CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-06-19
scottlsattler scottlsattler is offline
Junior Member
 
Join Date: 2006-04-26
Location: US
Posts: 17
Rep Power: 0
scottlsattler has an average reputation (10+)
Send a message via Yahoo to scottlsattler
Default Firewall Policy

So we had a SmartCenter server drive failure for a customer. Lost the opt directory (on Solaris)

They have no backups, of course, and the last time the Solsoft Admin took a snapshot of the smartcenter was a few months ago. So we could recover most of the rules with solsoft, however there were 3 months of rule changes we're too lazy to type back in.

Luckily the firewalls have the last policy running on them. However, we're going to have to push some rules sooner or later. We have recovered the smart center and wouldn't it be great if you could do a fw get and poll in the last policy that was pushed......anyone know of a tool or utility that can "magically" do this?

cp_merge wants to chat with smartcenter so that option is out...

Scott,
Reply With Quote
  #2 (permalink)  
Old 2008-06-19
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Firewall Policy

Data Recovery Services, Software, Solutions - Ontrack Data Recovery - They do a wonderful job of recovering data from failed hard drives. My guess is they could recover everything you need. The cost is usually between $1,000 and $2,000 for us.

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-06-20
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 142
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Firewall Policy

do you have a cpinfo from any point from the box. I can recover from that but you will need to reset sic with the firewall's. The good news is all of your policy and objects will be avail.
Reply With Quote
  #4 (permalink)  
Old 2008-06-21
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Firewall Policy

If you don't know whether you have a cpinfo, check in any support cases you may have opened with Check Point or Nokia. There may be one attached to a case.

Ray
Reply With Quote
  #5 (permalink)  
Old 2008-06-22
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Firewall Policy

And I'm thinking now that you've got a reasonably good business case for putting mirrored drives in your SCS.

Plus of course writing a simple backup script to at least scp the configuration to some other system.
Reply With Quote
  #6 (permalink)  
Old 2008-06-22
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 143
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Firewall Policy

At the Gateway take a look into the following directory:
Code:
cd $FWDIR/database/
-rw-rw----    1 root     root      1530778 Jun 20 12:15 objects.C
-rw-rw----    1 root     root       450480 Jun 20 12:15 rules.C
From the objects.C file you can recover the objects with ofiller, from the rules.C you can get parts of the topolgy (read with favorite asci editor)


Before you try anything at the original harddisk such as massive fsck think about the more secure way to get the data back.

If the HD is working but has lost the partition table / corrupt filesystem...
#> dd if=/dead/harddisk of=/lot/of/space/dead_hd.dd bs=1m (HD mount -ro)

If the HD is not working (no spin up)
Try to find the same HD and change the HD controller, if the drive comes up now try to '#> dd' the harddisk.


If you where able to dd the HD read on, else the following suggestion are not from interest since insecure.

There are tools out such as
The Sleuth Kit & Autopsy: Digital Investigation Tools
gpart - Guess hard disk partitions
The Coroner's Toolkit (TCT)

These tools can operate at the dd-image and recover lost files, restore a partition table...
At some places you can also find a bootable Linux CD with the tools, keep in mind the dd-image can be copied to another *NIX station.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:17.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0