CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-15
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default checkpoint sk33821 and hotfix 249

How can you tell if a system has been patched with Checkpoint hotfix
249 from sk33821? For example, this is my system before the patch:

BEFORE:
[root@Linux-lab hfa_249]# fwm mds ver
This is Check Point Provider-1 Server NGX (R65) HFA_02, Hotfix 602 - Build 003
[root@Linux-lab hfa_249]#

AFTER:
[root@Linux-lab hfa_249]# fwm mds ver
This is Check Point Provider-1 Server NGX (R65) HFA_02, Hotfix 602 - Build 003
[root@Linux-lab hfa_249]#


If you're a consultant walking into a new environment, how can you tell if
a system has been patched with this sk? Installing it again on the same
system is NOT an option. Bad things could happen.
Reply With Quote
  #2 (permalink)  
Old 2008-03-15
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 861
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: checkpoint sk33821 and hotfix 249

Does it support the -k switch, as in

fw ver -k

on a non-P1 system?

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-03-15
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: checkpoint sk33821 and hotfix 249

I found the solution myself. For those who are interested, here it is.
The solution is the same for both Provider-1 and SmartCenter:

[root@Linux-lab root]# mdsenv (Provider-1 system only)
[root@Linux-lab root]# cd $CPDIR
[root@Linux-lab CPshrd-R65]# ls
bin database LICENSE.TXT registry svn_HOTFIX_R65_02_bcp.tgz util
conf lib log svn_HOTFIX_ENF_HF_HA02_249_bcp.tgz tmp
[root@Linux-lab CPshrd-R65]#


As you can see, if you see 249 in this directory, then you know.
Reply With Quote
  #4 (permalink)  
Old 2008-03-15
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 323
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: checkpoint sk33821 and hotfix 249

Not sure about this - doesn't this just mean the hotfix file is on the system, not necessarily that the installer has been run? Or am I missing something....
Reply With Quote
  #5 (permalink)  
Old 2008-03-15
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: checkpoint sk33821 and hotfix 249

if you see "svn_HOTFIX_ENF_HF_HA02_249_bcp.tgz" in the $CPDIR
directory, it means that someone did run the "UnixinstallScript" before
Reply With Quote
  #6 (permalink)  
Old 2008-03-16
jacobsen jacobsen is offline
Member
 
Join Date: 2006-07-10
Location: Germany
Posts: 30
Rep Power: 0
jacobsen has an average reputation (10+)
Default Re: checkpoint sk33821 and hotfix 249

Hi,

how about to query the cp registry:


[Expert@fw]# ckp_regedit -p "//SOFTWARE//CheckPoint//FW1//6.0//HotFixes"
//SOFTWARE//CheckPoint//FW1//6.0//HotFixes : { HOTFIX_R65_02=[s]1 HOTFIX_ENF_HF_HA02_249=[s]1 }

[Expert@fw]# ckp_regedit -p "//SOFTWARE//CheckPoint//FW1//6.0//HOTFIX_ENF_HF_HA02_249"
//SOFTWARE//CheckPoint//FW1//6.0//HOTFIX_ENF_HF_HA02_249 : { SilentUninstall=[s]/opt/CPsuite-R65/uninstall_fw1_HOTFIX_ENF_HF_HA02_249 -SU }

getting a positive result must not mean, that the hotfix is actualy installed.
it only means, the unixinstallscript (well the binarie which is called then) made that reg entry.

I had the situation when the unixinstallscript ended with error messages and the hotfix wasnt installed proper.
I tried to install the hotfix again, but got the error message "already installed".
After I deleted both registry entries i was able to install the hotfix again.
that solved it.

cheers
J
Reply With Quote
  #7 (permalink)  
Old 2008-03-17
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 118
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: checkpoint sk33821 and hotfix 249

If the patch has been installed you will see the uninstall option in opt/CPsuite-R65.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:43.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0