CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-25
Junior Member
 
Join Date: 2006-08-03
Posts: 12
Rep Power: 0
JoeShmoe has an average reputation (10+)
Default Manually updating Policy on standalone Firewall

We have a scenario where we are upgrading our mgt server to NGX R61 but still have 10 firewalls on our estate that are FP2 and thus incompatible.

These are due to be decomm'd in 3 months but in the meantime we need some way of keeping them in service and allowing this mgt server upgrade (which we need for other project functionality)

Therefore what we want to do is disconnect these firewalls and leave them standalone. However if a policy change is made on the parent group of firewalls these 10 would come under, can we somewhow export the ploicy off the mgt server, and import the file into these Firewalls manually? Do the Firewalls have some sort of command line interface that would allow import of policy files? Weve only ever done this as a push down from a mgt server?

Many Tks
Reply With Quote
  #2 (permalink)  
Old 2007-01-25
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Manually updating Policy on standalone Firewall

Bit of a tricky scenario. I think it might be possible to manually edit .pf files and the like, but there's no way I'd want to do it in production.

If I was in your position, I'd probably build a new R61 server, and manage my upgraded firewalls with that, leaving the FP2 one alone.

Or, if you want to keep using the FP2 hardware, then I'd export the config from that management station to another R55 system, and manage the old firewalls with that.

If you're only looking at a handful of possible changes, for low traffic firewalls, then just chuck SPLAT R55 on any old PC, and manage the FP2 systems with that, while you upgrade your main management server
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 21:14.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0