- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- changing "masters" file on SMB
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
changing "masters" file on SMB
Hi,
I've changed "masters" file in $FWDIR/conf/ on SMB 1500 checkpoint, of course every time SMB downloads policy from SMS changed it. On gateway firewall I can use GuiDBedit to change this behaviour on gateway firewall , but how to change it on SMB ?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Contacted TAC and they resolved it by sk171055
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Albrecht,
Today I realized a couple of 1550s stopped logging.
They are running R81.10 and those two firewalls are in a VPN community along with another identical firewall that doesn't have the logging issue.
Traditionally, modified the masters file to replace the hostname of the CPM with its external IP address, also added the CPM with the ext IP to the /etc/hosts file and froze the define_logging_servers and use_loggers_and_masters by setting them to "false" in GUIEDEDIT
Then saved the changes to the DB and opened SmartConsole R81.20 and pushed the policies, the content of the masters file got overwritten therefore the logging issue didn't get resolved.
It might be useful to mention I faced this issue with every firewall we recently upgraded (replaced the appliance), which includes the 3000 series with R81.20 T631
Your kind advice on this will be appreciated, I cannot troubleshoot other connectivity issues without logging.
Regards,
Sarshar Dadashzadeh
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you want to ensure masters isn't overwritten, try setting the immutable flag on the masters file in expert mode.
e.g. chattr +i $FWDIR/conf/masters
How persistent this change is across upgrades is not known.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Better consult with TAC ! That should not be needed and 1 working but two identical units not needs finding the cause !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Contacted TAC and they resolved it by sk171055
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Very good!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The oldest trick in such cases from the book is to limit access rights so overwrite will not be possible 8).
