cancel
Showing results for 
Search instead for 
Did you mean: 

Is IVE 6.3R2 Ready for Primetime?

DanSmart_
Contributor

Is IVE 6.3R2 Ready for Primetime?

I'm installing some new ISG firewalls with IDPs, so I'm going to be doing an NSM upgrade to 2008.2. This would be a good time to add my SA boxes to NSM. Was wondering if IVE 6.3 is stable enough for a heavily used (200 user ave) SA 4000 box?

I'm currently at 6.0R8 but wouldn't mind getting the Firefox 3 issues fixed as well as manage change control in NSM.

Any advice?

TIA

-=Dan=-

11 REPLIES 11
Jickfoo_
Super Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

Even if the code is stable, the upgrade process will be hairy especially if your using Host Checker. If you have a test box, try migrating 50 users or so to get a sense of the issues you will encounter. Upgrades are my biggest complaint about NetConnect. It's a lot to upgrade to new switch code and have all your users upgraded all at once, you will get calls. I wish Juniper would create a client independent of the switch code. I cant comment specifically on the stability of 6.3R2 but I've learned to wait until R5's or higher.

Good Luck..

DanSmart_
Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

Good Suggestions.

The SA box has an option of having applets be removed after logout. I, too, have had issues with users successfully downloading the upgraded Network Connnect without problems. My thought was to turn on having applet removed on logout a week before upgrade so the majority of machines would NOT have the Host Check or Network Connect clients loaded and would get a "clean" install. Anyone try this? Or would this just create more problems and support calls?

I agree that being able to "phase in" Network Connect upgrades would be very helpful.

What, exactly, is the issue with upgrades and Host Checker?

TIA

-=Dan=-

aterockz_
Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

Hardest problem for me was the that the juniper installer / active x control element has changed.

I wasn't really well prepared for that. (I have been told, last time it has been updated 2 yeas ago).

Immediatly there poppt up a lot of calls because the users did not have the rights to install the new piece of software.

Juniper Installer / Network Connect should be rolled out 1 month in advance.

Sounds long term, but keep in mind that some users might be on vacation / ill or whatever.

ActiveX control element / juniper installer should be compatible with older versions but I would test that.

Esp. try it with non priviliged accounts after roll out.

Ate RocKz

ben_
Frequent Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

But for the case that a user does not have the rights to install e.g. NC, SAM etc. Juniper has the installer service to manage that.
aterockz_
Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

True true...

But in this update ... even the installer has changed and with it the active x control element.

This leads to following situation:

The user also needs priviliged/admin rights to upgrade the installer.

So you need to roll out the installer with software distribution in advance but a software distribution is not always available for external users.

So long,

Ate RocKz

tonym_
New Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

One big change I found with 6.3R2 is the AV Signature checking. Before Host Checker looked at the date of the AV DAT file. With 6.3 in order to check the DAT file age, the IVE has to log into the Juniper Support site and pull down an XML file and uses that to check the DAT file version. The 6.3 version has no provision for going out thru the internal proxy server to the Internet.
Ray_
Frequent Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

One royal pain is the anti-virus host checker being changed from "xx days old" to "xx updates old". Whereas fourteen days was acceptable to us before, the new setting only allows up to 10 updates old.

Our anti-virus vendor sometimes kicks out a minor update every day or two, sometimes not, and setting the host checker to 3 updates old caused major problems for people who connect their computer to the Internet only once a week. Our executives a use desktop as their primary computer but have a laptop for weekend use or travelling only.

I had to reset it to the maximum of 10 and I really have no idea how long that is in days. Potentially it could be ten weeks. <sigh>

It looks like this change was introduced in v6.2.

Ray

Mrkool_
Super Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

6.3R3 was just released so you might want to go for that one as that has alot of bug fixes
aterockz_
Contributor

Re: Is IVE 6.3R2 Ready for Primetime?

Where have you found the 6.3R3 ? It's is not posted in the juniper.net support forum.

Ate