- CheckMates
- :
- Products
- :
- General Topics
- :
- rulebase / policy export from enforcement gateway
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rulebase / policy export from enforcement gateway
Hi there,
Couldn't find anything similar, so here it goes.
I need to integrate Checkpoint firewalls into an existing scripted solution. The requirement is to export the entire policy / rulebase / object definitions in human or machine readable form. But there's a catch. I only have access to the gateways and not to the management server. Any ideas? Version is R77.30.
Thanks,
Eli
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is stored on the gateways is in compiled form in $FWDIR/state/local/FW1.
We do not have a documented process or tools outside of Professional Services to recover the data from these directories.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What about file is $FWDIR/database directory? They sort of look like my policy?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There's an SK that talks about clearing both directories in case of some corruption: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Between $FWDIR/database and $FWDIR/state/local/FW1, you may be able to recover what you need.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
either way, you cannot convert compiled policies into human readable form without very hard effort. get access to the management station for that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@ekagan you write:
CUT>>>
I only have access to the gateways and not to the management server. Any ideas?
<<<CUT
Why don't you have access to management? Is it a password problem or is the server damaged?
If it is a password problem you can reset the GAIA password and then set a new console password with "cpconfig".
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
