Checkpoint - Ive pushed the Wrong Policy

Firewalls - Checkpoint

Issue

There may be a time where you install the wrong policy onto a Checkpoint Firewall. This can block your connections, and screw which traffic is allowed through the firewall.

Resolution

These steps will show you how to remove and reinstall the correct policy via the CLI on the manager (SCS),

  1. fw stat -l [firewall ip]
  2. fwm unload [fwname]
  3. fwm load [PolicyName].W [fwname]

Steps Explained,

  1. This will show you the policy history, so we can find out the name of the policy we need to reinstall. 
  2. This will remove the security policy from the firewall.
  3. This will install the correct policy back onto your Firewall. Note how we add the .W to the policy name as it has yet to be be compiled into a .cf file (which is what is installed onto the Firewall/Gateway)   

Additional Resources

Additonal Checkpoint commands can be found here

Article updates via email..


We have 23 guests online

Related Articles

Copyright © 2010 Fir3net.com - Keeping You In The Know. All Rights Reserved.
Joomla! is Free Software released under the GNU/GPL License.