- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi,
I want to know if it's possible to retrieve the policy on a local gateway. When we do the fw stat, we can see the Policy name but I'm wondering "where" this policy is stored in local (if it's stored at all).
I've search a little bit here, but couldn't find the right answer.
My overall goal is to try and set let's say an "automated reboot" on a previous Policy from the gateway itself, I'm not sure if it's possible at all but I'm exploring options ;).
Thank you in advance for your help.
On a R80.x gateway the installed policy can be found within $FWDIR/state/local/FW1/
The rulebase for example is within $FWDIR/state/local/FW1/local.rule
To reach your goal of automatically booting a different policy I recommend doing backups of each policy and then automatically select the backup you want to boot from, restore it and reboot. Done.
Afaik a local copy should be located in $FWDIR/state/__tmp/FW1
to load local copy: fw fetchlocal -d $FWDIR/state/__tmp/FW1
The policy is stored in compiled form in $FWDIR/state in several files/directories. When you do an fw fetchlocal, it comes from this directory structure.
Note that only the current policy is stored here, not previous policies. The only supported way to change the policy loaded is to push a new one from the Security Management.
Thanks guys for the directory suggestions (and the other replies)
I found the cheat code.
cat $FWDIR/state/local/FW1/local.sic_name |grep 'o='|awk -F ,o= '{print $2}'|awk -F . '{print $NR}'
Background
cat local.sic_name
sic_name=cn=<fwname>,o=<domainname>..<CAthingy>
Excellent!
On a R80.x gateway the installed policy can be found within $FWDIR/state/local/FW1/
The rulebase for example is within $FWDIR/state/local/FW1/local.rule
To reach your goal of automatically booting a different policy I recommend doing backups of each policy and then automatically select the backup you want to boot from, restore it and reboot. Done.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY