- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: need help removing a bad NAT in the Command li...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
need help removing a bad NAT in the Command line
I locked myself out of the firewall by not paying attention to the NAT rule. its no good and I cant figure out what command I need to remove it from the command line. (since I cant get back into the web interface) please help I don't want to have to start from square 1. I have
R77.20.81
thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you not use "fw unloadlocal" ? to temporarily unload the policy from the appliance and then make necessary NAT changes and deploy the policy again.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
that worked but how to I enable the local again after running "fw unloadlocal"? sorry i'm still new to these firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Lee,
1) You can push the policy from the smart dashboard to the gateway.
2) or you can run this command in the gateway cli "fw fetch InsertYourManagementServerName"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Given that it's R77.20.81 - I'm assuming that this is a 700-series or 1400-series appliance?
So it's plausible that there might not be a management server, and SmartDashboard might not be an option.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1200R firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Ahmed,
smart dashboard --not sure what that is. It is a locally managed firewall
haven't done a management server yet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the future, please post queries about the 1200R in the SMB and SMP space so you are provided the most relevant help.
The CLI command to show NAT rules is show nat-rules
Once you figure out what position the erroneous NAT rule is in, you can use delete nat-rule position X to remove the erroneous rule.
See also: Check Point 600/700/1100/1200R/1400 Appliance R77.20.80 Technical Reference Guide
