<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to check modified files/config before replace in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229406#M44179</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a cluster of two 6700 gateways to be replaced with brand new 9200, unfrotunately these old gateways have been managed by an external supplier for years and I'm quite sure they did some changes in files (ie. table.def) or enabled/disabled some configurations.&lt;/P&gt;&lt;P&gt;Is there a way to find exactly what has been changed compared to a default configuration?&lt;/P&gt;&lt;P&gt;Or what do you suggest to keep these changes in the new devices?&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 10 Oct 2024 14:57:48 GMT</pubDate>
    <dc:creator>AkiYa</dc:creator>
    <dc:date>2024-10-10T14:57:48Z</dc:date>
    <item>
      <title>How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229406#M44179</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a cluster of two 6700 gateways to be replaced with brand new 9200, unfrotunately these old gateways have been managed by an external supplier for years and I'm quite sure they did some changes in files (ie. table.def) or enabled/disabled some configurations.&lt;/P&gt;&lt;P&gt;Is there a way to find exactly what has been changed compared to a default configuration?&lt;/P&gt;&lt;P&gt;Or what do you suggest to keep these changes in the new devices?&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 14:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229406#M44179</guid>
      <dc:creator>AkiYa</dc:creator>
      <dc:date>2024-10-10T14:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229416#M44185</link>
      <description>&lt;P&gt;Was this a Full HA cluster (without external management) or with external management?&lt;BR /&gt;Believe you can run the pre-upgrade verifier tool to get this information:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Code" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Code-Body-Body1"&gt;
&lt;TD class="TableStyle-TP_Table_Code-BodyA--Body1"&gt;
&lt;P&gt;&lt;CODE&gt;$MDS_FWDIR/scripts/migrate_server verify -v &lt;SPAN class="mc-variable Book_Variables_Common.tp_cpversion variable"&gt;R81.20&lt;/SPAN&gt; -skip_upgrade_tools_check&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 16:17:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229416#M44185</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-10T16:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229437#M44189</link>
      <description>&lt;P&gt;You can compare needed files between freshly installed gateway and questionable gateway. Make sure the version and Take are the same. Download file to be checked (like table.def) from both gateways, use Excel or NotePad++ features to see differencies between 2 files.&lt;/P&gt;
&lt;P&gt;Another idea can be to check when was needed file last modified. In theory, the .def file is supposed to be modified during upgrade or Jumbo installation. But it can be also modified by management by pushing the file to gateway... You can check when was needed file created, modified and last accessed using linux command "stat".&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 06:00:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229437#M44189</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-10-11T06:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229455#M44194</link>
      <description>&lt;P&gt;I'm guessing there are a lot more files than just table.def. It would be a bit of a hassle to manually download them from the gateway and then compare them manually, even if you knew all the possible candidate files. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 08:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229455#M44194</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2024-10-11T08:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229507#M44199</link>
      <description>&lt;P&gt;Most of .def files are stored on management and pushed to the gateway during policy installation.&lt;/P&gt;
&lt;P&gt;But I am pretty sure there might be some rare cases where .def file was modified directly on gateway.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2024 06:40:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229507#M44199</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-10-12T06:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229561#M44203</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;it's a HA cluster with external management&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 07:23:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229561#M44203</guid>
      <dc:creator>AkiYa</dc:creator>
      <dc:date>2024-10-14T07:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229562#M44204</link>
      <description>&lt;P&gt;This will help a lot:&lt;/P&gt;
&lt;H5 class="css-245gzq"&gt;Creating a file with all the kernel parameters and their values:&lt;/H5&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk33156" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk33156&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Compare the output with new gateway.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 07:27:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229562#M44204</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-10-14T07:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229563#M44205</link>
      <description>&lt;P&gt;Thank you to everyone for the suggestions,&lt;/P&gt;&lt;P&gt;good to know that the table.def is pushed from the Management (which I already upgraded), but what about configurations enabled/disabled on the gateways themselves?&lt;/P&gt;&lt;P&gt;For example I'm thinking of the command to pass the traffic to the standby gateway and similar, is there a way to know if something has been modified compared to a default configuration?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 09:02:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229563#M44205</guid>
      <dc:creator>AkiYa</dc:creator>
      <dc:date>2024-10-14T09:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229624#M44208</link>
      <description>&lt;P&gt;Some of the commands you enter on the gateway are ephemeral, some are not.&lt;BR /&gt;A few things to check/review:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Customizations to the Mobile Access VPN portal (usually involves editing files in $CVPNDIR).
&lt;UL&gt;
&lt;LI&gt;Here I would refer file modification dates compared to stuff in the same directory.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;/web/templates (manual changes to web servers)&lt;/LI&gt;
&lt;LI&gt;/etc/ssh/templates (under the hood changes for SSH)&lt;/LI&gt;
&lt;LI&gt;$FWDIR/conf/fwaccel_dos_rate_on_install (DDoS Mitigation Rules)&lt;/LI&gt;
&lt;LI&gt;$FWDIR/conf/*.ttm and $FWDIR/conf/ipassignment.conf
&lt;UL&gt;
&lt;LI&gt;VPN-related configuration&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;$FWDIR/boot/modules/fwkern.conf and $FWDIR/boot/modules/vpnkern.conf
&lt;UL&gt;
&lt;LI&gt;Recommended to review settings here before copying them over as they may not apply, especially if the version between the two gateways is changing&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;There are likely other files, these are just the ones that come to mind as I type this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 16:17:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229624#M44208</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-14T16:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to check modified files/config before replace</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229730#M44210</link>
      <description>&lt;P&gt;To identify configuration changes on your 6700 gateways, review backups, compare configurations using tools like CCA, or consult the external supplier. Document the changes and test them on a 9200 gateway before migration.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2024 11:37:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-modified-files-config-before-replace/m-p/229730#M44210</guid>
      <dc:creator>Matrio</dc:creator>
      <dc:date>2024-10-15T11:37:07Z</dc:date>
    </item>
  </channel>
</rss>

