CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-18
giuffrolo giuffrolo is offline
Junior Member
 
Join Date: 2006-10-12
Posts: 2
Rep Power: 0
giuffrolo has an average reputation (10+)
Default Database Revision Control Restore

Hi to all,
I have a big problem: after the installing new rules, the access with SmartDashboard is denied. I have reconfigured using cpconfig a new IP of another interface, but the problem is the same: the connection is dropped using the last rule (Any Any Deny All). I have a Database Revision Control updated to the last month.
The question is: I can restore the last Database Revision Control using CLI???
I have found the command to list, delete, create... but not to restore.

My configuration is NGX (6.0) in to IPSO350.

Thanks.

Last edited by giuffrolo; 2008-02-18 at 11:47.
Reply With Quote
  #2 (permalink)  
Old 2008-02-18
eduardw eduardw is offline
Member
 
Join Date: 2007-08-04
Posts: 50
Rep Power: 1
eduardw has an average reputation (10+)
Default Re: Database Revision Control Restor

Database revision can not help you in this case.
This is because your not allowed to connect to the firewall
The fastest way to fix this is. Enable the management using implied rules.
Next you have to get root access to the firewall and use the command fw unloadlocal (be aware this will result in outage no traffic is allowed to go trough the firewall, so you probably need to plan a service window)
After the unloadlocal test the syc status (use the gui) next update the topology of your firewall and try to push the “new”policy.

Eduard
Reply With Quote
  #3 (permalink)  
Old 2008-02-19
leekutti leekutti is offline
Junior Member
 
Join Date: 2008-02-14
Posts: 3
Rep Power: 0
leekutti has an average reputation (10+)
Default Re: Database Revision Control Restor

just thought, the first problem is cannot access the management , without access the management Not possible to change the implied rule.
"FW unloadlocal" should work.
lee
Reply With Quote
  #4 (permalink)  
Old 2008-02-20
giuffrolo giuffrolo is offline
Junior Member
 
Join Date: 2006-10-12
Posts: 2
Rep Power: 0
giuffrolo has an average reputation (10+)
Default Re: Database Revision Control Restor

Thanks you very much to all.

I have resolved using "FW unloadlocal", but to reconnect the smartdashboard I have also recreated the sic channel, destroing the ICA. It is very strange, because I have only installed the new rules.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:19.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0