CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-12
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 552
Rep Power: 10
BarryStiefel has disabled reputation
Default How do I edit objects.C or objects_5_0.C properly?

How do I edit objects.C or objects_5_0.C properly?



Editing objects.C is a lot more successful when there are no GUI clients (fwpolicy, fwlog, fwstatus) running against the management console. You can ensure that this is the case by killing the 'fwm' process using the command cpwd_admin stop -name FWM in NG or fw kill fwm in 4.1 and earlier. You can restart it by typing cpwd_admin start -name FWM in NG or fw fwm in 4.1. You should also remove objects.C.sav and objects.C.bak since if they have a more recent timestamp than objects.C, FireWall-1 will replace objects.C with one of these files. If your management console is on Windows, then make sure you use DOS edit or Wordpad. Do not use notepad!

Check Point generally recommends you fwstop or cpstop your management console when applying manual changes to objects.C, then typing fwstart or cpstart.

All changes to objects.C generally require re-installing the policy for them to take effect.

In NG, it is generally recommended that you use a utility called dbedit to edit the objects_5_0.C file. A graphical version of this utility called GUIdbedit is also available from Check Point's site. If your management console is on a Nokia platform and you are using a version of NG prior to FP3, dbedit is known to be unstable and should not be used. In these cases, use GUIdbedit or manually edit the file. An example of using dbedit is provided below.

c:> dbeditEnter Server name (ENTER for 'localhost'): 10.0.0.16Enter User Name: dwelchEnter User Password: abc123Please enter a command, -h for help or -q to quit:dbedit> modify properties firewall_properties nat_dst_client_side_manual truedbedit> update properties firewall_properties firewall_properties updated successfully.dbedit> quitAlternatively, you may wish to use the Check Point Database Tool (guidbedit), available from the Check Point Utilities Download Page.-- Main.PhoneBoy - 30 Dec 2003

FAQForm FAQs.Class: MiscellaneousFAQs OperatingSystem?: FAQs.Version:
Reply With Quote
  #2 (permalink)  
Old 2005-11-24
HotDog HotDog is offline
Junior Member
 
Join Date: 2005-11-24
Location: Sweden
Posts: 1
Rep Power: 0
HotDog has an average reputation (10+)
Default Re: How do I edit objects.C or objects_5_0.C properly?

Hi,
I cant edit the objects_5_0.c to add a post_connect _script into SecureClient VPN.

I have tried to change the objects_5_0.c in order to get a post_connect_script to run after successfull vpn connection.

I run cpstop, edit the objects_5_0.c file with dbedit - post_connect_script (c:\blabla.bat). The change is applied to the file.
I run cpstart. I open the smart dashboard an reinstall the policy.

I use the SecureClient packaging tool and create an install package (connect mode). I create a new site in the SecureClient an connect to our FW1.
The policy gets uppdated. But ther is no sign of the post_connect script

Did i miss something ? Tried to follow the post "How do I edit Objects_5_0.c properly"

Regards
HotDog
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:33.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0