<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80+ Change Control: A Visual Guide in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39709#M98528</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the "panic button" as described by Tim (install a previous revision on the gateway) satisfy&amp;nbsp;the case that you described - overcoming VSX misconfiguration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I would like to thank &lt;A href="https://community.checkpoint.com/migrated-users/41625"&gt;Tim Hall&lt;/A&gt;‌ for centralizing all these&amp;nbsp;features in one visual guide &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jan 2018 12:44:56 GMT</pubDate>
    <dc:creator>Tomer_Sole</dc:creator>
    <dc:date>2018-01-16T12:44:56Z</dc:date>
    <item>
      <title>R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39702#M98521</link>
      <description>&lt;P&gt;As mentioned in the article &lt;A href="https://community.checkpoint.com/thread/6601" target="_blank" rel="noopener"&gt;Revisions Management in R80.x&lt;/A&gt;, I do have an informal writeup I use when teaching CCSA R80.10 that helps summarize how R80+ Change Control and Revisions are handled for the inevitable questions that arise in class.&amp;nbsp; This document is a sprucing up of those notes complete with some new screenshots.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Absolutely no way this document would have been possible without the incredible contributions of &lt;A href="https://community.checkpoint.com/migrated-users/6703" target="_blank" rel="noopener"&gt;Tomer Sole&lt;/A&gt; and in particular these articles with content contributed by him:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/5098" target="_blank" rel="noopener"&gt;How to revert a Policy or discard changes?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/6601" target="_blank" rel="noopener"&gt;Revisions Management in R80.x&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/1262" target="_blank" rel="noopener"&gt;How do you rollback an old policy?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What follows is merely a roll-up of Tomer's content from an operational perspective, with some new screenshots I have put together.&amp;nbsp; I hope you find it useful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;Preface: Install the "Change Report" SmartConsole Extension (R80.30+)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Back in R77.30, there was an SMS feature called "SmartWorkflow".&amp;nbsp; One of the more useful elements of this feature was a "Change Report" which could clearly and succinctly show the object and policy differences between different sessions.&amp;nbsp; Based on feedback from the CheckMates User Community, the Change Report functionality is back in R80.30+,&amp;nbsp; but in the form of a SmartConsole Extension.&amp;nbsp; In other words this feature is NOT available by default in R80.30 and later, and you must manually add it to your R80.30+ SMS in order to use it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Trust me: You want to install this Change Report functionality if you have R80.30 or later (but it is not supported on a standalone SMS/gateway combination); the instructions to do so are here:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/Show-changes-from-session-gt-from-a-single-session/m-p/80570#M4670" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/Show-changes-from-session-gt-from-a-single-session/m-p/80570#M4670&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166435&amp;amp;partition=Advanced&amp;amp;product=SmartConsole" target="_blank"&gt;sk166435: How to view changes performed between revisions&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Once this extension has been successfully installed a new button called "Changes" shows up on a variety of different SmartConsole screens.&amp;nbsp; Clicking it presents a popup window that looks like the following; the next three screenshots are scrolled through a single Change Report and its results:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="changes1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5622iFC298437194A6418/image-size/large?v=v2&amp;amp;px=999" role="button" title="changes1.png" alt="changes1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="changes2.png" style="width: 933px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5623i2E6BFF49E267486E/image-size/large?v=v2&amp;amp;px=999" role="button" title="changes2.png" alt="changes2.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="changes3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5624i2727D311C3F4DA6F/image-size/large?v=v2&amp;amp;px=999" role="button" title="changes3.png" alt="changes3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The new "Changes" button will also appear in many more places other than the Security Policy layers screen as shown above, particularly on screens where Audit Logs can be potentially viewed.&amp;nbsp; A sampling:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="changes4.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5625iB409335CC03A4C39/image-size/large?v=v2&amp;amp;px=999" role="button" title="changes4.png" alt="changes4.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="changes5.png" style="width: 996px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5626i8D54FE1B3468BBAB/image-size/large?v=v2&amp;amp;px=999" role="button" title="changes5.png" alt="changes5.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="5" color="#FF0000"&gt;&lt;EM&gt;&lt;STRONG&gt;Note: The "Changes" button will not be shown in any of the subsequent screenshots in this article or mentioned again.&amp;nbsp; It is up to YOU to keep an eye open for the "Changes" button that will appear on various screens and take advantage of it, assuming you have installed this very useful SmartConsole Extension.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;Part 1: What are you about to do?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;You are in the process of making changes in the SmartConsole and are unsure (or have lost track of) what you have done due to one of your coworkers constantly interrupting you.