CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-08
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Checkpoint backup for Mgmt HA

Hi All,

Wondering how do we backup a mgmt HA?

I know for standalone, we use upgrade_export, on my previous standalone scs, i have done a script to backup the config daily at ard 3am and after that on my nms machine, theres a script to pull the backup from my scs.

I have changed from the standalone to a distributed scs with mgmt ha, i'm currently still doing the above mentioned way of backup currently for my primary scs, and my mgmt ha was jus up like 2 days ago..


Also, is there a more graceful way to do a backup, was thinking what if one of us admin logs in to the dashboard and happily goes home without logging out.. The backup will fail and thats it, no backup done for the day.. any "graceful workarounds"?? was think to add in cpstop b4 the backup, but this seems quite bruteful and imagine the changes the admin done is lost!

Currently running NGX R65 scs on RHEL 3.0, update 9. Would appreciate all help.. thanks..
Reply With Quote
  #2 (permalink)  
Old 2007-11-08
Senior Member
 
Join Date: 2007-07-16
Posts: 603
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Checkpoint backup for Mgmt HA

Send an RFE/Support call to Check Point to request a command-line way to disconnect GUI clients. This is the achilles heel in CP's management backup strategy, and has been for some time. Upgrade_export is still the way to go.
Reply With Quote
  #3 (permalink)  
Old 2007-11-09
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Checkpoint backup for Mgmt HA

ok.. the login for portion for upgrade_export i guess theres no workaround..

but what about the recomended backup procedure for a mgmt ha? do we upgrade_export both pri n sec mgmt?
Reply With Quote
  #4 (permalink)  
Old 2007-11-09
Senior Member
 
Join Date: 2007-06-04
Posts: 1,062
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Checkpoint backup for Mgmt HA

You should upgrade_export both boxes. However the secondary only pulls the important part from the primary so it's not that big a deal to build the secondary from scratch if necessary
Reply With Quote
  #5 (permalink)  
Old 2007-11-09
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Checkpoint backup for Mgmt HA

Quote:
Originally Posted by mcnallym View Post
You should upgrade_export both boxes. However the secondary only pulls the important part from the primary so it's not that big a deal to build the secondary from scratch if necessary
But my concern is that for whatever reason the secondary scs becomes active for a period of time, and theres a problem, we lose the config... is there a way to check if its the primary scs before doing a upgrade_export??

In terms of file structure, or database, lets say the sec scs becomes active/pri, so is the database like a full fledged normal pri scs??

I mean in cli mode, since i'm using a cron script..
Reply With Quote
  #6 (permalink)  
Old 2007-11-11
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Checkpoint backup for Mgmt HA

Quote:
Originally Posted by chuachongchee View Post
But my concern is that for whatever reason the secondary scs becomes active for a period of time, and theres a problem, we lose the config... is there a way to check if its the primary scs before doing a upgrade_export??

In terms of file structure, or database, lets say the sec scs becomes active/pri, so is the database like a full fledged normal pri scs??

I mean in cli mode, since i'm using a cron script..
any help??
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 07:15.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0