<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Smart1 - Firewalls - Checkpoint extract info - Package - Routes in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/172102#M31257</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;&lt;P&gt;I understand that users with admin-role have no problem to connect via scp to SMART1.&lt;BR /&gt;If I want to generate a particular user for this purpose I would have to execute:&lt;BR /&gt;R80&amp;gt;=&lt;BR /&gt;Example:&lt;BR /&gt;add user scpuser01 uid 2700 homedir /home/scpuser&lt;BR /&gt;set user scpuser realname Scpuser&lt;BR /&gt;add rba role scpRole domain-type System readwrite-features expert&lt;BR /&gt;add rba user scpuser roles scpRole&lt;BR /&gt;set user scpuser gid 100 shell /usr/bin/scponly&lt;BR /&gt;set user scpuser password&lt;BR /&gt;save config‍‍‍‍‍‍‍‍‍‍‍‍‍‍&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to this, the netstat command is valid for Gaia Clish Commands:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/202015" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/202015&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are asking me to pull/execute from checkpoint:, well from SMART-1 this:&lt;BR /&gt;java -jar web_api_show_package-jar-with-dependencies.jar -k &amp;lt;PACKAGE NAME&amp;gt;&lt;BR /&gt;So they tell me that it generates a tar.gz file that I have to get and deliver.&lt;/P&gt;&lt;P&gt;Thank you for your time and comments.&lt;/P&gt;&lt;P&gt;I remain attentive&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Mon, 20 Feb 2023 23:15:11 GMT</pubDate>
    <dc:creator>CheckGatzMet</dc:creator>
    <dc:date>2023-02-20T23:15:11Z</dc:date>
    <item>
      <title>Smart1 - Firewalls - Checkpoint extract info - Package - Routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/171930#M31233</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;SPAN&gt;Hello CheckMates! good afternoon&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;I hope you are very well.&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;I have a doubt, of a FW or some Firewalls Checkpoints that you have to obtain the Package of policies, which have a SMART1 console Appliance and two FW in cluster.&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;Environment: SMART-1=====FW01--FW02&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;When entering in expert mode, in the SMART1:&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;1.- Is the Linux command cp valid ? is it copy or some other command ? to copy and move a file from one directory to another ? ?&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;2.- To get the Package, do you get it from the SMART1 CLI or from the firewalls ?&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;3.- For the routes netstat -nr &amp;gt; routes.txt, is this taken from the Firewalls or from the SMART1 ? this command executes from expert mode or Gaia Shell?&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;4.- If I connect for example with WinSCP to the Smart-1 or one of the Firewalls, can I remove, copy, move files without problems ?&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;5.- When I run these scripts, the package file that it generates, in which path is it placed ? in the same directory where I run it ?&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;6.-&amp;nbsp;&lt;/FONT&gt;To update the version of I have to put the new version &lt;FONT size="3"&gt;web_api_show_package-jar-with-dependencies.jar&amp;nbsp;&lt;/FONT&gt;in the path:&amp;nbsp;&lt;FONT size="3"&gt;MDS_FWDIR/api/samples/lib/ then execute: only $MDS_FWDIR/scripts/web_api_show_package.sh or I need execute&amp;nbsp;java -jar web_api_show_package-jar-with-dependencies.jar -v and then&amp;nbsp;java -jar web_api_show_package-jar-with-dependencies.jar -k &amp;lt;PACKAGE NAME&amp;gt; -d &amp;lt;DOMAIN NAME&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;Scripts:The Check Point Management Server also has a wrapper script so the tool can be run as $MDS_FWDIR/scripts/web_api_show_package.sh which in turn executes java -jar $MDS_FWDIR/api/samples/lib/web_api_show_package-jar-with-dependencies.jar&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;&lt;EM&gt;-Export Package ( Exporting Configuration )&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;&lt;A class="" href="https://github.com/CheckPointSW/ShowPolicyPackage" target="_blank" rel="noopener nofollow ugc"&gt;https://github.com/CheckPointSW/ShowPolicyPackage&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;&lt;A class="" href="https://github.com/CheckPointSW/ShowPolicyPackage#examples" target="_blank" rel="noopener nofollow ugc"&gt;https://github.com/CheckPointSW/ShowPolicyPackage#examples&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;&lt;A class="" href="https://community.checkpoint.com/t5/API-CLI-Discussion/Enabling-web-api/td-p/32641" target="_blank" rel="noopener nofollow ugc"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion/Enabling-web-api/td-p/32641&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;Thanks for your time, support, collaboration, and good vibes.&lt;/FONT&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;FONT size="3"&gt;Best regards&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 18 Feb 2023 00:48:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/171930#M31233</guid>
      <dc:creator>CheckGatzMet</dc:creator>