&amp;nbsp; If still in an unpublished session, you can see what changes are pending by enabling the Session Pane (only available in R80.10+ management) like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="width: 620px; height: 603px;" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62080_todo0.png" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will create a new pane on the far right of the SmartConsole where you can see pending unpublished changes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="height: auto;" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62090_todo01.png" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This information can be very helpful when deciding to publish or discard a session.&amp;nbsp; Another way to find pending unpublished rule changes in your current session is to look for "Edited" Access Control rules, indicated by default using a purple line in the Smart Scrollbar:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="width: 620px; height: 171px;" class="image-16 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64408_scrollbar.jpg" border="0" alt="Smart Scrollbar changes" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that the colored lines in the Smart Scrollbar will also by default show rule locks currently held by other administrators (dark grey) and search results (yellow) by default.&amp;nbsp; You can even make section titles (light grey) and a selected/highlighted rule (blue) show up as well:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="height: auto;" class="image-17 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64427_scrollbar2.jpg" border="0" alt="Smart Scrollbar options" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information about the Smart Scrollbar and some other great tips for efficiently navigating a large rulebase in the SmartConsole, see this post:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/message/1305?sr=search&amp;amp;searchId=f6f1dbf5-b33b-4713-a30a-9cd67f8fd959&amp;amp;searchIndex=0" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;What are some of the tips and tricks for jumping between rules in the rulebase?&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you have now published your session and think you are ready to install policy to the gateway.&amp;nbsp; A very good habit to get into prior to installation is looking at how many changes you are about to make:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="width: 620px; height: 386px;" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62091_todo1.jpg" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Along the top of the screen, you should ALWAYS look at how many sessions and by how many administrators will be part of what you are about to deploy on the gateway.&amp;nbsp; Note that this is the total number of changes made in the &lt;EM&gt;SMS config&lt;/EM&gt; since policy was last installed to this particular gateway, and not every change counted here is necessarily part of this gateway's security configuration or will impact how it operates.&amp;nbsp; If you see sessions and changes that are unfamiliar or unexpected though, it is a very good idea to hit the &lt;STRONG&gt;View Changes&lt;/STRONG&gt; button to see exactly what will be included:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="width: 620px; height: 372px;" class="image-4 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62092_todo3.png" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Along the top of the screen is a summary of all the different published sessions whose changes will be included if you install policy to the gateway.&amp;nbsp; As shown above you can highlight one of those sessions, and then select the &lt;STRONG&gt;Audit Logs&lt;/STRONG&gt; tab to see a very detailed list of exactly what changes were made in that particular highlighted session.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let's assume that everything looks OK and you proceed to install policy to the gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;Part 2: The Panic Button&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Your phone is ringing nonstop, people are pounding on your door, and it has all gone horribly wrong!&amp;nbsp; Some very bad change got implemented when you pushed policy to the gateway at the end of the last section and it is impacting production traffic.&amp;nbsp; You need to fix what you did RIGHT NOW.&amp;nbsp; Thankfully the &lt;STRONG&gt;Installation History&lt;/STRONG&gt; screen will be your savior in this case:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 445px;" class="image-5 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62094_panic1.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;The first &lt;STRONG&gt;Installation Date&lt;/STRONG&gt; shown above (1/15/2018) represents the most recent policy push (which is probably what messed everything up), just highlight one of the older installations below it, then click &lt;STRONG&gt;Install Specific Version&lt;/STRONG&gt; like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 384px;" class="image-6 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62095_panic2.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;When you hit &lt;STRONG&gt;Install&lt;/STRONG&gt;, a previously installed known-good copy of the firewall policy will be installed and hopefully undo whatever bad change was installed to the gateway.&amp;nbsp; &lt;EM&gt;Note that doing this does not change any configurations shown to you in the SmartConsole&lt;/EM&gt;, &lt;EM&gt;it ONLY changes what is installed on the gateway back to a good config that was previously installed&lt;/EM&gt;.&amp;nbsp; If you hit the &lt;STRONG&gt;Install Specific Version&lt;/STRONG&gt; "panic button", install the older policy to the gateway, then reinstall the current security policy again, you will be right back in the "panic" situation again!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;So hopefully you have been able to halt the endless door pounding and phone ringing by hitting the "panic" button as shown.&amp;nbsp; You have bought yourself some time to now figure what boneheaded change was made by one of your coworkers (or you!) that caused this unfortunate situation to occur.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;Part 3: The Investigation&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;While the &lt;STRONG&gt;Installation History&lt;/STRONG&gt; screen is typically associated with "panic" reverts of gateway policies as shown in the last section, the &lt;STRONG&gt;View Installed Changes&lt;/STRONG&gt; button on that same screen can be very handy for examining the specific changes in a suspect revision that came after the one you reverted to in the prior section:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 398px;" class="image-7 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62096_inv0.