CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-07
Junior Member
 
Join Date: 2006-06-06
Location: Tampa
Posts: 12
Rep Power: 0
BSDsnob has an average reputation (10+)
Default Proper Backup Question

Hello,

Voyager says that backups are backing up the /config folder and I assume that is were the configuration script lies for the firewall rules. In the event of a complete system failure would I be able to recover from this backup or would I need the system to be preinstalled. I exported the smartcenter database with the installation CD and I assume that if I had nothing the copying over the /config backup would not be sufficient to rebuild the firewall. Or could I just install the ckpt fw version and replace the /config folder with the backup that I have? In the event of a total failure (smartcenter failure and fw machine) would I need a database backup to get a machine back up and running?
Reply With Quote
  #2 (permalink)  
Old 2006-06-08
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Proper Backup Question

Usually a Voyager backup gets placed in /var/backup or /var/backup/sched (for scheduled backups). If this is not a smartcenter server then the only information that you will need to backup is the Voyager information which will include the Interface information, routes, any VRRP or IP clustering configuations.

To do a restore, you will have to install the same version of IPSO and then install the verion of check Point that you are using, do a restore using Voyager and then push a policy from the smartcenter server.

In the event of a crash of the smartcenter server you will need to have a check Point backup from there to recover all of the Check Point data. This is best obtained from doing an upgrade_export on the smartcenter server.

hope this helps.
Reply With Quote
  #3 (permalink)  
Old 2006-06-08
Junior Member
 
Join Date: 2006-06-06
Location: Tampa
Posts: 12
Rep Power: 0
BSDsnob has an average reputation (10+)
Default Re: Proper Backup Question

Thank you looks like they were backing stuff up in a script, is there a way to recover the smart center not using the import method. Sorry I am new to checkpoint, and l'll tell you checkpoint and nokia are a pain in my arse! BSD used to be so simple cd to the port directory make and then make install what did they do to my OS!
Reply With Quote
  #4 (permalink)  
Old 2006-06-08
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Proper Backup Question

By far the most critical piece is the SmartCenter configuration because it has all of the object definitions, the certificate authority, the user database and the rule base. SmartCenter pushes these to the Nokia box. Here's what I do:

Redundant physical drives in the SmartCenter. Every week or after a big change, I run upgrade_export.exe to export the SmartCenter stuff that's installed on the C: to the physically separate D:

Before any Windows Updates or major changes are made to the SmartCenter, an image is created. This gives me the SmartCenter on C: and the upgrade_export.tgz file on the D: in the image. I keep multiple images available.

After each HFA application to the enforcement module, I manually create the backup on the Nokia box and send it to the SmartCenter. That way it's included in the images as well.

I keep a copy of the relevant HFA's on the SmartCenter. I also keep a copy of the installation wrapper for FW-1 and a copy of the running version of IPSO.tgz file on the SmartCenter. This not only puts them all in the image, it lets me totally rebuild an enforcement module without having to go to the Internet at all.

I had to do this once to a remote firewall. It came with a different version of IPSO & FW-1. I cleaned it off via SSH and had it on the correct versions and up and running in one hour after the remote site got the replacement box from Nokia (an IP-120).

HTH,

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 07:33.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0