CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-16
technick22 technick22 is offline
Junior Member
 
Join Date: 2007-10-10
Posts: 22
Rep Power: 0
technick22 has an average reputation (10+)
Default backup question

I presently run an upgrade_export on my SC manually, which i understand is all i need if system needs to be rebuilt.

I also have three FW-1 SPLAT firewalls (two clustered and one alone) in which i connect to web interface and run the backup command and store on TFTP server.

My question...

Is this all that is required, or should i also run upgrade_export on the firewalls themselves?

Thanks
Nick
Reply With Quote
  #2 (permalink)  
Old 2008-01-16
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: backup question

You should only need to run the upgrade_export on SmartCenter system, or if it is SPLAT the backup function would get the FW1 config, as well the system config, maybe saving you some setup time in the event you need to restore. Where as an upgrade_export would only get your FW config, not the OS... If your SC system is a Windows/Solaris/Etc... type box, you will want to run some sort of system backup as well in case you have any special routes, ip setups, etc... If it is a SPLAT, you could use it's scheduled backup process to do pretty much the same thing.

Last edited by rokudan; 2008-01-16 at 08:15.
Reply With Quote
  #3 (permalink)  
Old 2008-01-16
technick22 technick22 is offline
Junior Member
 
Join Date: 2007-10-10
Posts: 22
Rep Power: 0
technick22 has an average reputation (10+)
Default Re: backup question

My SC is running on a Windows 2003 server.
And Splat is running on all three firewalls.

And if i understand you correctly all i need is upgrade_export to be run on my SC and backup (web interface function) to be run on my SPLAT firewalls.

If this is accurate than it is exactly what i'm presently doing. Mind you it's a manual process right now, but it still does the task :)

On my Windows SC server, what else do i need to backup (using third party backup software)?
Reply With Quote
  #4 (permalink)  
Old 2008-01-16
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: backup question

You can get away fine with just the upgrade_export from the Windows server, but just make sure you note your ip and any routes you have added to that box. Usually not a big deal, but in a large environment you may have a few routes to get to various gateways... As well you have to reconfigure the box as a bastion host, meaning lock it down by removing services, patching everything, etc... So sometimes a full backup, can ease that process...
Reply With Quote
  #5 (permalink)  
Old 2008-01-19
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 876
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: backup question

Also note that in order for the SPLAT backup to be restored properly, you need to reinstall SPLAT and the last HFA you applied first. If you don't do that, some of the files restored will be from a later HFA than what you built up for recovery.

Of course, in order to install the HFA you also need to run sysconfig and install whatever Check Point packages were installed before doing the HFA and the backup restore.

If you try to apply the correct HFA after you do the restore, it won't do anything because it thinks it's already installed. That will cause issues because the binaries won't match the config files. If you run the version commands, it will say the HFA is installed but it's not.

So make sure you know what the latest HFA is that's installed on the firewalls as well as any non-HFA hotfixes, if any. Also make sure you know what Check Point packages are installed.

Restoring the SmartCenter with upgrade_import is a lot easier because it's platform-independent.

Ray
Reply With Quote
  #6 (permalink)  
Old 2008-01-19
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 461
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: backup question

This is also where the snapshot command can be handy on SPLAT. If you take a snapshot after installing HFAs, you can use the snapshot to revert to the HFA version before running your latest backup or upgrade_import. Makes the DR document easier, because you don't need to include the product install and HFA install process before the data restore process.
Reply With Quote
  #7 (permalink)  
Old 2008-01-23
technick22 technick22 is offline
Junior Member
 
Join Date: 2007-10-10
Posts: 22
Rep Power: 0
technick22 has an average reputation (10+)
Default Re: backup question

damn....much more complicated than i thought. There should be a sticky with what should be done to fully backup and restore the different platforms.

I think it would help alot of people
Reply With Quote
  #8 (permalink)  
Old 2008-01-23
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: backup question

Quote:
Originally Posted by rokudan View Post
You can get away fine with just the upgrade_export from the Windows server, but just make sure you note your ip and any routes you have added to that box.
Also note the FQDN as your certs are generated using this.
__________________
There's no place like 127.0.0.1
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:00.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0