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;To see even more information about a certain session, hit the View button which will bring up a read-only copy of the SmartConsole showing the exact state of the configuration &lt;EM&gt;after&lt;/EM&gt; that particular highlighted session was published:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 375px;" class="image-8 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62097_inv2.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;By this time you may have some suspicions that a certain policy layer and its rules may have been changed in a way that caused the "panic" situation to occur.&amp;nbsp; If so select the policy layer in question, then select &lt;STRONG&gt;Actions&lt;/STRONG&gt;...&lt;STRONG&gt;History&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 385px;" class="image-10 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62099_inv5.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 380px;" class="image-11 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62100_inv6.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;A nice concise list of all changes made in that policy layer in the various sessions is presented.&amp;nbsp; If you want to see the history of only a specific rule that you suspect is the culprit, simply highlight the rule and click its &lt;STRONG&gt;History&lt;/STRONG&gt; tab:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 233px;" class="image-9 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62098_inv4.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;You can also view all changes on the screen below if you aren't sure exactly where to look:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 285px;" class="image-12 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62101_inv7.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Suppose you have now identified a specific policy layer that was messed with and caused the panic situation to occur.&amp;nbsp; If there were a multitude of changes made and you don't want to manually back all of them out, you can &lt;STRONG&gt;Revert&lt;/STRONG&gt; the policy layer configuration back to a specific point in time, thus discarding the changes made in one or more revisions like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 359px;" class="image-13 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62102_revert2.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;In our example above we will be removing (or undo'ing) a total of 5 changes made in the two published sessions just above the one we selected.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;Part 4: Your Final Log Analysis Option&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;If you still can't determine what changes caused the problem, your last ditch effort is to look at the raw system-wide Audit logs like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 483px;" class="image-14 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62103_inv8.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;IMG style="width: 620px; height: 402px;" class="image-15 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62104_inv9.png" border="0" alt="" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;This technique was also possible in R77.30 with the&lt;STRONG&gt; Audit/Management&lt;/STRONG&gt; tab of the SmartView Tracker.&amp;nbsp; The SmartWorkflow product also has some nice change reports in that version.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;SPAN style="font-size: 22px;"&gt;&lt;STRONG&gt;Part 5: Your Last Resort..."Revert to this Revision" (R80.40+ Only)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;PLEASE READ THIS SECTION IN ITS ENTIRETY BEFORE INVOKING THIS FEATURE.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;The "Revert" option covered in Part 3 has a glaring limitation: While it can certainly revert changes made to a particular policy layer as shown, it DOES NOT revert any changes to object properties that also might have been made in association with those policy layer changes, nor does it revert any other properties changes of any type either including Global Properties, Policy Layer properties or Threat Prevention properties, to name a few.&amp;nbsp; Therefore once you have reverted the policy layer as shown part 3, if the underlying problem is that the properties of some kind of object were tampered with, the Revert operation will not change the object properties back and the problem will still be present.&lt;/P&gt;
&lt;P&gt;Enter the new "Revert to this Revision" feature introduced in R80.40, added by Check Point in response to various concerns expressed by the CheckMates User Community.&amp;nbsp; Note that all this feature requires for use is a R80.40+ SMS or MDS, it DOES NOT require R80.40 on the security gateways themselves for use.&amp;nbsp; On an R77.30 and earlier SMS it was possible to "Restore a Database Revision"&amp;nbsp; and essentially revert all elements of the Check Point configuration (objects, policies, settings) back to a known good point in time.&amp;nbsp; Any changes made since the restored revision was originally taken were GONE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is exactly what the "Revert to this Revision" feature does in R80.40+.&amp;nbsp; You can essentially choose a published session that had known-good changes in it, and revert to it, which will completely remove all changes since that selected revision was published which includes all object, policy, and properties changes.&amp;nbsp; All changes made after the reverted session are GONE, just like they were after restoring a revision in R77.30.&amp;nbsp; Note that all the changes in the selected published revision are preserved after the&amp;nbsp;"Revert to this Revision", so normally you'll want to select that known-good revision when invoking this operation.&lt;/P&gt;
&lt;P&gt;A few cautions before use:&lt;/P&gt;
