CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-01
sachden sachden is offline
Junior Member
 
Join Date: 2005-10-03
Location: India
Posts: 12
Rep Power: 0
sachden has an average reputation (10+)
Default Requirement for "fw unload local" command

Hi all

We manage lot of Checkpoint firewalls for our customers.During one of the issues a CP Mgmt Server (for which we take RDP) was rebooted , it came up however only onsite engineer (at datacentre ) was able to see . When we tried pinging locally (please note ping was working earlier from our end to management server) we were not able to reach the server.After that we asked our onsite engg. to give comamnd "fw unload local " , after that we were able to take RDP of the mgmt server

Please let me know as to in whch circumstance this command is used and why in my circumstance it was required

Regrds
Ankur
Reply With Quote
  #2 (permalink)  
Old 2008-05-01
eduardw eduardw is offline
Member
 
Join Date: 2007-08-04
Posts: 49
Rep Power: 0
eduardw has an average reputation (10+)
Default Re: Requirement for "fw unload local" command

Hi,

fw unloadlocal is usually used on firewalls when you by accident ad a rule to the policy which blocks the traffic to the firewall. Or after a clean install the default policy will block almost traffic to and through the newly installed firewall.
This command unloads the local fw policy and also stops the routing deamon. So then you are only able to communicate to the firewall and not able to send packets through it.
But in you case It looks like that your management station also has a firewall policy. Check the checkpoint object of your management station and see if the fw1 option is highlighted.
When you do not use your management station as a firewall you could deactivated the firewall on the management station. When it also is in use as a firewall make sure the appropriate rules for management are in place.

Eduard
Reply With Quote
  #3 (permalink)  
Old 2008-05-01
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Requirement for "fw unload local" command

What that means is that there is a firewall module running on the management server. Not sure that is the intended scenario. That's why you needed to unload the policy before you could connect.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:45.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0