<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How install InitialPolicy after use fw unloadlocal in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-install-InitialPolicy-after-use-fw-unloadlocal/m-p/243242#M47254</link>
    <description>&lt;P&gt;If you haven't installed a different policy (after the uninstall) then just running &lt;STRONG&gt;fw fetch localhost&lt;/STRONG&gt; will fetch the Initial Policy.&lt;/P&gt;
&lt;P&gt;If you want to install / fetch Initial Policy when there is a different policy you will need compile it and perform additional steps&lt;/P&gt;</description>
    <pubDate>Fri, 07 Mar 2025 08:48:10 GMT</pubDate>
    <dc:creator>Tal_Paz-Fridman</dc:creator>
    <dc:date>2025-03-07T08:48:10Z</dc:date>
    <item>
      <title>How install InitialPolicy after use fw unloadlocal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-install-InitialPolicy-after-use-fw-unloadlocal/m-p/243221#M47243</link>
      <description>&lt;P&gt;I used the command fw unloadlocal on my cluster XL gateways, but I would like to install the initial policy. How could I do that?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 00:50:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-install-InitialPolicy-after-use-fw-unloadlocal/m-p/243221#M47243</guid>
      <dc:creator>SecdetKrypton</dc:creator>
      <dc:date>2025-03-07T00:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: How install InitialPolicy after use fw unloadlocal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-install-InitialPolicy-after-use-fw-unloadlocal/m-p/243229#M47250</link>
      <description>&lt;P&gt;This is in the Installation and upgrade guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Security-Before-Firewall-Activation.htm?TocPath=Special%20Scenarios%20for%20Security%20Gateways%7CSecurity%20Before%20Firewall%20Activation%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Security-Before-Firewall-Activation.htm?TocPath=Special%20Scenarios%20for%20Security%20Gateways%7CSecurity%20Before%20Firewall%20Activation%7C_____0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may (or may not) need to run the initial policy compiler first:&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Dark_Header_and_Pattern" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Dark_Header_and_Pattern-Body-White_Background"&gt;
&lt;TD class="TableStyle-TP_Table_Dark_Header_and_Pattern-BodyE-Column_Style-White_Background"&gt;
&lt;P&gt;&lt;CODE&gt;$FWDIR/bin/comp_init_policy [-g | -G]&lt;/CODE&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Dark_Header_and_Pattern-BodyD-Column_Style-White_Background"&gt;
&lt;P&gt;Creates the local state Initial Policy&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then load the policy manually:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;fw fetchlocal -d $FWDIR/state/local/FW1/&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;InitialPolicy loaded:&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[Expert@cpgw01:0]# fw stat
HOST      POLICY           DATE              
localhost InitialPolicy     7Mar2025  0:11:41 :  [&amp;gt;eth0] [&amp;lt;eth0]
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please test this on your own before trying on a production gateway, however! &amp;nbsp; After InitialPolicy is loaded, you can still SSH to the gateway and run various CPD management commands from SmartConsole (or wherever). &amp;nbsp;You can't ping the gateway, however.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to build your own custom default filter, review the documentation section:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Boot-Security.htm?tocpath=Special%20Scenarios%20for%20Security%20Gateways%7CSecurity%20Before%20Firewall%20Activation%7C_____1" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Boot-Security.htm?tocpath=Special%20Scenarios%20for%20Security%20Gateways%7CSecurity%20Before%20Firewall%20Activation%7C_____1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 05:19:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-install-InitialPolicy-after-use-fw-unloadlocal/m-p/243229#M47250</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-03-07T05:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: How install InitialPolicy after use fw unloadlocal</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-install-InitialPolicy-after-use-fw-unloadlocal/m-p/243242#M47254</link>
      <description>&lt;P&gt;If you haven't installed a different policy (after the uninstall) then just running &lt;STRONG&gt;fw fetch localhost&lt;/STRONG&gt; will fetch the Initial Policy.&lt;/P&gt;
&lt;P&gt;If you want to install / fetch Initial Policy when there is a different policy you will need compile it and perform additional steps&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 08:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-install-InitialPolicy-after-use-fw-unloadlocal/m-p/243242#M47254</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-03-07T08:48:10Z</dc:date>
    </item>
  </channel>
</rss>

