Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AkiYa
Contributor
Jump to solution

How to check modified files/config before replace

Hi all,

I have a cluster of two 6700 gateways to be replaced with brand new 9200, unfrotunately these old gateways have been managed by an external supplier for years and I'm quite sure they did some changes in files (ie. table.def) or enabled/disabled some configurations.

Is there a way to find exactly what has been changed compared to a default configuration?

Or what do you suggest to keep these changes in the new devices? 

thanks!

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Some of the commands you enter on the gateway are ephemeral, some are not.
A few things to check/review:

  • Customizations to the Mobile Access VPN portal (usually involves editing files in $CVPNDIR).
    • Here I would refer file modification dates compared to stuff in the same directory. 
  • /web/templates (manual changes to web servers)
  • /etc/ssh/templates (under the hood changes for SSH)
  • $FWDIR/conf/fwaccel_dos_rate_on_install (DDoS Mitigation Rules)
  • $FWDIR/conf/*.ttm and $FWDIR/conf/ipassignment.conf
    • VPN-related configuration
  • $FWDIR/boot/modules/fwkern.conf and $FWDIR/boot/modules/vpnkern.conf
    • Recommended to review settings here before copying them over as they may not apply, especially if the version between the two gateways is changing

There are likely other files, these are just the ones that come to mind as I type this 🙂

 

View solution in original post

9 Replies
PhoneBoy
Admin
Admin

Was this a Full HA cluster (without external management) or with external management?
Believe you can run the pre-upgrade verifier tool to get this information: 

 

$MDS_FWDIR/scripts/migrate_server verify -v R81.20 -skip_upgrade_tools_check

 

0 Kudos
AkiYa
Contributor

Hi @PhoneBoy ,

it's a HA cluster with external management

0 Kudos
JozkoMrkvicka
Authority
Authority

You can compare needed files between freshly installed gateway and questionable gateway. Make sure the version and Take are the same. Download file to be checked (like table.def) from both gateways, use Excel or NotePad++ features to see differencies between 2 files.

Another idea can be to check when was needed file last modified. In theory, the .def file is supposed to be modified during upgrade or Jumbo installation. But it can be also modified by management by pushing the file to gateway... You can check when was needed file created, modified and last accessed using linux command "stat".

Kind regards,
Jozko Mrkvicka
0 Kudos
Vincent_Bacher
Advisor
Advisor

I'm guessing there are a lot more files than just table.def. It would be a bit of a hassle to manually download them from the gateway and then compare them manually, even if you knew all the possible candidate files. 🙂

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
JozkoMrkvicka
Authority
Authority

Most of .def files are stored on management and pushed to the gateway during policy installation.

But I am pretty sure there might be some rare cases where .def file was modified directly on gateway.

Kind regards,
Jozko Mrkvicka
0 Kudos
Lesley
Leader Leader
Leader

This will help a lot:

Creating a file with all the kernel parameters and their values:

https://support.checkpoint.com/results/sk/sk33156

Compare the output with new gateway. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
AkiYa
Contributor

Thank you to everyone for the suggestions,

good to know that the table.def is pushed from the Management (which I already upgraded), but what about configurations enabled/disabled on the gateways themselves?

For example I'm thinking of the command to pass the traffic to the standby gateway and similar, is there a way to know if something has been modified compared to a default configuration?

0 Kudos
PhoneBoy
Admin
Admin

Some of the commands you enter on the gateway are ephemeral, some are not.
A few things to check/review:

  • Customizations to the Mobile Access VPN portal (usually involves editing files in $CVPNDIR).
    • Here I would refer file modification dates compared to stuff in the same directory. 
  • /web/templates (manual changes to web servers)
  • /etc/ssh/templates (under the hood changes for SSH)
  • $FWDIR/conf/fwaccel_dos_rate_on_install (DDoS Mitigation Rules)
  • $FWDIR/conf/*.ttm and $FWDIR/conf/ipassignment.conf
    • VPN-related configuration
  • $FWDIR/boot/modules/fwkern.conf and $FWDIR/boot/modules/vpnkern.conf
    • Recommended to review settings here before copying them over as they may not apply, especially if the version between the two gateways is changing

There are likely other files, these are just the ones that come to mind as I type this 🙂

 

Matrio
Explorer

To identify configuration changes on your 6700 gateways, review backups, compare configurations using tools like CCA, or consult the external supplier. Document the changes and test them on a 9200 gateway before migration.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events