CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-31
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Restore backup file to another CP firewall

Hi all,

we use upgrade_export to backup our firewall monthly, how can we use this bk file to restore another cp firewall?

we are currently using Nokia IPSO 4.2 and the Checkpoint NGX R60 or how can we find the restore step, do we need to input the key againt.

Please help, thanks.
Reply With Quote
  #2 (permalink)  
Old 2008-03-31
Senior Member
 
Join Date: 2007-07-16
Posts: 628
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Restore backup file to another CP firewall

Use upgrade_import.
Reply With Quote
  #3 (permalink)  
Old 2008-03-31
Junior Member
 
Join Date: 2008-01-03
Posts: 1
Rep Power: 0
subliminator has an average reputation (10+)
Default Re: Restore backup file to another CP firewall

Hi:

upgrade_import is at the heart of your restore. If you've got a series of standalone firewalls, someone else will need to chime in to help (I manage NGX appliance clusters). You would only use your original file if it was upgrade_exported from a management server that was responsible for the other firewall. We place my backup file on CD when moving around from gateway to gateway as a matter of convenience; our build lab is off of our production network. We also have sufficient spares to build out a management server, and place the backup file there (restoring the management server) in order to clone as many gateways as we need to. That is accomplished by simply applying the desired security policy to the replacement hardware, and then putting that device into service. FWIW, I have gotten away without re-SICing restored gateways, but do it now as a matter of standard practice. It isn't as painful under NGX as it has been in the past.

cheers.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:20.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0