Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SecdetKrypton
Explorer

"Command to check which policy set is installed on a Gateway or cluster."

I want to know the command to check which policy set is installed on a gateway and how to revert the incorrect policy installation on the wrong gateway.

0 Kudos
4 Replies
the_rock
Legend
Legend

https://sc1.checkpoint.com/documents/latest/APIs/?#cli/install-policy~v2%20

If you have expert mode, just run fw stat to see which policy is currently installed, or if threat prevention is also active, then fw stat -b AMW. To revert, if you have access to smart console, you can install it from there, but if not, then you need to use mgmt_cli

Andy

0 Kudos
AkosBakos
Leader Leader
Leader

Hi,

Totally agree with @the_rock, but if you not a CLI expert, just learn this command: cpview

2025-02-18 09_24_32-admin@gw-sakos-lab01_~.png

 

----------------
\m/_(>_<)_\m/
0 Kudos
Timothy_Hall
Legend Legend
Legend

Normally you would reinstall the correct policy to the gateway from the SmartConsole as the_rock said.  However if you can't do that for some reason, starting in R81.20 Jumbo 54+ and R82 the gateway itself will cache the last two policies installed prior to the current one.  These can be reinstalled right from the gateway itself using policy_rev_toolsk181437: Access Control Policy Revert Tool (policy_rev_tool)

This is one of the tips in my upcoming CPX Vegas presentation.

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
0 Kudos
Lesley
Mentor Mentor
Mentor

Only thing i would like to add, if for some reason you cannot re-install the correct policy. You might need to run:

fw unloadlocal

Description

Uninstalls all policies from the Security Gateway or Cluster Member.

Lesley_0-1739914292399.png

 

Warning:

  1. The "fw unloadlocal" command prevents all traffic from passing through the Security Gateway (Cluster Member), because it disables the IP Forwarding in the Linux kernel on the Security Gateway (Cluster Member).

  2. The "fw unloadlocal" command removes all policies from the Security Gateway (Cluster Member). This means that the Security Gateway (Cluster Member) accepts all incoming connections destined to all active interfaces without any filtering or protection enabled.

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events