&lt;P&gt;1) Once completed, a "Revert to this Revision" is &lt;FONT color="#FF0000"&gt;permanent&lt;/FONT&gt; and &lt;FONT color="#FF0000"&gt;cannot be undone&lt;/FONT&gt;.&amp;nbsp; If considering use of the "Revert to this Revision" feature, it is &lt;FONT color="#FF0000"&gt;strongly recommended&lt;/FONT&gt; to take a backup of the SMS and &lt;FONT color="#FF0000"&gt;verify the backup is good&lt;/FONT&gt;&amp;nbsp;before proceeding.&amp;nbsp; This can be easily accomplished from the Gaia web interface of the SMS, and the resulting backup file can be downloaded directly to your desktop for safekeeping.&amp;nbsp; All SmartConsole administrators will need to exit the SmartConsole to ensure the backup is successfully run. Once downloaded, make sure the backup *tgz file can be successfully opened by tools such as &lt;STRONG&gt;7-Zip&lt;/STRONG&gt; before proceeding.&lt;/P&gt;
&lt;P&gt;2) This feature should only be used as a last resort; if you have skipped to this section without reading all of this document I'd strongly recommend you STOP and read this whole document in its entirety first.&amp;nbsp; It is highly likely that the techniques documented earlier will be able to meet your needs without having to resort to the "big gun" of&amp;nbsp;"Revert to this Revision".&lt;/P&gt;
&lt;P&gt;OK so let's suppose that we have made 11 changes in a session that are causing major problems once installed to a gateway; you can see them summarized on the Revisions screen which we have seen earlier:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Risky_changes.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5198i2330A043D3D6213D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Risky_changes.jpg" alt="Risky_changes.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But what were all those 11 changes exactly?&amp;nbsp; Let's take a look:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="globalprops.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5199i6D9D2078614B1811/image-size/large?v=v2&amp;amp;px=999" role="button" title="globalprops.jpg" alt="globalprops.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="networks.jpg" style="width: 904px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5200i4473689154866684/image-size/large?v=v2&amp;amp;px=999" role="button" title="networks.jpg" alt="networks.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="allnew_policy.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5201iCD85FB80862AABEE/image-size/large?v=v2&amp;amp;px=999" role="button" title="allnew_policy.jpg" alt="allnew_policy.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Se we can see a smattering of object, policy, and global properties changes representing every part of our configuration.&amp;nbsp; These "bad" changes comprise the 11 changes shown in the first screenshot.&amp;nbsp; Now we want to essentially undo everything (and we mean EVERYTHING) in that session.&amp;nbsp; So we choose the next-oldest known-good published session (17 changes in our example) and pick "Revert to this Revision" like this (note that you must be using R80.40+ on your SMS to see this option):&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rvert_to.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5202i1F60CC16DD54B6E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="rvert_to.jpg" alt="rvert_to.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Screen 1 of the Revert operation appears.&amp;nbsp; READ IT ALL BEFORE PROCEEDING by clicking Next:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rvert1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5203i2D2815C6A3C90C43/image-size/large?v=v2&amp;amp;px=999" role="button" title="rvert1.jpg" alt="rvert1.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Screen 2, which performs a verification of your current configuration's eligibility to be reverted, if this fails DO NOT PROCEED and contact TAC for assistance if you still need to Revert.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="revert2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5204i13C8A75587C7CD6A/image-size/large?v=v2&amp;amp;px=999" role="button" title="revert2.jpg" alt="revert2.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Screen 3, final confirmation:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="revert3.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5205iCEE1FF99EDFD5899/image-size/large?v=v2&amp;amp;px=999" role="button" title="revert3.jpg" alt="revert3.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Screen 4, Revert operation complete, you will next be prompted to restart the SmartConsole:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="revert_final.jpg" style="width: 705px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5206iAA9704FF00A799DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="revert_final.jpg" alt="revert_final.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="restart.jpg" style="width: 708px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5207iA3FC5FEA6CB3FADA/image-size/large?v=v2&amp;amp;px=999" role="button" title="restart.jpg" alt="restart.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;After logging back into the SmartConsole, we can see that all changes made in that 11-change published session are gone:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gone.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5208iB5B0BC7546D3057D/image-size/large?v=v2&amp;amp;px=999" role="button" title="gone.jpg" alt="gone.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gone2.jpg" style="width: 701px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5209i166F58ACD968C754/image-size/large?v=v2&amp;amp;px=999" role="button" title="gone2.jpg" alt="gone2.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;And that concludes our use of the "Revert to this Revision" feature, introduced in R80.40 but should only be used as a LAST RESORT.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Hopefully you found this writeup useful, please let me know if you have any other change control techniques that were missed and I'll be happy to add them.&amp;nbsp; Thanks again to &lt;A href="https://community.checkpoint.com/migrated-users/6703" target="_blank" rel="noopener"&gt;Tomer Sole&lt;/A&gt;‌!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 23:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39702#M98521</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-08T23:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39703#M98522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tim! I would be very interested to hear about VSX and revision control. Is it really all "under control" now with R80.x when you have VSes stretching across multiple CMAs? All routing and spoofing updates and object changes considered? Ability to roll back to revisions as far as 2000+?