CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-27
cames cames is offline
Junior Member
 
Join Date: 2007-03-19
Location: London
Posts: 6
Rep Power: 0
cames has an average reputation (10+)
Default Backing up NGX - Options Compared

Hi All,

I’m just trying to get the various (and recommended) backup procedures clear in my head, so I’d be really grateful if people more knowledgeable than myself could read the below and comment/correct?

1) Database Revision Control is used to create a roll-back copy of all policy rules, objects, users, groups, smart defence, and global properties (and presumably VPNs etc). This will not backup server/FW specific info such as the OS, logs, and interface settings, however. Also, it will not create a file for separate safekeeping, so is not appropriate for disaster recovery.

2) upgrade_export will backup the same as Database Revision Control (everything but server/fw specifics) but does so from the command console or the CD upgrade program, and creates an exportable .tgz file that can be moved to another machine for safekeeping. It also backs up license information and is good for disaster recovery.

3) The “Backup” command (or the SmartCenter's web backup tool) will backup just the SmartCenter server settings such as the OS, interface settings and logs?

Notes:

Important files and folders are…

$FWDIR/Conf (containing Objects.c, Objects_5_0.c and Rulebases_5_0.fws)
$FWDIR/Lib (containing base.def)
$FWDIR/Logs (containing logs)
$FWDIR/Database (contains user database – fwauth.ndb)

…but these are all backed up by using the “upgrade_export” program.

Logs should be regularly backed up by switching the logs (with fw logswitch) and archiving the older files.

Is that all correct, and/or could anyone fill in the gaps for me?

Thanks in advance!
Reply With Quote
  #2 (permalink)  
Old 2007-03-27
ngxadmin ngxadmin is offline
Junior Member
 
Join Date: 2007-03-26
Posts: 24
Rep Power: 0
ngxadmin has an average reputation (10+)
Default Re: Backing up NGX - Options Compared

It is my understanding that the backup command does back up your checkpoint policy configuration in addition to what you mentioned and you would be able to restore policy. However, upgrade_export is a more comprehensive type of backup and has fewer issues when restoring your configuration/policy.
Reply With Quote
  #3 (permalink)  
Old 2007-03-27
cames cames is offline
Junior Member
 
Join Date: 2007-03-19
Location: London
Posts: 6
Rep Power: 0
cames has an average reputation (10+)
Default Re: Backing up NGX - Options Compared

Ah, I see. Thanks, I appreciate it!
Reply With Quote
  #4 (permalink)  
Old 2007-04-05
fwleno fwleno is offline
Junior Member
 
Join Date: 2006-07-25
Posts: 7
Rep Power: 0
fwleno has an average reputation (10+)
Default Re: Backing up NGX - Options Compared

I suggest using and enjoying both backup and upgrade_export. In case you will need to restore you can select the fastest way. If just the checkpoint failed than you can use upgrade_import file but if the whole server crashed or damaged using the backup/restore option is faster and will recreate all interfaces , routing , dynamic routes and many other system files that you may have customized...
Reply With Quote
  #5 (permalink)  
Old 2007-11-21
trinity trinity is offline
Member
 
Join Date: 2007-06-23
Posts: 60
Rep Power: 2
trinity has an average reputation (10+)
Default Re: Backing up NGX - Options Compared

Quote:
Originally Posted by cames View Post

3) The “Backup” command (or the SmartCenter's web backup tool) will backup just the SmartCenter server settings such as the OS, interface settings and logs?
Where is the web backup tool? Or is this the same as the web visualisation tool?
Reply With Quote
  #6 (permalink)  
Old 2007-11-21
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Backing up NGX - Options Compared

Is actually the SecurePlatform Web Backup Tool not the SMARTCenter as such.
Reply With Quote
  #7 (permalink)  
Old 2007-11-21
trinity trinity is offline
Member
 
Join Date: 2007-06-23
Posts: 60
Rep Power: 2
trinity has an average reputation (10+)
Default Re: Backing up NGX - Options Compared

Quote:
Originally Posted by mcnallym View Post
Is actually the SecurePlatform Web Backup Tool not the SMARTCenter as such.
Ah right sorry, we're using windows so i didnt realise!
Reply With Quote
  #8 (permalink)  
Old 2007-11-22
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 335
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Backing up NGX - Options Compared

Quote:
Originally Posted by cames View Post
Hi All,


Notes:

Important files and folders are…

$FWDIR/Conf (containing Objects.c, Objects_5_0.c and Rulebases_5_0.fws)
$FWDIR/Lib (containing base.def)
$FWDIR/Logs (containing logs)
$FWDIR/Database (contains user database – fwauth.ndb)

…but these are all backed up by using the “upgrade_export” program.

Thanks in advance!
Also add

$CPDIR/conf
$CPDIR/database

These are where (among other things) the SIC key and policy, license files and the CP Registry are stored.

I'd recommend running a upgrade_export and opening up the .tgz fle to see the files and folders it grabs.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:18.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0