Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RioAung
Contributor

How to export basic config and import to new firewalls

Hi,

I have multiple site to deploy .So I would like to standard config for every site.

I want to export basic setting like stealth rule, hardening setting, manangement IP and password ,etc. and then i want to import other firewall. what kind of function can i use ? if i use backup function and import to other firewall,I got stability issue . i used dbset backup:override_hfs t to fix if i got the errror.

 

let me know any best way to import standard setting.

0 Kudos
7 Replies
G_W_Albrecht
Legend
Legend

See here: sk108902 - Best Practices - Backup on Gaia OS.

But i would suggest that the best solution for you is sk120193: Blink - Gaia Fast Deployment !

CCSE CCTE CCSM SMB Specialist
_Val_
Admin
Admin

Not sure about stealth rule, that is always on the MGMT side.

For the rest, could you elaborate on backup function and stability issues?

For the most basic things, I would use "show config" in clish and then copy/paste to the new FW.

0 Kudos
PhoneBoy
Admin
Admin

What precisely are you migrating from in terms of hardware and software versions?
What precisely are you migrating to in terms of hardware and software versions?
How is the gateway managed? (Stand-alone or distributed)
The precise steps will depend on the answer to those questions, but will most likely involve the standard migration tools. 

0 Kudos
RioAung
Contributor

Hi @PhoneBoy ,

I have multiple site and all site are using same models and some basic rule are same . all are using same hardening config. I don't want to do hardening for every appliance . Blink deployment is only can include basic config like password , IP, SIC information ,right.

So i would like to export standard config including hardening config and import to other devices.

 

0 Kudos
PhoneBoy
Admin
Admin

Access and Threat Prevention policies comes from the management, so it's just a matter of installing the same policy to the different devices.
If you configured anything in Gaia OS using clish, that can be replicated easily enough with blink and/or CDT as mentioned in this thread.
You may also want to leverage CDT's "RMA" mode: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos
the_rock
Legend
Legend

I know sk @G_W_Albrecht provided you is definitely good start, but I would add that statement in it saying that backup can be imported into a different hardware model is not factually true. Say if you have 6000 appliance, but want to restore that backup on say 13000 series appliance, that would most likely not work. Personally, I would go with show configuration output from clish, as I find that easiest way to quickly get box up and running.

0 Kudos
G_W_Albrecht
Legend
Legend

Personally, i would go with blink and create deployment templates !

CCSE CCTE CCSM SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events