CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-07
vadi_ag vadi_ag is offline
Junior Member
 
Join Date: 2006-04-07
Posts: 27
Rep Power: 0
vadi_ag has an average reputation (10+)
Default Policy recovery

Hi All
I have installed a policy on my firewall I have to make some changes in the installed policy I have created a new version and when i tried to install this new policy i got time out error and installation failed and the new version of policy got corrupted can u help me how can i recover this policy Pls help me
Reply With Quote
  #2 (permalink)  
Old 2006-04-08
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Policy recovery

If you get time out error, it doesn't mean that your policy corrupted. May be with this error your policy is installed (sometimes it happens). But if you lost connections with your SC after that, you need to execute "fw unloadlocal" on module and try to reinstall policy.
Reply With Quote
  #3 (permalink)  
Old 2006-04-08
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Policy recovery

Yes, what usually happens is the rulebase that you are pushing out blocks the connection from the management station. It gets pushed out according to the firewall but because the managment station couldn't finish it's transaction it ends with an error.

Make sure you have a rule in your rulebase to access the firewall from the managment station.l
Reply With Quote
  #4 (permalink)  
Old 2006-04-10
vadi_ag vadi_ag is offline
Junior Member
 
Join Date: 2006-04-07
Posts: 27
Rep Power: 0
vadi_ag has an average reputation (10+)
Default Re: Policy recovery

Hi All
Thnx a lot for ur reply I do agree with u that if the time out error occurs then policy gets installed but this time i got this error and if i try to reinstall this policy then i am unable to do so can u pls help me on this i think that the policy is corrupted is there any way to recover this policy
Reply With Quote
  #5 (permalink)  
Old 2006-04-10
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Policy recovery

Do you use phisical or virtual environment? Check loading your servers, free resources.

You can increase timeout between the SmartCenter server to the module:
1. stop the SmartCenter server
2. edit $FWDIR/conf/objects_5_0.C
3. search :install_policy_timeout
4. edit value in brackets
5. save the file and start the SmartCenter
6. Install the policy.
Reply With Quote
  #6 (permalink)  
Old 2006-04-10
vadi_ag vadi_ag is offline
Junior Member
 
Join Date: 2006-04-07
Posts: 27
Rep Power: 0
vadi_ag has an average reputation (10+)
Default Re: Policy recovery

Hi
Thnx for ur help this time the policy got installed
But I need to know Is there any way to recover the policy if it gets corrupted anticipating ur reply
Reply With Quote
  #7 (permalink)  
Old 2006-04-10
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Policy recovery

What does it mean corrupted policy?
You can verify policy. If process of verify end without errors that does mean policy is correct. If you install policy and process of verify send you error, this policy doesn't install on your module.
You have troubles only if you get error messages in installation process (after correct verifying). But it doesn't connected with corrupted policy. If you have error in this case you need to reinstall policy.
Reply With Quote
  #8 (permalink)  
Old 2006-04-11
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Policy recovery

When you push a policy, select the check box at the bottom to save a backup to the database. You can then revert to that backup from the File menu. This recovers the user database, the SmartDefense settings, a whole lot of stuff besides the policy.

Or use the command line upgrade_export.exe to occasionally create a .tgz compressed backup of your entire SmartCenter configuration, and burn it to a DVD or something for backup.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:53.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0