CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-18
Junior Member
 
Join Date: 2007-09-27
Posts: 18
Rep Power: 0
BirdDog has an average reputation (10+)
Default Undo a bad pushed policy

Folks,

This hasn't happened to me yet, but in case it ever does I would like to know what my options are.

Scenerio -

I have a Nokia FW at my physical locaiton in the server room. However, the management GUI is located on a server in another country which we access via a site-to-site VPN (yes...will eventually change this).

If I push a bad policy and hose my network, provided I can console directly onto the box, how do I change that policy? Undo that policy? Unload that policy? And can I revert to the previous policy?

thanks...BirdDog
Reply With Quote
  #2 (permalink)  
Old 2007-10-18
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 255
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Undo a bad pushed policy

You can do a "fw unloadlocal" to unload the policy and install a new one. On the management server you can use the database revision control to revert to a previous version. mostly you don't need to use it to recover a bad policy since you'll know what you changed.
Reply With Quote
  #3 (permalink)  
Old 2007-10-18
Junior Member
 
Join Date: 2007-09-27
Posts: 18
Rep Power: 0
BirdDog has an average reputation (10+)
Default Re: Undo a bad pushed policy

What actually happens when with the "fw unloadlocal". It will unload the existing policy, but then I have no policy correct? My site to sites would still be down until I get the correct policy? But, my SmartDashboard is on another server that I wouldn't be able to get to.

Is there a way to keep a backup of a good working policy on the Nokia? That way, if this happens, I can unlodlocal and import this backed up policy. Anything like that?
Reply With Quote
  #4 (permalink)  
Old 2007-10-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,071
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Undo a bad pushed policy

You can't have a backup policy other then the default. Whilst this can be modified I don't think that you will get to modify to the extent that you want.

I would suggest that you create a backdoor access method to the Server that does not rely on the Check Point Site to Site for access and then keep the access method unpublished other then to the firewall admins, and only use in an emergency.
Reply With Quote
  #5 (permalink)  
Old 2007-10-19
Junior Member
 
Join Date: 2007-09-27
Posts: 18
Rep Power: 0
BirdDog has an average reputation (10+)
Default Re: Undo a bad pushed policy

Ok...that's what I wanted to know and needed to know.

The FW(m) load won't do anything for me?
Reply With Quote
  #6 (permalink)  
Old 2007-10-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,071
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Undo a bad pushed policy

If you can perform an fwm load at the SMARTCenter then that will push a policy to the gateway.

You could change the policy name everytime you change and so use the previous policy name with the fwm load. It's not reverting to the old policy as such it merely pushes a policy down to the gateway.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:55.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0