CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-15
avilT avilT is offline
Member
 
Join Date: 2006-03-14
Posts: 73
Rep Power: 3
avilT has an average reputation (10+)
Default Firewall Manager Disaster Recovery

I have Nokia IP 330, VRRP running NG FP3, firewall Manager is on Windows 2000. I need disaster recovery for Windows Firewall Manager. If the firewall manager crashes, how do I bring up the firewall manager on a new maching after installing Windows 2000? What files I need to backup? Thanks in advance.
Reply With Quote
  #2 (permalink)  
Old 2006-03-16
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

You can use the FP3 version of upgrade_export. This will create a backup of all of the Check Point data. All you have to do is rebuild a machine with the same IP address and Hostname, install Check Point and import this back into it.
Reply With Quote
  #3 (permalink)  
Old 2006-03-19
avilT avilT is offline
Member
 
Join Date: 2006-03-14
Posts: 73
Rep Power: 3
avilT has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

Thank you very much for the reply. Does this also back up the SIC data? Many books suggested to backup only 2 files, object_5_0.C and rulebases_5_0.fws, install the firewall manager on a new PC, restore these two files and then reset the SIC. I was able to load the smart dashboard with this method but had to face several problems. What is the best way to perform the recovery?

Last edited by avilT; 2006-03-19 at 20:13.
Reply With Quote
  #4 (permalink)  
Old 2006-03-20
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

This does back up the SIC data.
Reply With Quote
  #5 (permalink)  
Old 2006-05-19
Blueberry Blueberry is offline
Junior Member
 
Join Date: 2006-04-13
Posts: 3
Rep Power: 0
Blueberry has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

upgrade_tools i.e. the export and import utilities are the best way of backing up that I have come across. As stated as long as the hostname, ip address and versions are the same this will work without a problem.

Sometime the import fails at the very end or you get a random seed issue but these are easily rectified by redoing the task.
Reply With Quote
  #6 (permalink)  
Old 2006-05-22
srikrishnak srikrishnak is offline
Junior Member
 
Join Date: 2005-09-06
Location: Singapore
Posts: 16
Rep Power: 0
srikrishnak has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

Agree. Export/Import DB is the best option available for the time being. As an idot proof method backup all the FWDIR directory in to another Hard Drive. Some times its quite handy.
Reply With Quote
  #7 (permalink)  
Old 2006-09-20
sengkhoon sengkhoon is offline
Junior Member
 
Join Date: 2006-05-29
Posts: 4
Rep Power: 0
sengkhoon has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

Hi All,

I just want to confirm that by running the command upgrade_export. IT will not cause any service to reset or the firewall to be down for a while . which will cause impact to the network
Reply With Quote
  #8 (permalink)  
Old 2006-09-20
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

I'm not sure if you're asking the question or affirming the above responses. You are correct. It will not affect anything. Just don't save it on the same drive as where SmartCenter is installed. :-)

Ray
Reply With Quote
  #9 (permalink)  
Old 2006-09-26
danensis danensis is offline
Junior Member
 
Join Date: 2006-05-18
Posts: 7
Rep Power: 0
danensis has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

Isn't there a registry string that you have to save as well? I understand SIC will not work unless you do this?
Reply With Quote
  #10 (permalink)  
Old 2007-02-04
sengkhoon sengkhoon is offline
Junior Member
 
Join Date: 2006-05-29
Posts: 4
Rep Power: 0
sengkhoon has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

Hi ,

I was trying to do a backup on the FW1 folder but i am getting an error.

cannot copy cpsql_ccN3ceiszAyxgC: It is being used by another program.
Can i know what is this file?

Thanks
Reply With Quote
  #11 (permalink)  
Old 2007-02-05
baboo baboo is offline
Junior Member
 
Join Date: 2006-02-20
Location: Switzerland, Burgdorf
Posts: 22
Rep Power: 0
baboo has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

AFAIK the "update_export"-command does not backup your routes.

So remember to write down your routes.
(I found out that the routes are saved in /etc/sysconfig/netconf.C but I'm not sure if it's enough to just save that file.. )

Kind regards,
Manuel
__________________
To know recursion, you must first know recursion-1
Reply With Quote
  #12 (permalink)  
Old 2007-02-09
stefan73er stefan73er is offline
Junior Member
 
Join Date: 2006-02-28
Posts: 17
Rep Power: 0
stefan73er has an average reputation (10+)
Default Re: Firewall Manager Disaster Recovery

Quote:
Originally Posted by danensis View Post
Isn't there a registry string that you have to save as well? I understand SIC will not work unless you do this?
yes there is a registry string on a windows system but the upgrade export will save this also.

And for sure this is the best way to backup checkpoint i know.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:09.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0