Friday, April 21, 2023

Transfer Configuration from one appliance to another

 Checkpoint How To Documentation

Source CP appliance (Existing)
HostName > save configuration <filename>

SCP File to New Hardware

Destination CP Appliance (New)
HostName > set clienv on-failure continue
HostName > load configuration <filename>
HostName > set clienv on-failure stop
HostName > save config



Checkpoint Snapshots and hotfixes

 

Collect:

  • Snapshot - after a fresh installation, before an upgrade, and before a hotfix installation.
  • Scheduled Backup - monthly or weekly, depending how frequently you perform changes in your configuration and policy

Snapshot Management

The snapshot creates a binary image of the entire root (lv_current) disk partition. This includes Check Point products, configuration, and operating system.

The log partition is not included in the snapshot. Therefore, any locally stored Firewall logs will not be saved.

Backup Management

System Backup can be used to backup current system configuration. A backup creates a compressed file that contains the Check Point configuration including the networking and operating system parameters, such as routing and interface configuration etc., but unlike a snapshot, it does not include the operating system, product binaries, and hotfixes.


I've also highlighted in Green where each command is preferable.


Snapshot Management
snapshot

System Backup
backup
How much time does it take ?
30 - 60 minutes
5 - 30 minutes
Size of output file on Security Gateway
5-100 GB
Depends on configuration
Size of output file on Management Server
5-100 GB
5-100 GB
Does it back up Gaia OS configuration ?
Yes
Yes
Does it back up Products configuration ?
Yes
Yes
Does it back up Hotfixes ?
Yes
No (*)
Does it back up Check Point logs?
No
No
Does it support automatic scheduling ?
No
Yes
Can you restore from different version ?
Yes
No
Does it require to close SmartConsole GUI clients ?
No
R7x - No
R80 - Yes
Does it require to stop Check Point services?
No
No
Does it require reboot ?
No
No

 

CP FWM Useful Commands

 Useful command on your management server to determine if there are any issues going on 


#df -h
#free -m
#free -mh
#uptime
#cpstat os
#cpinfo -y all
# clish -c "show installer packages installed"
# cpprod_util FwIsLogServer
#cpprod_util RtIsAnalyzerServer
#cpprod_util RtIsAnalyzerCorrelationUnit
#fw stat
#fwm ver
# cpprod_util FwIsStandAlone
#fwm mds ver
#cpwd_admin list


 -What is the latest smartconsole build number installed?
  in smartconsole > from top left menu > about smartconsole
 
Outputs for these commands for the Mgmt server:
#df -h
[Expert@my_fwm01:0]# df  -h
Filesystem                       Size  Used Avail Use% Mounted on
/dev/mapper/vg_splat-lv_current  300G   21G  280G   7% /
/dev/sda1                        291M   80M  197M  29% /boot
tmpfs                             94G   33M   94G   1% /dev/shm
/dev/mapper/vg_splat-lv_log       13T   19G   13T   1% /var/log
cgroup                            94G     0   94G   0% /sys/fs/cgroup
[Expert@my_fwm01:0]# 



#free -m
[Expert@my_fwm01:0]# free -m
              total        used        free      shared  buff/cache   available
Mem:         191651       11183      154661        3496       25807      175861
Swap:         95464           0       95464
[Expert@my_fwm01:0]#
 



#free -mh
[Expert@my_fwm01:0]# free -mh
              total        used        free      shared  buff/cache   available
Mem:           187G         10G        151G        3.4G         25G        171G
Swap:           93G          0B         93G
[Expert@my_fwm01:0]# 


#uptime
[Expert@my_fwm01:0]# uptime
 19:04:49 up 14 days, 22:03,  6 users,  load average: 0.19, 0.31, 0.37
[Expert@my_fwm01:0]# 


 
#cpstat os
[Expert@my_fwm01:0]# cpstat os
Product Name:                  SVN Foundation
SVN Foundation Version String: R81.10
SVN Foundation Build Number:   996000057
SVN Foundation Status:         OK
OS Name:                       Gaia
OS Major Version:              3
OS Minor Version:              10
OS Build Number:               -
OS SP Major:                   -
OS SP Minor:                   -
OS Version Level:               
Appliance SN:                  XXXXXX
Appliance Name:                Smart-1 XXXXX-L
Appliance Manufacturer:        CheckPoint
[Expert@my_fwm01:0]# 


