CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-22
Member
 
Join Date: 2006-09-25
Posts: 42
Rep Power: 0
Brentd has an average reputation (10+)
Default Staging updates in SmartCenter

Hi all

I have a customer that wishes to stage updates to the Smart Center. These updates will be added and saved to the smartcenter however they will be installed at a predetermined time (not before).

I believe this could prove problematic because when/if the Gateways are rebooted they will automatically fetch the policy.

Q. Is there a way to disable the default fetching function on the GW, specifically SPLAT, but if it can also be done on other OS's as well I would love to know about it!

Thanks
Brent
Reply With Quote
  #2 (permalink)  
Old 2007-04-24
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Staging updates in SmartCenter

Quote:
Originally Posted by Brentd View Post
Hi all

I have a customer that wishes to stage updates to the Smart Center. These updates will be added and saved to the smartcenter however they will be installed at a predetermined time (not before).

I believe this could prove problematic because when/if the Gateways are rebooted they will automatically fetch the policy.

Q. Is there a way to disable the default fetching function on the GW, specifically SPLAT, but if it can also be done on other OS's as well I would love to know about it!

Thanks
Brent
I don't think you can get the gateway to unlearn it's "master" and thus be unable to pull a policy. The only method I can think of is to either block the traffic--via firewall rule (although its probably implied) or break the network routing so its unable to fetch a policy, in which case you may block the logging functionality too.

Why not have the user not save the changes until a specific time?
Reply With Quote
  #3 (permalink)  
Old 2007-04-24
Member
 
Join Date: 2006-09-25
Posts: 42
Rep Power: 0
Brentd has an average reputation (10+)
Default Re: Staging updates in SmartCenter

Thanks for the reply,

That is the way they wish their change control structure to function. They can save edits to the SmartCenter but only want these showing up on the GWs when they choose!

Hence having a GW reboot and pickup the changes would be bad for them!

Thanks
Brent
Reply With Quote
  #4 (permalink)  
Old 2008-01-22
Member
 
Join Date: 2006-09-25
Posts: 42
Rep Power: 0
Brentd has an average reputation (10+)
Default Re: Staging updates in SmartCenter

I will answer my own post here for others that wish to know!

When you change and save a policy to the smart center this will not be picked up by a firewall that is performing a fetch, it seems that a fetch will only get the last compiled policy from the SC and not the changes that have been saved if those changes were never installed on the gateway.

Brent
Reply With Quote
  #5 (permalink)  
Old 2008-01-23
Senior Member
 
Join Date: 2007-07-16
Posts: 625
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Staging updates in SmartCenter

Brent is correct about the way that Fetch works.

The one thing to be careful about if doing this is to realise that the policy you see in the dashboard and the policy that is being enforced will be different. BUT.... in the File Menu on the SmartDashboard there is an option called Installed Policies - using this, you can View the installed policy on a gateway, and accurately troubleshoot with the installed policy.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:55.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0