CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-04
Member
 
Join Date: 2006-02-17
Posts: 30
Rep Power: 0
pgovindg has an average reputation (10+)
Default Two SmartCenter sever consoldiation to one

Hi Forum guys,

We have two SmartCenter servers manges its own firewall's in diffrent locations and one standalone firewall smartcenter server on the same.

we wanted to accomplish following:

Two smartcenter servers manages diffrent FW's in diffrent locations & one standalone firewall which includes smartcenter.

1. How do I add polices & firewalls of smartcenter server 2 to smartcenter server 1?

2. How do I add standalone firewall to smartcenter server 1?

Please let me know the best method.

Thanks in advance
Reply With Quote
  #2 (permalink)  
Old 2007-09-04
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Two SmartCenter sever consoldiation to one

Personally I would start with a new box and move everything there. Barring that make sure you have good backup, that you can restore.

The tool you want to look at is cp_merge. There are other folks who have used this a lot more than I, but that's where to start...

-----

cp_merge -help
This is Check Point Database Merge tool NG Build NGX (R65) - Build 006.

Usage:
cp_merge merge_objects [-s <db server>] [-u <user> | -c <certificate file>] [-p <password>] -d <input directory> [-t]

cp_merge export_policy [-s <db server>] [-u <user> | -c <certificate file>] [-p <password>] [-n <package name> | -l <policy name> [-f <output file>]] [-d <output directory>] [-r]

cp_merge import_policy [-s <db server>] [-u <user> | -c <certificate file>] [-p <password>] [-n <package name>] [-d <input directory>] -f <input file> [-v]

cp_merge delete_policy [-s <db server>] [-u <user> | -c <certificate file>] [-p <password>] -n <package name>

cp_merge list_policy [-s <db server>] [-u <user> | -c <certificate file>] [-p <password>]

cp_merge restore_policy [-s <db server>] [-u <user> | -c <certificate file>] [-p <password>] [-n <package name>] [-d <input directory>] -f <input file> -v

cp_merge delimited_policy [-s <db server>] [-u <user> | -c <certificate_file>] [-p <password>] [-l <policyname>] [-f <file name>] [-a export | import_new | import_override | import_append ] [-k security | nat | all ]

Run cp_merge -help for detailed usage

-s <server> specify database server IP / name
-c <certificate file> path to certificate file
-u <user> database administrator user name
-p <password> user's password
-d <directory> specify working directory
-help print this summary

Objects Merge options:
-t test mode - does not save

Policy Export options:
-n <package name> policy package to export
-l <policy name> export policy package which <policy name> belongs to.
-r remove the original policy from the repository
-f <file name> specify output file name (default: <policy name>.pol)
(If both '-n' and '-l' are omitted all policies are exported)

Policy Import options:
-f <file name> specify input file name
-v override existing policy if found
-n <policy name> rename policy to <policy name> when importing

Policy Restore options:
-f <file name> specify input file name
-v override existing policy if found
-n <policy name> rename policy to <policy name> when importing
Note: Restore will work only when run locally on managment server.

Policy Delete options:
-n <policy name> policy to delete

Delimited Policy Import/Export options:
-a export export policy
import_new import a new policy
import_override imported policy will replace current
import_append imported policy's rules will be appended to current
-l <policy name> policy to export to/from
-f <file name> file to export to/from
-k security | nat | all types of policy to operate on
Note: security policy file is file_name.sec, NaT policy file is file_name.nat.
Reply With Quote
  #3 (permalink)  
Old 2007-09-05
Senior Member
 
Join Date: 2007-07-16
Posts: 603
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Two SmartCenter sever consoldiation to one

Nother useful tool is Object Filler and Object Dumper Download Site . I've found cp_merge to be very unrelieable.

You can use the object filler/dumper to dump the objects and then import them back into the other system. This gives you better control over integration of objects and duplicates etc... It does mean you'll need to manually re-create rules, but as part of the consolidation you should be doing a review of the rulebases anyway.....

Good luck.
Reply With Quote
  #4 (permalink)  
Old 2007-09-05
Member
 
Join Date: 2006-02-17
Posts: 30
Rep Power: 0
pgovindg has an average reputation (10+)
Default Re: Two SmartCenter sever consoldiation to one

Thanks You friends, let me try out...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:40.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0