      <dc:date>2023-02-18T00:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Smart1 - Firewalls - Checkpoint extract info - Package - Routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/171932#M31234</link>
      <description>&lt;OL&gt;
&lt;LI&gt;In Expert Mode, cp works the same as it does on a regular Linux system.&lt;/LI&gt;
&lt;LI&gt;"To get the package" what precisely do you mean by this? In any case, you can only get the full details of the policy from the Smart-1. There is a command to retrieve the policy from the CLI of the gateways:&amp;nbsp;&lt;SPAN&gt;db_tool -p $FWDIR/state/local/FW1 get_rules&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;netstat can only be executed from expert mode as it is not a valid clish command. It works similar to a standard Linux system, i.e. only gets routes from the local system.&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;You can use WinSCP. However, the user in question cannot have /etc/cli.sh as the default shell as that will not work.&lt;/LI&gt;
&lt;LI&gt;Believe it puts the output in current working directory.&lt;/LI&gt;
&lt;LI&gt;If you're using a different version of the Show Package Tool than is included in your installation, then I would execute it separately (i.e. not replace the existing installed version).&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sat, 18 Feb 2023 02:52:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/171932#M31234</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-18T02:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Smart1 - Firewalls - Checkpoint extract info - Package - Routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/172024#M31254</link>
      <description>&lt;P&gt;There is a caveat. The command `&lt;SPAN&gt;db_tool -p $FWDIR/state/local/FW1 get_rules&lt;/SPAN&gt;` only show the policy the gateway is supposed to have. If a policy installation failure occurs on the gateway it may not actually run that policy. But a nifty command to know about during policy install trouble shoooting.&lt;/P&gt;
&lt;P&gt;And removing files at will is ... frowned upon. If you don't know what the purpose of a file is then just ripping it out is sort of like using the rm command in the wrong directory. It makes for some digital fireworks and a big mess. (Not something I would put on your resume.)&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 08:50:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/172024#M31254</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2023-02-20T08:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Smart1 - Firewalls - Checkpoint extract info - Package - Routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/172102#M31257</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;&lt;P&gt;I understand that users with admin-role have no problem to connect via scp to SMART1.&lt;BR /&gt;If I want to generate a particular user for this purpose I would have to execute:&lt;BR /&gt;R80&amp;gt;=&lt;BR /&gt;Example:&lt;BR /&gt;add user scpuser01 uid 2700 homedir /home/scpuser&lt;BR /&gt;set user scpuser realname Scpuser&lt;BR /&gt;add rba role scpRole domain-type System readwrite-features expert&lt;BR /&gt;add rba user scpuser roles scpRole&lt;BR /&gt;set user scpuser gid 100 shell /usr/bin/scponly&lt;BR /&gt;set user scpuser password&lt;BR /&gt;save config‍‍‍‍‍‍‍‍‍‍‍‍‍‍&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;According to this, the netstat command is valid for Gaia Clish Commands:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/202015" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/202015&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are asking me to pull/execute from checkpoint:, well from SMART-1 this:&lt;BR /&gt;java -jar web_api_show_package-jar-with-dependencies.jar -k &amp;lt;PACKAGE NAME&amp;gt;&lt;BR /&gt;So they tell me that it generates a tar.gz file that I have to get and deliver.&lt;/P&gt;&lt;P&gt;Thank you for your time and comments.&lt;/P&gt;&lt;P&gt;I remain attentive&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 23:15:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/172102#M31257</guid>
      <dc:creator>CheckGatzMet</dc:creator>
      <dc:date>2023-02-20T23:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: Smart1 - Firewalls - Checkpoint extract info - Package - Routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/172208#M31286</link>
      <description>&lt;P&gt;The Show Package Tool generates a tar.gz file because the output of this tool contains multiple things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;HTML files with the policy in a human readable form (open index.html in your web browser)&lt;/LI&gt;
&lt;LI&gt;Multiple JSON files that contain the policy and objects extracted&lt;/LI&gt;
&lt;LI&gt;A log file&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;More details at:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk120342" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk120342&lt;/A&gt;&lt;BR /&gt;A .tar.gz file can be extracted using standard Linux commands (tar -xvfz) or using 7zip on Windows.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 16:55:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart1-Firewalls-Checkpoint-extract-info-Package-Routes/m-p/172208#M31286</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-21T16:55:09Z</dc:date>
    </item>
  </channel>
</rss>

