Thread: Policy Backup
View Single Post
  #17 (permalink)  
Old 2008-03-13
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,030
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Policy Backup

You have two issues here. If you don't want assistance on how to upgrade to NGX in this then don't mention it as it just confuses us as to what you are looking to do.

ISSUE 1: Policy backup within NG FP2

Pls remember that I am using NG FP2(dnt want to upgrade into FP3).
I also clicked the given link but not able to get that file, little bit confuse that what link should I go for.
I want to tell you what exactly I want to do, in my organization checkpoint policy editor consists of two policy package "a" & "b".
"b" having the updated policies & "a" is for backup. So I want to take the full backup from the "b" & push to "a", if any thing go wrong can use "a" as a production.


ISSUE 2: Upgrade of Management Server to NGX R65

My organization is using older version of checkpoint that is " NG Feature pack 2 build 520144" with alteon Acc & Dir.

We are planning to upgrade into NGX65 with Nokia Box.

I want to know how to take the policies backup, policies printout to maintain all policies database if anything goes wrong.

ISSUE 1: If I am reading you correctly then you have two policy packages on the same SMARTCenter.

You have a policy B that is used on the product box. You also have a policy called A that is the backup policy.

In the event that policy B is not working you want to be able to revert to policy A.

If you want to copy the policy from package A to package B, then just use the

File, Save As, and then save PolicyA with the name of PolicyB. This will overwrite the contents of the policy package B with the contents from policy package A.

Alternatively you just open up Policy A and install Policy A onto the production box.

The File Save As and saving will give you a backup policy of the policy that you have open.

If you save PolicyB with the name of Policy A then it will save a seperate copy of PolicyB available as a backup with the name of PolicyA.

This however will not give you an upgrade path from NG FP2 to NGX. Nor will it save you from corruption of the objects or users, as this purely makes a copy of the rules.

ISSUE 2: Upgrade to NGX R65.

It is not possible to upgrade from NG FP2 to NGX R65 in one go, you have to have an intermediate step. I would suggest that goto NG AI R55.

Check Point Software: SmartCenter Tools)

Is a link to the upgrade_tools for NG AI R55 for the different platforms.

Select the platform for which the management server is installed on, and the version that you want to upgrade too.

On your management server goto

$FWDIR/bin

create a directory called upgrade_tools

ftp the downloaded file from the check point website into the $FWDIR/bin/upgrade_tools

unzip the .tgz file and it will extract the upgrade_export tools into the directory.

run the pre upgrade verifier (instructions are in the upgrade guide to which there is a link from the page above) to check the system.

make any changes recommended by the pre_upgrade verifier.

Once done then run the upgrade_export tool to generate an R55 export.

Build a seperate management server box with the same hostname, ip address of the existing management server and ensure is not connected to the network.

Transfer the exported config to the new box.

Install a clean copy of the NG AI R55 onto the new management server, select to import the configuration and point at the exported config file.

This will install an R55 Management Server with the objects, users and policy upgraded from NG FP2 to NG AI R55. You will need to change the version of the gateway object to be NG AI for the upgrade to NGX R65. As you are not installing the policy from this box then it doesn't matter.

You can then repeat the process but using the NGX R65 CD to upgrade to NGX R65.

This will then give you an R65 Management Server. You can then build your Nokia and update the policy substituting the Nokia object for the Alteon Object in the policy manually.
Reply With Quote