- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
I have a cluster of two 6700 gateways to be replaced with brand new 9200, unfrotunately these old gateways have been managed by an external supplier for years and I'm quite sure they did some changes in files (ie. table.def) or enabled/disabled some configurations.
Is there a way to find exactly what has been changed compared to a default configuration?
Or what do you suggest to keep these changes in the new devices?
thanks!
Some of the commands you enter on the gateway are ephemeral, some are not.
A few things to check/review:
There are likely other files, these are just the ones that come to mind as I type this 🙂
Was this a Full HA cluster (without external management) or with external management?
Believe you can run the pre-upgrade verifier tool to get this information:
|
|
Hi @PhoneBoy ,
it's a HA cluster with external management
You can compare needed files between freshly installed gateway and questionable gateway. Make sure the version and Take are the same. Download file to be checked (like table.def) from both gateways, use Excel or NotePad++ features to see differencies between 2 files.
Another idea can be to check when was needed file last modified. In theory, the .def file is supposed to be modified during upgrade or Jumbo installation. But it can be also modified by management by pushing the file to gateway... You can check when was needed file created, modified and last accessed using linux command "stat".
I'm guessing there are a lot more files than just table.def. It would be a bit of a hassle to manually download them from the gateway and then compare them manually, even if you knew all the possible candidate files. 🙂
Most of .def files are stored on management and pushed to the gateway during policy installation.
But I am pretty sure there might be some rare cases where .def file was modified directly on gateway.
This will help a lot:
https://support.checkpoint.com/results/sk/sk33156
Compare the output with new gateway.
Thank you to everyone for the suggestions,
good to know that the table.def is pushed from the Management (which I already upgraded), but what about configurations enabled/disabled on the gateways themselves?
For example I'm thinking of the command to pass the traffic to the standby gateway and similar, is there a way to know if something has been modified compared to a default configuration?
Some of the commands you enter on the gateway are ephemeral, some are not.
A few things to check/review:
There are likely other files, these are just the ones that come to mind as I type this 🙂
To identify configuration changes on your 6700 gateways, review backups, compare configurations using tools like CCA, or consult the external supplier. Document the changes and test them on a 9200 gateway before migration.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 15 | |
| 14 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY