . . . . . . . . . . . 120
Removing Unused Analyzer Elements . . . . . . . 121
Upgrading Engines Locally . . . . . . . . . . . . . . . . 122
Upgrading From an Engine Installation DVD . . 122
Upgrading From a .zip File . . . . . . . . . . . . . . . 123
APPENDICES
APPENDIX A
Command Line Tools . . . . . . . . . . . . . . . . . . . . 127
Security Management Center Commands . . . . . 128
NGFW Engine Commands . . . . . . . . . . . . . . . . 139
Server Pool Monitoring Agent Commands . . . . . 147
APPENDIX B
Default Communication Ports. . . . . . . . . . . . . . 149
Security Management Center Ports . . . . . . . . . 150
Security Engine Ports . . . . . . . . . . . . . . . . . . . 153
APPENDIX C
Example Network Scenario. . . . . . . . . . . . . . . . 157
Overview of the Example Network . . . . . . . . . . 158
Example Headquarters Intranet Network. . . . . . 159
HQ IPS Cluster . . . . . . . . . . . . . . . . . . . . . . . 159
Example Headquarters Management Network. . 160
HQ Firewall. . . . . . . . . . . . . . . . . . . . . . . . . . 160
SMC Servers . . . . . . . . . . . . . . . . . . . . . . . . 160
Example Headquarters DMZ Network . . . . . . . . 161
DMZ IPS . . . . . . . . . . . . . . . . . . . . . . . . . . . 161
Index. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 163