&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2018 21:47:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39703#M98522</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-15T21:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39704#M98523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;VSX is not really in my area of expertise, &lt;A href="https://community.checkpoint.com/migrated-users/6703"&gt;Tomer Sole&lt;/A&gt; should be able to weigh in though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A class="" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Jan 2018 21:59:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39704#M98523</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-01-15T21:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39705#M98524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm very interested as well about the status of MDSM with VSX regarding R80.x revision control.&lt;/P&gt;&lt;P&gt;This is where it is really important to function properly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 07:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39705#M98524</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-01-16T07:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39706#M98525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm really concerned as our MDS had 3000 odd revisions available over 9 months period - would it really work on VSX to roll back to version 1 (the earliest) considering that there has been number of interface and routing changes on top of regular rules. If not, what's the point having 3000 revisions and making code more complex and chewing resources that could be utilised for better purpose? I really think that one should be able to turn it off completely. There are other tools available to achieve the same result (i.e. Tufin)&lt;/P&gt;&lt;P&gt;Since management is becoming noticeably resource hungry all these little things start to add up and decrease user experience &amp;nbsp;- soon we will need management server performance optimisation book Tim - I only take 10% for the idea &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 07:35:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39706#M98525</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-16T07:35:15Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39707#M98526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tim,&lt;/P&gt;&lt;P&gt;This is really nice &amp;amp; Informative document.&lt;/P&gt;&lt;P&gt;I just want to know that when we click on History option, How many entry it will show. Means what is the limit of that we can get back to earlier config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 10:42:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39707#M98526</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-01-16T10:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39708#M98527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we had 1500+ revisions available on a busy CMA. That's since the first upgrade to R80 back in March 2017. If you discard VSX concerns then I guess you should be able to go back all the way. Theoretically &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 11:20:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39708#M98527</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-16T11:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39709#M98528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the "panic button" as described by Tim (install a previous revision on the gateway) satisfy&amp;nbsp;the case that you described - overcoming VSX misconfiguration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I would like to thank &lt;A href="https://community.checkpoint.com/migrated-users/41625"&gt;Tim Hall&lt;/A&gt;‌ for centralizing all these&amp;nbsp;features in one visual guide &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 12:44:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39709#M98528</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-01-16T12:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39710#M98529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guarav,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will show history back to when the SMS was first loaded/upgraded, unless you have purged prior sessions from the Manage &amp;amp; Settings...Revisions screen.&amp;nbsp; Note that purging revisions doesn't appear to actually free up any disk space on the SMS as shown by the &lt;STRONG&gt;df&lt;/STRONG&gt; command, but presumably makes more storage space within the configuration database available.&amp;nbsp; Also just to be clear doing a purge does not roll back or undo changes in the purged sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 13:01:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39710#M98529</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-01-16T13:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39711#M98530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok Great.&lt;/P&gt;&lt;P&gt;If this is the case then at some point of time we need to free up the space. I which directory it stores History/ Revision database.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 14:35:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39711#M98530</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-01-16T14:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39712#M98531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gaurav, revisions are not stored in "directories" anymore. The new R80 backend uses native lightweight revisions based on the diff. Purge is available from the GUI. See&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/6312"&gt;How can I control the size of my R80.10 Security Management Server?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 14:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39712#M98531</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-01-16T14:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39713#M98532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They are stored now everywhere and nowhere &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113615" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113615"&gt;Revisions Management in R80.x&lt;/A&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;Revisions are now built-in in the database, describing different baselines of the database state.