- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Critical File Watcher is an interactive command-line tool designed to easily monitor and manage potentially configurable files on Check Point Security Gateways. It is particularly useful during version upgrades and migration to a new device(This topic is specifically addressed in the preparation/prerequisites section of the Installation and Upgrade Guides).
Critical File Watcher is a simple yet powerful tool that allows administrators to monitor critical files with a single command and take prompt action when necessary.
Note: One-time before running the script
[Expert@X_Gw22:0]# chmod +x Critical_File_Watcher.sh
[Expert@X_Gw22:0]# dos2unix Critical_File_Watcher.sh
Critical File Watcher is an interactive command-line tool designed to easily monitor and manage potentially configurable files on Check Point Security Gateways. It is particularly useful during version upgrades and migration to a new device(This topic is specifically addressed in the preparation/prerequisites section of the Installation and Upgrade Guides).
For the context, output from my R82 lab fw:
[Expert@CP-GW:0]# ./check_critical_files.sh
============================================
==== Check Point Critical File Check ====
============================================
File modification dates:
------------------------------
/opt/CPcvpn-R82/conf/cvpnd.C : 2024-10-14 20:21:55.000000000 -0400
/opt/CPsuite-R82/fw1/boot/modules/fwkern.conf : 2025-11-06 15:50:14.492000000 -0500
/opt/CPsuite-R82/fw1/conf/cpha_bond_ls_config.conf : 2024-10-15 12:18:07.000000000 -0400
/opt/CPsuite-R82/fw1/conf/cpha_specific_vlan_data.conf : 2024-10-15 12:18:09.000000000 -0400
/opt/CPsuite-R82/fw1/conf/discntd.if : File not found
/opt/CPsuite-R82/fw1/conf/fw_fast_accel_export_configuration.conf : File not found
/opt/CPsuite-R82/fw1/conf/fwaffinity.conf : 2024-10-15 12:18:09.000000000 -0400
/opt/CPsuite-R82/fw1/conf/fwauthd.conf : 2025-11-05 08:30:05.974000000 -0500
/opt/CPsuite-R82/fw1/conf/hsm_configuration.C : 2024-10-15 12:18:03.000000000 -0400
/opt/CPsuite-R82/fw1/conf/identity_broker.C : 2024-10-15 12:18:09.000000000 -0400
/opt/CPsuite-R82/fw1/conf/ipassignment.conf : 2024-10-15 12:18:10.000000000 -0400
/opt/CPsuite-R82/fw1/conf/local.arp : File not found
/opt/CPsuite-R82/fw1/conf/malware_config : 2025-04-09 14:42:53.683000000 -0400
/opt/CPsuite-R82/fw1/conf/prioq.conf : 2025-04-09 14:50:51.686000000 -0400
/opt/CPsuite-R82/fw1/conf/rad_conf.C : 2024-10-15 12:20:33.000000000 -0400
/opt/CPsuite-R82/fw1/conf/synatk.conf : 2025-04-09 14:56:59.254000000 -0400
/opt/CPsuite-R82/fw1/conf/te.conf : 2025-11-11 08:58:30.772000000 -0500
/opt/CPsuite-R82/fw1/conf/thresholds.conf : 2024-10-15 12:20:33.000000000 -0400
/opt/CPsuite-R82/fw1/conf/trac_client_1.ttm : 2024-10-15 12:16:49.000000000 -0400
/opt/CPsuite-R82/fw1/conf/vsaffinity_exception.conf : 2024-10-15 12:18:09.000000000 -0400
/opt/CPppak-R82/conf/simkern.conf : File not found
/var/ace/sdconf.rec : 2025-04-09 15:44:26.093000000 -0400
/var/ace/sdopts.rec : 2025-04-09 15:44:26.092000000 -0400
/var/ace/sdstatus.12 : File not found
/var/ace/securid : File not found
For the context, output from my R82 lab fw:
[Expert@CP-GW:0]# ./check_critical_files.sh
============================================
==== Check Point Critical File Check ====
============================================
File modification dates:
------------------------------
/opt/CPcvpn-R82/conf/cvpnd.C : 2024-10-14 20:21:55.000000000 -0400
/opt/CPsuite-R82/fw1/boot/modules/fwkern.conf : 2025-11-06 15:50:14.492000000 -0500
/opt/CPsuite-R82/fw1/conf/cpha_bond_ls_config.conf : 2024-10-15 12:
Just a thought I had...do you think there would be any way to actually show which files would be 100% needed if customer was to upgrade?
Just a thought I had...do you think there would be any way to actually show which files would be 100% needed if customer was to upgrade?
;Hello @the_rock
In my opinion, these files should be fully backed up before every upgrade and migration. This is already explicitly stated in the Upgrade & Installation Guide. However the critical point here is to check the modification dates of these files that come by default after first installation(or jumbo hot fix if needed). By doing so it can be determined whether any changes were made and after a fresh install or migration the modified files can be compared and transferred accordingly.
In other words these files are configured differently depending on various scenarios.
Thank you
Hello @the_rock
In my opinion, these files should be fully backed up before every upgrade and migration. This is already explicitly stated in the Upgrade & Installation Guide. However the critical point here is to check the modification dates of these files that come by default after first installation(or jumbo hot fix if needed). By doing so it can be determined whether any changes were made and after a fresh install or migration the modified files can be compared and transferred
...;About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY