Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SecdetKrypton
Explorer

How install InitialPolicy after use fw unloadlocal

I used the command fw unloadlocal on my cluster XL gateways, but I would like to install the initial policy. How could I do that?

0 Kudos
2 Replies
Duane_Toler
Advisor

This is in the Installation and upgrade guide:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Gui...

 

You may (or may not) need to run the initial policy compiler first:

$FWDIR/bin/comp_init_policy [-g | -G]

Creates the local state Initial Policy

 

Then load the policy manually:

fw fetchlocal -d $FWDIR/state/local/FW1/

 

InitialPolicy loaded:

[Expert@cpgw01:0]# fw stat
HOST      POLICY           DATE              
localhost InitialPolicy     7Mar2025  0:11:41 :  [>eth0] [<eth0]

 

Please test this on your own before trying on a production gateway, however!   After InitialPolicy is loaded, you can still SSH to the gateway and run various CPD management commands from SmartConsole (or wherever).  You can't ping the gateway, however.

 

If you want to build your own custom default filter, review the documentation section:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Gui...

 

 

Tal_Paz-Fridman
Employee
Employee

If you haven't installed a different policy (after the uninstall) then just running fw fetch localhost will fetch the Initial Policy.

If you want to install / fetch Initial Policy when there is a different policy you will need compile it and perform additional steps

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 18 Mar 2025 @ 09:30 AM (EET)

    CheckMates Live Greece

    Tue 25 Mar 2025 @ 12:00 PM (MDT)

    Salt Lake City: CPX 2025 Recap

    Tue 08 Apr 2025 @ 12:00 PM (MDT)

    Denver: CPX 2025 Recap
    CheckMates Events