The following procedures explain how you prepare for and generate the new SunScreen 3.1 configuration.
Choosing which of the next two procedures to follow depends on whether you plan to run SunScreen 3.1 on the former FireWall-1 machine or on a new machine. Option 1 discusses preparing the FireWall-1 machine to become a SunScreen machine. Option 2 discusses preparing a new machine to run the converted FireWall-1 configurations.
Choose only one option or the other.
Open a terminal window and become root.
Save the existing FireWall-1 configuration files located in the /opt/SUNWfw/conf directory as a backup.
Use the pkgrm command to remove the SUNWfw package by typing:
# pkgrm SUNWfw |
Upgrade your operating environment to at least Solaris 2.6 (if not already done).
See your Solaris documentation for instructions, if necessary.
Install the additional Solaris packages and kernel packages required as listed in "Installation Overview" (if not already done).
Prior to installing the SunScreen software, make sure that the machine is performing properly as a router.
Install the SunScreen 3.1 software as described in "Installing in Routing Mode With Local Administration."
Continue to the section, "To Generate the New SunScreen Configuration."
Prior to installing the SunScreen 3.1 software, make sure that the machine is performing properly as a router.
Open a terminal window and become root.
Upgrade your operating environment to at least Solaris 2.6 (if not already done).
See your Solaris documentation for instructions, if necessary.
Install the additional Solaris packages and kernel packages required as listed in "Installation Overview" (if not already done).
Copy the generated configuration files to a directory on the new SunScreen machine.
Install the SunScreen 3.1 software as described in "Installing in Routing Mode With Local Administration."
Continue to the section, "To Generate the New SunScreen Configuration."
Open a terminal window and become root.
Change to the directory where the conversion files were saved and make the policy.name_sscfg file executable by typing:
# chmod 544 policy.name_sscfg |
Verify that the commands in the generated file are accurate.
Run the script by typing:
# ./policy.name_sscfg |
policy.name_sscfg creates the new SunScreen configuration from the FireWall-1 configuration, which is similar to the FireWall-1 policy.
See the SunScreen 3.1 Administration Guide for instructions on activating the configuration.