- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
over the years we had to change many values in the checkpoint database to special setting (url_filtering cache for example).
Is there a way to export or show all database entries where the value is not default?
Jan
It’s not clear exactly what settings you’re referring to here.
Defaults can also change from version to version in any case.
More details (including the specific settings you’re interested, possibly with screenshots, and versions involved) will help.
In general, any changes made through SmartConsole/API should show in the audit logs.
Changes made outside of this (Expert Mode) may not be reflected in logs.
Nothing that I’m aware of that will show you “differences from a default configuration.”
No there is not something out there. There are ways to verify specific changes. In GuiDBedit if you find the relevant object there is a column "last modify time'' this is an indication of a change. Also the column display current value and default value. That is the second indication.
For other changes set with fw ctl set I would recommend this sk: https://support.checkpoint.com/results/sk/sk33156
Creating a file with all the kernel parameters and their values
This will create a file with all important kernel parameters. As a reference you should get the same file from a similar default installed system (in a lab for example, same version / take)
I recommend always to keep track of custom changes like this. Check Point is a very open system, meaning you can change a lot. It is simply impossible to always be able to keep track what has been changed and what is different from factory default. Only way is solid documentation.
Thank you for your reply. I almost expected the answer. I was trying to figure out the changes made via dbedit over the last decades 🙂 We try to track all changes, but sometimes you change something in a remote session with TAC and miss documentation. That's why I had the hope that you can make a database diff or something like that. As you mentioned the default values are already in the database.
Thanks,
Jan
Recommending to use show objects API command.
https://sc1.checkpoint.com/documents/latest/APIs/index.html#cli/show-objects~v2%20
I used the following:
mgmt_cli -r true show objects type "application-site-group" details-level full
You can see creator/last modified.
By the way, you can also set up a simple "clean" Management Server and copy the relevant files from $FWDIR/conf/ to compare them with those from your Production Management Server using a file diff.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY