Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Copper

Compare policy

HI All,

Is there a method to compare policies on two different SmartCenters? I have the following case:

We have a customer with a R80.20 SmartCenter managing the perimeter firewall cluster. The SmartCenter runs on a Smart-1 appliance. We have migrated the SmartCenter to VM and R80.30 with a advanced migration. We also changed the hostname and IP-address of this new R80.30 SmartCenter.

The R80.30 SmartCenter is managing the new core firewall cluster and now we need to perform a SIC reset on the perimeter firewall cluster so the new SmartCenter is managing the perimeter firewall also.

But this customer is a large hospital so with the current Corona crisis, we cannot change anything on the perimeter firewall. Except a policy offcourse. So when the customer changes something on the perimeter firewall, this change must also be added to the new R80.30 SmartCenter. This has to be done as long the perimeter firewall is not migrated to the new SmartCenter. We do not know how long this will be the case.

To avoid mistaked, we would like to have a procedure to compare the policy of the perimeter firewall on both SmartCenters just before migrating the perimeter firewall. If all changed where added on both SmartCenters, the difference should be zero. But a mistake is easily made so comparing the policies could show those mistakes.

Anyone done this before?

Regards, Martijn

0 Kudos
2 Replies
Highlighted
Admin
Admin

Re: Compare policy

In a pinch, I'd take the results from (probably successive) API call to both management servers and compare outputs using diff.
Or compare output of the Show Package Tool: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
If the output is different, there's a difference.
0 Kudos
Highlighted
Copper

Re: Compare policy

Thanks Dameon,

We used the Show Package Tool and performed a migration from one SmartCenter to the other without downtime.

Customer was very happy.

Regards,

Martijn

0 Kudos