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please take a look at other threads here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/6601"&gt;Revisions Management in R80.x&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/6312"&gt;How can I control the size of my R80.10 Security Management Server?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;The revisions themselves are very light and only contain the delta diff (this is unlike pre-R80 Management servers where a revision was a zipped copy of the entire configuration). Either way, you can always open the Revisions view and &lt;STRONG&gt;purge&lt;/STRONG&gt; older revisions.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;In order to avoid an ever-growing database size, R80.10 Jumbo Hotfix take 42 and above introduces automatic IPS purge which deletes revisions older than 30 days. In R80.10 Jumbo Hotfix take 42 and above this purge happens automatically every 7 days.&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 14:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39713#M98532</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-01-16T14:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39714#M98533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bravo, Tim!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 23:23:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39714#M98533</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-16T23:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39715#M98534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dirk! Not really applicable to this topic about revisions &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;but I would use API script (or dbedit but that will be much slower) - we recently were faced with a similar issue so I just wrote an API script that created a group containing all IPs/subnets on the list. Depending on your environment (R80? SmartCentre Server or MDS/which CMAs, format of the list) could provide more advise.&lt;/P&gt;&lt;P&gt;Don't know but maybe &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;https://community.checkpoint.com/people/dwelccfe6e688-522c-305c-adaa-194bd7a7becc&lt;/A&gt;&amp;nbsp;can move this question to a new thread?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jan 2018 11:05:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39715#M98534</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-18T11:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39716#M98535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had a student point out that the Smart Scrollbar in the R80+ SmartConsole can also be used to locate pending unpublished changes, I added some text and screenshots documenting this technique.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2018 13:52:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39716#M98535</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-04-09T13:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39717#M98536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah this is&amp;nbsp;kind of a hidden feature, we really should publish this more&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/1171"&gt;What are some of the tips and tricks for jumping between rules in the rulebase?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;See more features that&amp;nbsp;maybe should get their shine&amp;nbsp;&lt;A __default_attr="1052" __jive_macro_name="polls" _jive_internal="true" class="jive_macro_polls jive_macro link-titled" href="https://community.checkpoint.com/polls/1052-what-is-your-favorite-hidden-feature-in-r8010"&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2018 16:42:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39717#M98536</guid>
      <dc:creator>Tomer_Sole</dc:creator>
      <dc:date>2018-04-09T16:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39718#M98537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Haha didn't know it was "hidden" - had to check my presentation i did to my troops back in March 2017.. it was already there! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 06:10:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39718#M98537</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-04-10T06:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39719#M98538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Come and check out our alpha version of 'Change&amp;nbsp;Report' supported by &lt;A href="https://community.checkpoint.com/docs/DOC-3472"&gt;SmartConsole Extensions&lt;/A&gt;&amp;nbsp;in CPX 2019&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78002_change-report.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2019 05:56:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39719#M98538</guid>
      <dc:creator>Ron_Izraeli</dc:creator>
      <dc:date>2019-01-29T05:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39720#M98539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there a way( like SmartDashboard) to revert all object changes&amp;nbsp; in one step&amp;nbsp; ??? similar to revert an old database revision. ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if so, I'll thanks to all for your help .&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2019 19:40:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39720#M98539</guid>
      <dc:creator>Fernando_Hagels</dc:creator>
      <dc:date>2019-02-23T19:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: R80+ Change Control: A Visual Guide</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39721#M98540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can revert what was installed on a gateway in one step (the compiled policy) — Step 2 of the root post in this thread.&lt;/P&gt;&lt;P&gt;Reverting the whole database in one step like a R77.30 Database Revision? Not currently possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Feb 2019 00:50:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-Change-Control-A-Visual-Guide/m-p/39721#M98540</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-24T00:50:27Z</dc:date>
    </item>
  </channel>
</rss>