#cpinfo -y all
[Expert@my_fwm01:0]# cpinfo -y all 
This is Check Point CPinfo Build 914000227 for GAIA
[CPFC]
        No hotfixes..
[IDA]
        No hotfixes..
[MGMT]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[FW1]
        HOTFIX_NGM_DOCTOR_AUTOUPDATE
        HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
        HOTFIX_WEBCONSOLE_AUTOUPDATE
        HOTFIX_GOT_MGMT_AUTOUPDATE
        HOTFIX_GOT_TPCONF_MGMT_AUTOUPDATE
FW1 build number:
This is Check Point Security Management Server R81.10 - Build 011
This is Check Point's software version R81.10 - Build 033
[SecurePlatform]
        HOTFIX_ENDER_V17_AUTOUPDATE
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[AutoUpdater]
        No hotfixes..
[CPinfo]
        No hotfixes..
[SmartLog]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[DIAG]
        No hotfixes..
[Reporting Module]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[CPuepm]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[VSEC]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[CPDepCon]
        No hotfixes..
[CPRepMan]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[SFWR77CMP]
        HOTFIX_R81_10_JHF_COMP  Take:  87
[SFWR80CMP]
        HOTFIX_R81_10_JHF_COMP  Take:  87
[R77CMP]
        No hotfixes..
[R8040CMP]
        HOTFIX_R81_10_JHF_COMP  Take:  87
[MGMTAPI]
        No hotfixes..
[CPUpdates]
        BUNDLE_ENDER_V17_AUTOUPDATE     Take:  21
        BUNDLE_CPVIEWEXPORTER_AUTOUPDATE        Take:  27
        BUNDLE_CPOTELCOL_AUTOUPDATE     Take:  25
        BUNDLE_CORE_FILE_UPLOADER_AUTOUPDATE    Take:  21
        BUNDLE_NGM_DOCTOR_AUTOUPDATE    Take:  15
        BUNDLE_GENERAL_AUTOUPDATE       Take:  13
        BUNDLE_INFRA_AUTOUPDATE Take:  58
        BUNDLE_DEP_INSTALLER_AUTOUPDATE Take:  25
        BUNDLE_TUNNEL_AUTOUPDATE        Take:  66
        BUNDLE_DANA_AUTOUPDATE  Take:  131
        BUNDLE_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE        Take:  19
        BUNDLE_CPSDC_AUTOUPDATE Take:  23
        BUNDLE_R81_10_JUMBO_HF_MAIN     Take:  87
        BUNDLE_DC_CONTENT_AUTOUPDATE    Take:  15
        BUNDLE_WEBCONSOLE_AUTOUPDATE    Take:  76
        BUNDLE_HCP_AUTOUPDATE   Take:  59
        BUNDLE_GOT_MGMT_AUTOUPDATE      Take:  108
        BUNDLE_GOT_TPCONF_MGMT_AUTOUPDATE       Take:  36
        BUNDLE_DC_INFRA_AUTOUPDATE      Take:  30
[itp_wrapper]
        HOTFIX_GOT_MGMT_AUTOUPDATE
[hcp_wrapper]
        HOTFIX_HCP_AUTOUPDATE
[R7540CMP]
        No hotfixes..
[R76CMP]
        No hotfixes..
[SFWR81CMP]
        No hotfixes..
[CPDepInst]
        No hotfixes..
[cpsdc_wrapper]
        HOTFIX_CPSDC_AUTOUPDATE
[sho_wrapper]
        HOTFIX_DANA_AUTOUPDATE
[infinity_onprem_wrapper]
        HOTFIX_TUNNEL_AUTOUPDATE
[core_uploader]
        HOTFIX_CHARON_HF
[CPotelcol]
        HOTFIX_OTLP_GA
[CPviewExporter]
        HOTFIX_OTLP_GA
[Expert@my_fwm01:0]# 



# clish -c "show installer packages installed"
[Expert@my_fwm01:0]# clish -c "show installer packages installed"
**  ************************************************************************* **
**                                 Hotfixes                                   **
**  ************************************************************************* **
Display name                                                                                    Type                      
R81.10 Jumbo Hotfix Accumulator General Availability (Recommended Jumbo Take 78)                Hotfix                    
R81.10 Jumbo Hotfix Accumulator Recommended Jumbo Recommended Jumbo Take 87                     Hotfix                    
**  ************************************************************************* **
**                                  Majors                                    **
**  ************************************************************************* **
Display name                                                                                    Type                      
R81.10 Gaia Fresh Install and upgrade                                                           Major Version             
[Expert@my_fwm01:0]# 

 
# cpprod_util FwIsLogServer
[Expert@my_fwm01:0]# cpprod_util FwIsLogServer

[Expert@my_fwm01:0]# 



#cpprod_util RtIsAnalyzerServer
[Expert@my_fwm01:0]# cpprod_util RtIsAnalyzerServer

[Expert@my_fwm01:0]# 


#cpprod_util RtIsAnalyzerCorrelationUnit
[Expert@my_fwm01:0]# cpprod_util RtIsAnalyzerCorrelationUnit

[Expert@my_fwm01:0]# 
 

Sunday, April 16, 2023

Understand Checkpoint RSA SecurID Authentication

 

RSA SecurID Authentication

SDCONF.REC file is generated from the RSA Authentication Manager for the Firewall MY-VPN-FW01 And it is placed in the /var/ace directory

SDOPTS.REC is a text file that contains Client_IP=100.114.255.29  (this the IP address of the Firewall member. The file is created by the System Admin.

