- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Boys,
Do you know if it is possible to obtain these policies to apply them to other backup equipment in stock?
I can't find information about where it is hosted.
[Expert@GW:0]# cpstat -f policy fw
Product name: Firewall
Policy name: Standard
I am looking for this so that I am not restarting the SIC again when a device fails or there is no technical equipment and it will only be changing cables, thank you very much!
Installing policy to a gateway generally requires SIC with management.
The currently installed policy is in $FWDIR/state (in its compiled form).
I'm fairly certain copying this directory from one system to another is NOT supported, especially across different hardware/software versions.
Note in R82, we will have the ability to configure a policy without management.
However, I believe even that requires establishing SIC with management first.
So you want a cold spare unit on the shelf?
If the hardware is the same as the unit it will replace you can use gaia snapshot:
Or backup, this is less complete backup and also needs policy push.
A firewall has way more config then only the policy. Putting only the policy on a box will not make it functional. So in general this is not a good idea.
Another option might be copy bits and pieces from show configuration, since I assume it would be different hardware, so interfaces wont match, but if its the same hardware, then it might be best option.
Andy
If I was referring to that, but I was also not sure if you could import the policy loaded from the firewall to other hardware with the same configurations, it is best to follow the recommendations of snapshots and backup to have the policies loaded on both computers in case one fails.
Just to make sure, are you trying to export one policy and then import it into another management server?
If so, then you need to follow below process.
https://support.checkpoint.com/results/sk/sk135172
Btw, its NOT just boys, lots of ladies here too, all very smart ones 🙂
Best,
Andy
I am referring to the policy loaded in the firewall:
[Expert@GW:0]# cpstat -f policy fw
Product name: Firewall
Policy name: Standard
Right, but Im still unclear on what exactly you are trying to do here. Are you tryng to export the policy, so it can be imported into another mgmt server or something totally different?
Andy
Installing policy to a gateway generally requires SIC with management.
The currently installed policy is in $FWDIR/state (in its compiled form).
I'm fairly certain copying this directory from one system to another is NOT supported, especially across different hardware/software versions.
Note in R82, we will have the ability to configure a policy without management.
However, I believe even that requires establishing SIC with management first.
If I was referring to that, but I was also not sure if you could import the policy loaded from the firewall to other hardware with the same configurations, it is best to follow the recommendations of snapshots and backup to have the policies loaded on both computers in case one fails.
So you want a cold spare unit on the shelf?
If the hardware is the same as the unit it will replace you can use gaia snapshot:
Or backup, this is less complete backup and also needs policy push.
A firewall has way more config then only the policy. Putting only the policy on a box will not make it functional. So in general this is not a good idea.
Another option might be copy bits and pieces from show configuration, since I assume it would be different hardware, so interfaces wont match, but if its the same hardware, then it might be best option.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 42 | |
| 21 | |
| 10 | |
| 8 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Thu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY