- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
If someone makes a policy change, then cant push policy.
And you go to policies/installation history and push the last known good policy - and it works!
The policy that exists on the management server is still the bad one right?
How do you revert the one on the management server to the last known good version? Do you need to do a database revision under manage&settings/Sessions/Revisions?
This would blatt all the objects created since that revision right?
In some cases we have customers with hundreds of gateways and multiple admins making concurrent changes all the time - a db revision is not feasible to fix one smb.
I found this SK to revert to the version on the gateway which is interesting - but again - this would make the policy on the mgmt server out of sync right? At least you can see the current revision number with this tool but how to correlate that to the mgmt server? The revision number isnt listed under revisions or installation history (as far as I can see);
sk181437 - Access Control Policy Revert Tool (policy_rev_tool)
[Expert@GW1:0]# policy_rev_tool list
Revision ID Policy Date Policy Name
----------- ----------- -----------
1760977277 Mon Oct 20 17:21:17 BST 2025 all_gateways_policy
1760977421 Mon Oct 20 17:23:41 BST 2025 all_gateways_policy
1760977922 [c] Mon Oct 20 17:32:02 BST 2025 all_gateways_policy
[c] - current policy
The manual is 'light' on the implications
"To work with the Policy installation history:
In SmartConsole
, go to Security Policies.From the Access Tools or the Threat Prevention Tools, select Installation History.
In the Gateways section, select a Security Gateway.
In the Policy Installation History section, select an installation date.
Perform the applicable action:
To see the revisions that were installed and who made them:
Click View installed changes.
To see the changes that were installed and who made them :
Click View.
To revert to a specific version of the policy:
Click Install specific version."
Thanks
Access Control Policy Revert Tool (policy_rev_tool) installs only the Access Control policies stored locally on the Gateway. It is not synchronized with the Security Management Server.
This means you will still need to address the issue on the Management side - either by using Revision Control or by manually reverting the changes that caused the problem.
As a useful aid, you can use the Changes Report between revisions to view modifications made by a specific administrator and identify what was changed.
Correct, installation history only stores a compiled version of the policy.
It does not change the policy on the management, which can only be reverted with a Database Revision.
Access Control Policy Revert Tool (policy_rev_tool) installs only the Access Control policies stored locally on the Gateway. It is not synchronized with the Security Management Server.
This means you will still need to address the issue on the Management side - either by using Revision Control or by manually reverting the changes that caused the problem.
As a useful aid, you can use the Changes Report between revisions to view modifications made by a specific administrator and identify what was changed.
Learnt something new, never even knew that existing...thank you @Tal_Paz-Fridman
One cool thing I also learnt (though I may had seen this before, long time ago) is if you are in expert mode and hit tab twice, you get below, so shows all the commands possible:
[Expert@CP-GW:0]#
Display all 2344 possibilities? (y or n)
cool - you can also do this if helpful(?)
[Expert@R82_mgmt_192.168.197.10:0]# clish -c "show commands" > commands.txt
[Expert@R82_mgmt_192.168.197.10:0]# less commands.txt
or cat or grep commands.txt etc
Thanks - in this instance, they had enabled the vpn blade then renewed the cert = then disabled the blade to fix a cosmetic error on many smbs, but one wouldnt then install policy - so really not clear how to manually revert that change in the policy as its not as simple as deleting a rule. Also advised them to follow sk182616 going forwards (as I was taught on a previous checkmates post). Thanks for the response.
However my question is still the same - If I use installation history to install last good poicy, but dont do a database revision, the policy on the management server and the one on the gateway will still be out of synch right? (as mentioned its not feasible to do db revision as there are about 50 admins making concurrent changes to 100s of gateways).
Correct, installation history only stores a compiled version of the policy.
It does not change the policy on the management, which can only be reverted with a Database Revision.
thank you
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY