<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing fwkern.conf. What environment variables are currently running? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Missing-fwkern-conf-What-environment-variables-are-currently/m-p/29430#M2350</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that Aleksei. Some of their gateways have been up for over &lt;STRONG&gt;900&lt;/STRONG&gt; days, where as the rest have an up-time of between 3-350 days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at their As-Builds, it doesn't state any such config, however the As-Builds are incorrect, as I've come to learn myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think I'll just bite the bullet then and carry on and list that as a caveat in my documentation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Feb 2018 18:51:13 GMT</pubDate>
    <dc:creator>Ray_Lal</dc:creator>
    <dc:date>2018-02-14T18:51:13Z</dc:date>
    <item>
      <title>Missing fwkern.conf. What environment variables are currently running?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Missing-fwkern-conf-What-environment-variables-are-currently/m-p/29428#M2348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a customer who's running R77.20 for their G/W's and Logs, and 77.30 for their CMA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am upgrading their gateways and logs to R77.30, however the one concern I have is that since they dont have any fwkern.conf files, whatever environment variables they have running will not survive a reboot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any magic command I can run to do this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be taking a snapshot, but small niggly things could cause alot of headaches weeks down the line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Feb 2018 03:22:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Missing-fwkern-conf-What-environment-variables-are-currently/m-p/29428#M2348</guid>
      <dc:creator>Ray_Lal</dc:creator>
      <dc:date>2018-02-14T03:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Missing fwkern.conf. What environment variables are currently running?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Missing-fwkern-conf-What-environment-variables-are-currently/m-p/29429#M2349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a normal situation - to not have fwkern.conf file. Usually administrators creates this file&amp;nbsp;himself, for these additional kernel settings to survive a reboot, when they are required for sure. If there is no fwkern.conf file and admin doesn't know about any additional parameters, I would assume that they are not needed in this case. Because even in case of power outage they need to somehow restore these parameters.&lt;/P&gt;&lt;P&gt;And did they never reboot their gateways? It is not a good&amp;nbsp;practice for Check Point gateways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this is what you need, but I never used it myself in practice:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33156" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33156"&gt;Creating a file with all the kernel parameters and their values&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the solution above is not working, or you want to make sure and verify, you can get a parameter value with &lt;SPAN style="font-size: 12px;"&gt;&lt;STRONG style="font-family: terminal, monaco, monospace;"&gt;fw ctl get int &amp;lt;parameter&amp;gt;&lt;/STRONG&gt; &lt;/SPAN&gt;command. But for that you need to know the exact name of a parameter. So you can try to find out if some of oftenly used parameters are changed, for example:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;STRONG style="font-family: terminal, monaco, monospace;"&gt;fw ctl get int fwha_mac_magic&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;STRONG style="font-family: terminal, monaco, monospace;"&gt;fw ctl get int&amp;nbsp;fwha_mac_forward_magic&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;STRONG style="font-family: terminal, monaco, monospace;"&gt;fw ctl get int&amp;nbsp;fwha_forw_packet_to_not_active&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-weight: 400;"&gt;&lt;/P&gt;&lt;P style="font-weight: 400;"&gt;Here is a list of some other parameters -&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33285" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33285"&gt;Kernel Global Parameters&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-weight: 400;"&gt;And you can try to find some other ones on Support Center in different sk by searching "kernel parameters":&lt;/P&gt;&lt;P style="font-weight: 400;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656"&gt;Dynamic NAT port allocation feature&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-weight: 400;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43872" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43872"&gt;ClusterXL - CCP packets and fwha_timer_cpha_res kernel parameter&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Feb 2018 07:31:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Missing-fwkern-conf-What-environment-variables-are-currently/m-p/29429#M2349</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-02-14T07:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Missing fwkern.conf. What environment variables are currently running?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Missing-fwkern-conf-What-environment-variables-are-currently/m-p/29430#M2350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that Aleksei. Some of their gateways have been up for over &lt;STRONG&gt;900&lt;/STRONG&gt; days, where as the rest have an up-time of between 3-350 days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at their As-Builds, it doesn't state any such config, however the As-Builds are incorrect, as I've come to learn myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think I'll just bite the bullet then and carry on and list that as a caveat in my documentation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Feb 2018 18:51:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Missing-fwkern-conf-What-environment-variables-are-currently/m-p/29430#M2350</guid>
      <dc:creator>Ray_Lal</dc:creator>
      <dc:date>2018-02-14T18:51:13Z</dc:date>
    </item>
  </channel>
</rss>

