CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-17
Member
 
Join Date: 2006-11-07
Posts: 64
Rep Power: 3
derspot has an average reputation (10+)
Default connecting a fw to a SmartCenter ..

Hi is this statement true:

You can attach any Gateway, no matter its currnet config, to a SmartCenter - provided that:
-you have full connectivity
- you perform a sic reset.

I played around and found that the time must match on the SC and the FW, for the sic to initialize. I think even the time zone must match. After the SIC is initialized, time doesnt really matter anymore.

Question 2.
What is in the so called InitialPolicy - that is , what traffic the FW allows from/to it. I guess it doesn't allow any traffic pass.

Question 3. What happens if the CP services are down. Is any traffic allowed throug the FW ? Can it talk to the SC ?
Reply With Quote
  #2 (permalink)  
Old 2006-12-17
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: connecting a fw to a SmartCenter ..

Quote:
Originally Posted by derspot View Post
Hi is this statement true:

You can attach any Gateway, no matter its currnet config, to a SmartCenter - provided that:
-you have full connectivity
- you perform a sic reset.

I played around and found that the time must match on the SC and the FW, for the sic to initialize. I think even the time zone must match. After the SIC is initialized, time doesnt really matter anymore.
Yup a gateway can be switched to a different SMC.

As for time, clocks always need to be close at least for SSL/TLS. Timezones should be set correctly then it will work. eg if the SMC is set to GMT and GW is set to EST, the clocks need to show a 5 hour difference.


Quote:
Question 2.
What is in the so called InitialPolicy - that is , what traffic the FW allows from/to it. I guess it doesn't allow any traffic pass.
See $FWDIR/conf/initial_module.pf for details.

Quote:
Question 3. What happens if the CP services are down. Is any traffic allowed throug the FW ? Can it talk to the SC ?
That's the idea. Routing should be disabled and controlled by FW1
Reply With Quote
  #3 (permalink)  
Old 2006-12-19
Member
 
Join Date: 2006-11-07
Posts: 64
Rep Power: 3
derspot has an average reputation (10+)
Default Re: connecting a fw to a SmartCenter ..

Thanks Thanks
Reply With Quote
  #4 (permalink)  
Old 2006-12-20
Member
 
Join Date: 2006-11-16
Location: Tallinn, Estonia
Posts: 82
Rep Power: 3
Reaper has an average reputation (10+)
Send a message via Skype™ to Reaper
Default Re: connecting a fw to a SmartCenter ..

If you want to, you can change the default policy. Use the following commands:

cp $FWDIR/lib/defaultfilter.ipso $FWDIR/conf/defaultfilter.pf
fw defaultgen
cp $FWDIR/state/default.bin $FWDIR/boot

Now you have SSH and HTTPS access even after running cpconfig and applying Initalpolicy. Much more convinient, in case you screw something up :)
Reply With Quote
  #5 (permalink)  
Old 2006-12-20
Member
 
Join Date: 2006-11-07
Posts: 64
Rep Power: 3
derspot has an average reputation (10+)
Default Re: connecting a fw to a SmartCenter ..

Thanks , geeky stuff.
Reply With Quote
  #6 (permalink)  
Old 2006-12-21
Member
 
Join Date: 2006-12-20
Posts: 83
Rep Power: 2
NickBrandson has an average reputation (10+)
Default Re: connecting a fw to a SmartCenter ..

Just wondering how it would work if the SmartCenter in the HQ and the remote gateways in different timezone. Possible to do so?
Or we have to give up the local time zone and set as the same as HQ.
Reply With Quote
  #7 (permalink)  
Old 2006-12-21
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: connecting a fw to a SmartCenter ..

As long as the OS's timezone is set correctly all is good. Time is stored as UTC/GMT and displayed in the local TZ. So its no problem having a SmartCenter in NYC on EST and a gateway in LA on PST. All is happy.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:49.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0