- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Security Manager Recovery
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Security Manager Recovery
I have two 3800 appliances running as cluster now. But the security manager server is completely crashed without any backup.
I am new to Check Point systems. Please advise how can I rebuild the server and retrieve the configuration from the firewall.
thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SW version?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the firewalls are R80.40
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If the SMS is crashed completely without a backup, the configuration is lost - you can not restore it from the compiled policy on the gateways.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I only have the admin password of the gateway. After build a new SMS, how can I modify the gateway to use the new server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've had a similar scenario. SMS harddrive crashed no backup. We engaged Checkpoint Professional services to extract the policies from the gateways and the import these into the a clean build SMS.
The have the tools to do this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, that is possible - but not a cheap solution,so i prefer backups 8).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree - but in our case with the customer we had little choice. I suspect it take 1 or 2hrs to do by Professional services but then charge the whole day.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Professional Services actually CAN do that now
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree,
We had to get PS involved to rebuild a manager and policy using the policy from the gateways!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there additional charge for this service from cp?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes - we specifically had to engage PS, which indeed cost.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You may be able to piece together the configuration from various files in $FWDIR/state.
However, it will be a manual process.
Check Point Professional Services can also assist with this.
However, if you want to start over, you can build a new management server and make a new configuration.
You will have to go to each gateway and use cpconfig to perform a SIC reset.
This will allow you to establish SIC from the new management server and push a new policy to the gateways.
Note that resetting SIC generally causes an outage.