SDSTATUS.12  this file is generated by Checkpoint and it contains information such as token passing successfully to auth manager, it records

SECURID – this is the Secret Node Key that is exchanged between the Security Gateway and RSA SecureID Server.


sdconf.rec (from Auth Manager), sdops.rec (Client_IP), sdstatus.12 (checkpoint generated token passed to RSA manager, and  securID (Secret Node Key)


"Wrong username and password" error when authenticating via SecurID

  • Users cannot authenticate with SecurID after replacing sdconf.rec file with an updated one from the RSA SecurID server, receiving "Wrong username and password" error.
  • "Node Secret mismatch: cleared on server but not on agent" message in the RSA SecurID server logs

The "securid" file (a Secret Node key that is exchanged between the Security gateway and the RSA SecurID Server) is corrupted.  sk106582


The sdopts.rec file will not be invoked

the sdopts.rec file was not being invoked by Firewall-1 because of the presence ofthe sdstatus.12 which is also in the /var/ace directory. The sdstatus.12 file takes precedence. Removing the sdstatus.12 file made the sdopts.rec take effect.

Any modification of these file will require a cpstop and cpstart on the active cluster member.



How to Download a the SDCONF.REC file 

Access –> Authentication Agent -> Generate Configuration File



RSA Authentication Manager (Auth Manager)

Authentication Manager has a WebUI, and it manages users, tokens agents and can produce reports and enforce policies like how many time. The Authentication Manager has a primary and a replica for redundancy. It is available in 2 options, software and appliance form factor. It’s main purpose is to handle user authentication requests, and also to system administration  such as users, tokens, agents, reporting, and policy and database backups 

 

Identity Router

To establish SIC with a new Checkpoint gateway and it's Management Sever

 To establish SIC with a new Checkpoint gateway and it's Management Sever 


1. The Gateway must  have CPD running in E Stat .. to validate it, you can run cpwd_admin list  if it is a T stat, you will not be able to establish SIC

[Expert@MY-VPN-FW01:0]# cpwd_admin list

APP        PID    STAT  #START  START_TIME             MON  COMMAND             
FWK_FORKER 73879  E     1       [21:37:50] 14/4/2023   N    fwk_forker          
FWK_WD     73888  E     1       [21:37:50] 14/4/2023   N    fwk_wd -i 43 -i6 0  
CPVIEWD    74765  E     1       [21:38:08] 14/4/2023   N    cpviewd             
CPVIEWS    74782  E     1       [21:38:08] 14/4/2023   N    cpview_services     
CVIEWAPIS  74787  E     1       [21:38:08] 14/4/2023   N    cpview_api_service  
SXL_STATD  74792  E     1       [21:38:08] 14/4/2023   N    sxl_statd           
CPD        74804  E     1       [21:38:08] 14/4/2023   Y    cpd                 
MPDAEMON   74816  E     1       [21:38:08] 14/4/2023   N    mpdaemon /opt/CPshrd-R81.10/log/mpdaemon.elg /opt/CPshrd-R81.10/conf/mpdaemon.conf
TP_CONF_SERVICE 230716 E     1       [00:24:39] 15/4/2023   N    tp_conf_service --conf=tp_conf.json --log=error
CXLD       75062  E     1       [21:38:10] 14/4/2023   N    cxld -d             
CI_CLEANUP 75078  E     1       [21:38:10] 14/4/2023   N    avi_del_tmp_files   
CIHS       75081  E     1       [21:38:10] 14/4/2023   N    ci_http_server -j -f /opt/CPsuite-R81.10/fw1/conf/cihs.conf
FWD        75105  E     1       [21:38:10] 14/4/2023   N    fwd                 
SPIKE_DETECTIVE 75120  E     1       [21:38:10] 14/4/2023   N    spike_detective     
DSDAEMON   158764 E     1       [01:32:16] 15/4/2023   Y    dsd                 
DASERVICE  100901 E     1       [21:39:35] 14/4/2023   N    DAService_script    
AUTOUPDATER 100918 E     1       [21:39:35] 14/4/2023   N    AutoUpdaterService.sh
CPHAMCSET  124212 E     1       [21:43:27] 14/4/2023   N    cphamcset -d        
WSDNSD     40975  E     1       [00:47:51] 15/4/2023   Y    wsdnsd              
RAD        125442 E     1       [21:43:30] 14/4/2023   N    rad                 
RTMD       125479 E     1       [21:43:31] 14/4/2023   N    rtmd                
LPD        15444  E     1       [04:34:46] 15/4/2023   N    lpd                 
[Expert@MY-VPN-FW01:0]#