Re: [fw-wiz] Backup Checkpoint Firewall

From: Nathaniel Hall (halln_at_otc.edu)
Date: 05/17/05

  • Next message: Paul Melson: "RE: [fw-wiz] PIX -> ISA -> OWA Configuration"
    To: Paul Melson <psmelson@comcast.net>, firewall-wizards@honor.icsalabs.com
    Date: Tue, 17 May 2005 10:51:55 -0500
    
    

    Thanks for the input. My next problem is with upgrade_export it says the following:

    "You are required to close all Check Point clients before the export begins. If the export fails, stop Check Point
    services and run the upgrade_export command again. Press ENTER when ready.."

    Problem 1) How can I ensure all clients are closed? My first thought was to run cpstop, but my coworker said it used to
    only stop the Dashboard, but now it stops everything. That is a problem since backups are going on at the same time.

    Problem 2) Press ENTER when ready. How would I do that in a batch file?

    I know this is not the best place for problem 2, but it is still a problem.

    Nathaniel Hall, GSEC
    Intrusion Detection and Firewall Technician
    Ozarks Technical Community College -- Office of Computer Networking

    halln@otc.edu
    417-447-7535
    GPG Public Key ID: 0xAC187312

    Paul Melson wrote:
    > I would use upgrade-export on the SmartCenter server to create backups.
    > This should get you everything you could ever hope to restore into a single
    > file. It definitely meets the last two criteria, and it should be easy
    > enough to encrypt, since the actual export is a tar/gzip archive. To
    > restore, you use the appropriately-named upgrade-import tool.
    >
    > PaulM
    >
    > -----Original Message-----
    > Subject: [fw-wiz] Backup Checkpoint Firewall
    > I am working on creating a secure means to backup a CheckPoint FW-1 with AI
    > firewall. I have procedures for encrypting the information, but what is the
    > best way to get all of the configuration? Here is what I would like to
    > have:
    >
    > Text output (preferred, I can encrypt to ASCII if needed)
    > All configuration settings
    > Easy way to import into a new installation
    >
    > If this is possible, what would be the command to execute to get the backup
    > and the command to import it back in? If it isn't possible, what is the
    > best way?
    >
    >

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul Melson: "RE: [fw-wiz] PIX -> ISA -> OWA Configuration"

    Relevant Pages

    • Re: IPTABLES
      ... > I need to setup the firewall IPTABLES on CentOS. ... You set up the firewall using command line commands. ... > allow to acces FROM the LAN only to a computer with MAC ADRESS xxxxxx. ...
      (comp.os.linux.setup)
    • Re: Adobe Reader will not launch in XP Home Edition SP 2
      ... for older versions of Adobe Reader all the way back to 5.x, ... and then when trying to launch the reader by clicking on a pdf file I get ... It might be your firewall, ... Results of command "notepad c:\test.txt" ...
      (microsoft.public.windowsxp.general)
    • Re: Problem about Window Xp SP2 firewall and the buildin FTP command
      ... I checked the firewall log, ... I always test the XP SP2 on both my own FTP ... I copy your example ftp command file to a.txt saved in C:\dell folder. ... I cannot turn off Windows Firewall, since it is controlled by Domain ...
      (microsoft.public.windowsxp.general)
    • Re: vista backup restore
      ... virtual pc is installed and try out the command that i have provided below. ... > Should I install virtual server? ... >> backups done and the files within it -- is wiped out. ... >> coming to restore files from complete pc - were you able to restore>> the ...
      (microsoft.public.windows.vista.file_management)
    • Re: SCO 5.0.7 AS ROUTER
      ... This command in the distribution startup script is a security hole: ... if you run it after startup, there is a momentary opening in the firewall ... between erasing the old entries and loading the new entries and of course, ...
      (comp.unix.sco.misc)