CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-18
Junior Member
 
Join Date: 2006-05-18
Posts: 1
Rep Power: 0
ckgreenman has an average reputation (10+)
Default Firewall Manager Recovery??

Hello,
Is it possible to pull the running profile from the firewall devices back into a restored firewall manager? Our manager died yesterday and it appears as though our latest backup was about 2 months ago (I have no idea why they aren't more current). Is there a way, after rebuilding and restoring, to pull the running profile and rules from the firewalls so that we don't have to manually rebuild 2 months worth of rule changes?

Thanks
Reply With Quote
  #2 (permalink)  
Old 2006-05-18
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Firewall Manager Recovery??

Nope, the rules are pushed to the firewall as compiled code.

If you still have access to the logs, you can use the Audit log to see what was done when.

Ray
Reply With Quote
  #3 (permalink)  
Old 2006-05-19
Junior Member
 
Join Date: 2006-04-13
Posts: 3
Rep Power: 0
Blueberry has an average reputation (10+)
Default Re: Firewall Manager Recovery??

Quote:
Originally Posted by RayPesek
Nope, the rules are pushed to the firewall as compiled code.

If you still have access to the logs, you can use the Audit log to see what was done when.

Ray
Agree its not possible to pull the rulebase back from the firewall. Had reason to ask our CP SE this recently for a client and as far as he knew, even the guys in Israel had only done this once, for a major customer running P1, and it cost a lot in consultancy hours!!
Reply With Quote
  #4 (permalink)  
Old 2006-06-01
Junior Member
 
Join Date: 2006-06-01
Location: Delaware
Posts: 3
Rep Power: 0
fw_bill has an average reputation (10+)
Send a message via AIM to fw_bill
Default Re: Firewall Manager Recovery??

In a VSX environment, there are 2 files that you can use, they are somewhat stripped but still human readable....

objects.C and rules.c in dir /var/CTX/CTXnnnnn/database
where nnnnn is the vsid #

You can try to read these and match what's missing, or if you're willing to take a short step back for an hour or two:

.save these two files off (critical!)
.push policy (yes you will lose 2 months of changes)
.grab the new versions of these 2 files
.run a comparison (CompareIT! is nice on windows) and adjust your rules accordingly

you should be able to get to where your new files are almost identical to the original files, except for some funny checkpoint generated bits

The above files have no comments or any other "fancy" stuff, but are usable.
To my knowledge there are no tools out there that will directly work with these. Yet.
Reply With Quote
  #5 (permalink)  
Old 2006-10-30
Junior Member
 
Join Date: 2006-10-30
Posts: 3
Rep Power: 0
fwjockey has an average reputation (10+)
Default Re: Firewall Manager Recovery??

It is possible. I did this for a customer a while back on r55. They lost their smartcenter and only had the cluster left. If I remember correctly, I grabbed the rules.c and objects.c out of the database directory on one of the enforcement points and went to town with some manual hacking and use of the cp_merge utility.

I think I did a cp_merge export policy on a small poilcy to get the format, then pasted parts of the rules.c into it and cp_merge policy import. Though this may have been one of the failed attempts. After using cp_merge (may have used fwm confmerge in conjuction with objects.c from enf point before doing this?) to pull in objects.

After a few hours of tinkering it was still a bit messed up, but I upgrade_export and then upgrade_imported the same config and it straightened out whatever I hadn't hacked properly and voila I had restored the smartcenter. The customer was happy and I was very proud of myself.

This post is not technically very useful, I don't remember exact steps, but it is possible with a few hours of patience.

fwj
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:12.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0