<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Export Firewall configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90145#M6896</link>
    <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;I am using 2 x CheckPoint 5600 Firewall in my workplace.&lt;BR /&gt;We are requested by our Internal Audit that we need to export and review the Firewall configuration periodically.&lt;BR /&gt;I am the only person here who hold the Firewall Administrator password, and I am not allow to share out the admin pwd.&lt;BR /&gt;&lt;BR /&gt;Can anyone guide me on how to create a READ ONLY account that can export the FireWall Configuration file?&lt;BR /&gt;&lt;BR /&gt;thank you very much.&lt;BR /&gt;---david&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2020 05:54:48 GMT</pubDate>
    <dc:creator>davidso</dc:creator>
    <dc:date>2020-06-30T05:54:48Z</dc:date>
    <item>
      <title>Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90145#M6896</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;I am using 2 x CheckPoint 5600 Firewall in my workplace.&lt;BR /&gt;We are requested by our Internal Audit that we need to export and review the Firewall configuration periodically.&lt;BR /&gt;I am the only person here who hold the Firewall Administrator password, and I am not allow to share out the admin pwd.&lt;BR /&gt;&lt;BR /&gt;Can anyone guide me on how to create a READ ONLY account that can export the FireWall Configuration file?&lt;BR /&gt;&lt;BR /&gt;thank you very much.&lt;BR /&gt;---david&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 05:54:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90145#M6896</guid>
      <dc:creator>davidso</dc:creator>
      <dc:date>2020-06-30T05:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90167#M6899</link>
      <description>&lt;P&gt;What kind of export? MGMT database? OS settings? Please elaborate&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 08:21:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90167#M6899</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-06-30T08:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90173#M6900</link>
      <description>&lt;P&gt;Only the OS settings.&amp;nbsp; thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 09:18:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90173#M6900</guid>
      <dc:creator>davidso</dc:creator>
      <dc:date>2020-06-30T09:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90174#M6901</link>
      <description>&lt;P&gt;according to some experts they mention something adding a RULE to allow these READ ONLY accounts to access SSH and the WEB interface that can serve the same purpose.&amp;nbsp; Can you please guide me through how to set this rule(s)?&amp;nbsp; Many Many thanks. --david&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 09:20:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90174#M6901</guid>
      <dc:creator>davidso</dc:creator>
      <dc:date>2020-06-30T09:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90175#M6902</link>
      <description>&lt;P&gt;You need to set up a new OS account and assign it to monitorOnly role&lt;BR /&gt;&lt;BR /&gt;Read the Gaia admin guide for more details.&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Gaia_AdminGuide/Content/Topics-GAG/Roles.htm?tocpath=User%20Management%7CRoles%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Gaia_AdminGuide/Content/Topics-GAG/Roles.htm?tocpath=User%20Management%7CRoles%7C_____0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 09:34:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90175#M6902</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-06-30T09:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90181#M6903</link>
      <description>&lt;P&gt;Hi _Val_, The two READ ONLY accounts that i mentioned were exactly in the MonitorRole.&amp;nbsp; But they seem do not have the privilege to export the configuration nor ssh-in.&amp;nbsp; thanks. --david&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 09:45:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90181#M6903</guid>
      <dc:creator>davidso</dc:creator>
      <dc:date>2020-06-30T09:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90193#M6905</link>
      <description>&lt;P&gt;Incorrect. You already have built-in monitor user in Gaia. Alternatively, create a new and assign monitorOnly role to it.&lt;BR /&gt;&lt;BR /&gt;This user (you will have to reset its password) is allowed to SSH, CLISH only. It can run "show..." commands. In this context, "show configuration" is what you are looking for.&lt;/P&gt;
&lt;P&gt;It will not "export" config out, but will allow auditors to see output of config as part of the ssh session. They can log the session and use the data.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do not want to give read-only users access to expert. If you are looking for a capability to send a file out, that is exactly the issue. Expert mode trumps all CLISH restrictions.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2020 12:33:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90193#M6905</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-06-30T12:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90293#M6908</link>
      <description>&lt;P&gt;thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 11:48:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90293#M6908</guid>
      <dc:creator>davidso</dc:creator>
      <dc:date>2020-07-01T11:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Export Firewall configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90309#M6909</link>
      <description>&lt;P&gt;you are welcome&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 11:49:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Export-Firewall-configuration/m-p/90309#M6909</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-07-01T11:49:04Z</dc:date>
    </item>
  </channel>
</rss>

