Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
marcinw
Contributor
Jump to solution

changing "masters" file on SMB

Hi,

I've changed "masters" file in $FWDIR/conf/ on SMB 1500 checkpoint, of course every time SMB downloads policy from SMS changed it. On gateway firewall I can use GuiDBedit to change this behaviour on gateway firewall , but how to change it on SMB ?

0 Kudos
1 Solution

Accepted Solutions
sarshar
Contributor

Contacted TAC and they resolved it by sk171055

View solution in original post

0 Kudos
8 Replies
PhoneBoy
Admin
Admin
What's the precise reason you need to change it?
G_W_Albrecht
Legend
Legend
0 Kudos
sarshar
Contributor

Hey Albrecht,

 

Today I realized a couple of 1550s stopped logging.

They are running R81.10 and those two firewalls are in a VPN community along with another identical firewall that doesn't have the logging issue.

 

Traditionally, modified the masters file to replace the hostname of the CPM with its external IP address, also added the CPM with the ext IP to the /etc/hosts file and froze the define_logging_servers and use_loggers_and_masters by setting them to "false" in GUIEDEDIT

Then saved the changes to the DB and opened SmartConsole R81.20 and pushed the policies, the content of the masters file got overwritten therefore the logging issue didn't get resolved.

It might be useful to mention I faced this issue with every firewall we recently upgraded (replaced the appliance), which includes the 3000 series with R81.20 T631

Your kind advice on this will be appreciated, I cannot troubleshoot other connectivity issues without logging.

 

Regards,

Sarshar Dadashzadeh

PhoneBoy
Admin
Admin

If you want to ensure masters isn't overwritten, try setting the immutable flag on the masters file in expert mode.
e.g. chattr +i $FWDIR/conf/masters

How persistent this change is across upgrades is not known.

G_W_Albrecht
Legend
Legend

Better consult with TAC ! That should not be needed and 1 working but two identical units not needs finding the cause !

CCSE CCTE CCSM SMB Specialist
sarshar
Contributor

Contacted TAC and they resolved it by sk171055

0 Kudos
G_W_Albrecht
Legend
Legend

Very good!

CCSE CCTE CCSM SMB Specialist
0 Kudos
G_W_Albrecht
Legend
Legend

The oldest trick in such cases from the book is to limit access rights so overwrite will not be possible 😎.

CCSE CCTE CCSM SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events