- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
I have an issue where the physical appliance that ran our check point management crashed spectacularly. Of course the backup has never been tested and seems to be corrupt.
We've managed to restore the objects, but are not able to restore the policy. We have recovered the rulebases_5_0.fws file, but not anything else from the management itself.
My question is - the security gateways are still up and running, is there in some way possible to recover the installed policy on a gateway or exctract it in a readable format so that we could've reconstructed it manually.
The gateways are running r77.30.
Thanks!
Br
There is a way with versions up to R77.xx - unsupported procedure attached 8)
Not that I know of unfortunately. You can try running the rulebases_5_0.fws through something like Nipper to get a policy printout.
Just a thought - if you have access to the filesystem are there perhaps backups under /var/log/CPbackup/backups/
I've also had success moving hard drives between appliances.
See also View rulebase when only CLI available
Thanks so much for your contribution! We've tried this now and got some progress, I will update you when I know the final result.
Nice to see that SK still kicking around! It's probably the most enduring single piece of documentation I've written.
Just be aware the part about removing certificates can be pretty dangerous. More than once, someone left an extra close paren in place, and when they started the management again, it hosed the objects file. If you use this process, be absolutely sure you have extra copies of all the files, including some on at least one other machine.
Which SK was it ? I just have the procedure, file dated 2013...
It's sk32508. I eventually got fast enough that I could get somebody an upgrade_export less than 30 minutes after getting those files from a dead management.
Of course, now everything is in a PostgreSQL database rather than text files. I left the TAC before R80 was even announced outside R&D, so I never figured out an equivalent process for it.
Hey,
I've tried the procedure, but the firewall blade is not coming up. I have different versions of the files, do you know which files that contain the firewall blade?
Got to open the firwall blade and the ruleset is empty. Any suggestions?
Just tested with some other files and seems like that worked. thanks so much!
I was just about to send you same process @G_W_Albrecht attached. But yes, he is correct, definitely not supported, but your best bet.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
24 | |
15 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY