<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manually modified files in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12315#M90572</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;To be totally in control you should document every change you’ve manually made to files, just like &lt;/SPAN&gt;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.checkpoint.com/people/cfe6e688-522c-305c-adaa-194bd7a7becc"&gt;Dameon Welch-Abernathy&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;already said. But unfortunatly you probably are not the only one working on that firewall.&lt;/SPAN&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;I was working on a script that allows you to copy a lot of known files that could have been changed. Afterwards you run it again to see if there are differences between the original files and the new ones.&lt;/P&gt;&lt;P class=""&gt;I might post it to Check Mates sometime. But best practice will be to just document it and “friendly” remind your colleagues that don’t .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Dec 2018 18:47:08 GMT</pubDate>
    <dc:creator>RickHoppe</dc:creator>
    <dc:date>2018-12-08T18:47:08Z</dc:date>
    <item>
      <title>Manually modified files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12312#M90569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #212121; background-color: #ffffff; font-size: 16px;"&gt;If I remember correctly, there was a SK with all the files that should be manually backup&amp;nbsp;in case of upgrades as they would have been overwritten during the upgrade or export / import procedura on a new management, but I'm not able to find it anymore.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #212121; background-color: #ffffff; font-size: 16px;"&gt;For example I mean crypt.def, user.def,&amp;nbsp;implied_rule.def, table.def etc etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #212121; background-color: #ffffff; font-size: 16px;"&gt;Someone remember this sk or some link with the information above?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #212121; background-color: #ffffff; font-size: 16px;"&gt;Danilo&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 08:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12312#M90569</guid>
      <dc:creator>Danilo_Molini</dc:creator>
      <dc:date>2018-12-04T08:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Manually modified files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12313#M90570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I'd do is look at the output of ls -lrt $FWDIR/lib/*.def.&lt;/P&gt;&lt;P&gt;A whole bunch of the files will have similar date/timestamps.&lt;/P&gt;&lt;P&gt;The ones at the bottom of that list&amp;nbsp;&lt;EM&gt;may&lt;/EM&gt; have been modified and may be worth backing up.&lt;/P&gt;&lt;P&gt;If you manage gateways of an earlier version, you may have modified .def files in various backward compatibility packages also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On gateways, a commonly modified file is&amp;nbsp;$FWDIR/boot/modules/fwkern.conf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In general, anytime you manually modify one of these files, you should document it for future use.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 23:43:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12313#M90570</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-07T23:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Manually modified files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12314#M90571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I always save original file as copy with some ending like .orig or .bak and by looking for those files I know I have altered the original one and can even do a diff to see my changes.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Dec 2018 18:06:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12314#M90571</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2018-12-08T18:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Manually modified files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12315#M90572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;To be totally in control you should document every change you’ve manually made to files, just like &lt;/SPAN&gt;&lt;A _jive_internal="true" class="jive-link-profile-small jive_macro jive_macro_user" href="https://community.checkpoint.com/people/cfe6e688-522c-305c-adaa-194bd7a7becc"&gt;Dameon Welch-Abernathy&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;already said. But unfortunatly you probably are not the only one working on that firewall.&lt;/SPAN&gt;&lt;P class=""&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;I was working on a script that allows you to copy a lot of known files that could have been changed. Afterwards you run it again to see if there are differences between the original files and the new ones.&lt;/P&gt;&lt;P class=""&gt;I might post it to Check Mates sometime. But best practice will be to just document it and “friendly” remind your colleagues that don’t .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Dec 2018 18:47:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/12315#M90572</guid>
      <dc:creator>RickHoppe</dc:creator>
      <dc:date>2018-12-08T18:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Manually modified files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/54749#M90573</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7384"&gt;@RickHoppe&lt;/a&gt;&amp;nbsp;any chance you have this script? I just realized in a migration that I'm doing someone has customized several of the different table.def files residing on MDS, and I'll need to move/inspect all 56 instances of them.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2019 16:22:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/54749#M90573</guid>
      <dc:creator>xman03</dc:creator>
      <dc:date>2019-05-30T16:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Manually modified files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/54778#M90574</link>
      <description>&lt;P&gt;Unfortunately I haven’t been able to work on that script for a long time. I wasn’t expecting that when I posted a reply on this topic. The script is not ready for publishing and at this time it is merely focussed on Security Gateways.&lt;/P&gt;&lt;P&gt;Please take&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98339&amp;amp;partition=Advanced&amp;amp;product=Security" target="_self"&gt;sk98339&lt;/A&gt; in mind when migrating MDS to a new version as the location of your table.def files might change.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also have a look at&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98239&amp;amp;partition=Advanced&amp;amp;product=Security" target="_self"&gt;sk98239&lt;/A&gt; for the naming convention of user.def when migrating MDS to a new version as this might change too.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In case you are migrating to R80.30 &amp;nbsp;both SK’s are not updated for R80.30 yet. I’ve submitted feedback on those SK’s for updating them to include R80.30 instructions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 05:01:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/54778#M90574</guid>
      <dc:creator>RickHoppe</dc:creator>
      <dc:date>2019-05-31T05:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Manually modified files</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/54828#M90575</link>
      <description>&lt;P&gt;Gotcha, figured it was worth asking&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&amp;nbsp;For my instance I ended up using a find command and piping it to tar to keep the structure intact, so I'll be able to simply untar on the new box after the migrate export/import. Thanks anyways!&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 20:40:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manually-modified-files/m-p/54828#M90575</guid>
      <dc:creator>xman03</dc:creator>
      <dc:date>2019-05-31T20:40:55Z</dc:date>
    </item>
  </channel>
</rss>

