CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-16
ajlafontaine ajlafontaine is offline
Junior Member
 
Join Date: 2006-05-16
Location: Toronto, Canada
Posts: 1
Rep Power: 0
ajlafontaine has an average reputation (10+)
Default Install Database > FW module doesn't show?

In the process of rolling out an NGX R60 installation beside an existing NG FP3 setup that is to be retired. When trying to install the user database selectively to update different FW modules, only the primary smart center FW appears in the list. Other FW modules managed from this smartcenter do not show up.

At one point I had a similar problem with NG FP3 but I just can't remember what I did to fix it. All settings between the new NGX and the old NG FP3 are identifical. This is a pain as some "user admins" are not allowed to update the rules, which is the only way to install user database for those FW modules at the moment.

Any ideas?
Reply With Quote
  #2 (permalink)  
Old 2006-08-11
humayun humayun is offline
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default Re: Install Database > FW module doesn't show?

I have a basic question, how do you install the User Database from the Dashboard to your firewall objects?

Needed urgently as I am assuming a corrupted database.
Thanks.
__________________
Systems Engineer
Reply With Quote
  #3 (permalink)  
Old 2006-08-11
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Install Database > FW module doesn't show?

You can "install database" only on SmartCenter, Log modules etc, not on modules. This feature helps to update users and groups without re-installing the Rule Base.
Reply With Quote
  #4 (permalink)  
Old 2006-08-12
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 776
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Install Database > FW module doesn't show?

humayun, if you think the DB is corrupted, just install policy on the module - that also installs the database.

ajlafontaine, you used to be able to have users who could install the database only, and then it became something you could only do by editing objects_5_0.C - have a look at sk15270. You need to edit allow_install_users_db_on_module

However, you should be warned that this can cause some problems. What ends up happening is that the DB gets out of sync with the policy. What I've seen happen is for SecureClient to start dropping all the authenticated rules on the cleanup rule, until you reinstall policy. I'm not sure exactly what causes it - things will be going fine, install DB a few times, no problems - and then it stops working. I'm not sure if it's caused by certain sorts of changes - perhaps user/object deletes?

I don't know what your setup is, but I understand having something like that, where you have user admins who are separate from the firewall team. What you could do, if the users are being authenticated externally, is to use a generic* user, and let the ACE server (or whatever) handle it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:09.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0