CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-22
Brentd Brentd is offline
Member
 
Join Date: 2006-09-25
Posts: 42
Rep Power: 0
Brentd has an average reputation (10+)
Default Policy revision question

Hi

I have two questions;

Q.
How do I know what version of the policy revision I have now loaded in the Smart Center?

Q.
How do I know what revision was last pushed to the gateway?

Thanks
(It would be great if this info could be shown in the GUI)
Brent
Reply With Quote
  #2 (permalink)  
Old 2007-04-24
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 788
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Policy revision question

Quote:
Originally Posted by Brentd View Post
How do I know what version of the policy revision I have now loaded in the Smart Center?
There is "Current" and "Previous" [which are numbered]. When you start up the Smart Center, you're looking at the current policy revision.

Quote:
Originally Posted by Brentd View Post
How do I know what revision was last pushed to the gateway?
(It would be great if this info could be shown in the GUI)
Smartview Monitor will show you when the last push date+time was. This will most likely coincide with a policy revision creation time. The only catch is if someone were to load up a previous policy and restore that version...I'm not exactly sure what would happen in that instance--they will be prompted to back up the current revision and prompted to create a new revision when they push said policy, if they don't create those revisions then you'd have a time mismatch between what the firewall reports and the revision history. There are logs in Smartview tracker when a policy is pushed & hopefully when it's reverted, see the "Control" messages.

HTH
Reply With Quote
  #3 (permalink)  
Old 2007-04-24
Brentd Brentd is offline
Member
 
Join Date: 2006-09-25
Posts: 42
Rep Power: 0
Brentd has an average reputation (10+)
Default Re: Policy revision question

Hi

I do not know whether you understood my question, maybe I explained it badly..

Take 2:

Lets say you have a policy that you have made 10 revisions of, then for some reason you have had to restore from an earlier one. You then install that policy to the GW, if then you were to restore an earlier one from the revision DB. This now means that your GW has one revision on it the smartcenter has another.

Now I ask the question again, how do I find what revision is on the GW and which I have in the SC... I believe there is a way of doing this (especially the one on the GW, more so than the SC)

Thanks!
Brent
Reply With Quote
  #4 (permalink)  
Old 2007-04-25
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 788
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Policy revision question

Quote:
Originally Posted by Brentd View Post
Now I ask the question again, how do I find what revision is on the GW and which I have in the SC... I believe there is a way of doing this (especially the one on the GW, more so than the SC)
Look at the output that Smartview Monitor / cpinfo [for example "/opt/CPshrd-R60/bin/cpstat -f policy fw"] gives you--there's nothing related to revision number. It only knows the date and time the policy was pushed / loaded. Using this information you could infer which revision is installed, for example:

Quote:
Originally Posted by Brentd View Post
Lets say you have a policy that you have made 10 revisions of, then for some reason you have had to restore from an earlier one.
You restore a policy. The policy server is now loaded up on revision 4--there are still 10 revisions in the database. So far so good.

Quote:
Originally Posted by Brentd View Post
You then install that policy to the GW,
You install that policy--since everyone enjoys revision control there's going to be a new revision--now the GW has policy revision 11, with date 4/25/2007 1:47pm.

Quote:
Originally Posted by Brentd View Post
if th you were to restore an earlier one from the revision DB.
You see that revision 4 doesn't have the objects you recently added, so you restore revision 9.

Now the GW is on revision 11 (aka revision 4), smartdashboard is on revision 9 (aka revision 12 when its pushed).

Quote:
Originally Posted by Brentd View Post
This now means that your GW has one revision on it the smartcenter has another.
True, however the timestmp on the GW's policy push will match the timestamp for when revision 11 was created. You can still identify which revision the GW is running--which is what you're after.

In this case it's up to YOU to know that you restored a revision that is not loaded on the gateway. If you cannot control which revision is loaded on the dashboard at any given time, then keep track of what revisions you've made and simply restore it when you start up SmartDashboard. You'll most likely lose changes but I'm guessing you've got bigger problems at this point.

If you're environment is unstable and your firewall reboots while you have an earlier revision restored (yet not pushed) then you may be in a position where you may not be positive as to which revision is loaded. I think the lesson here would be to not restore a revision unless you intend for it to be pushed immediately, and in this case of a rebooting GW I would push the policy again after reboot just to ensure the proper revision were on the GW.

Last edited by melipla; 2007-04-26 at 12:55.
Reply With Quote
  #5 (permalink)  
Old 2007-04-25
Brentd Brentd is offline
Member
 
Join Date: 2006-09-25
Posts: 42
Rep Power: 0
Brentd has an average reputation (10+)
Default Re: Policy revision question

This is great information,

thanks again for your reply, I now understand your initial answer much better!

Brent
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:40.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0