Monday, May 15, 2023

Checkpoint Firewall Customization - SIC cpd disable https2

 
For SIC to be established with management Server, endure CPD process on the Security Gateway is has started with E and not terminated T 

[Expert@my-FW:0]# cpwd_admin list
APP        PID    STAT  #START  START_TIME             MON  COMMAND             
FWK_FORKER 103721 E     1       [16:48:07] 27/4/2023   N    fwk_forker          
FWK_WD     103730 E     1       [16:48:07] 27/4/2023   N    fwk_wd -i 43 -i6 0  
CPD        104483 E     1       [16:48:23] 27/4/2023   Y    cpd                 
DASERVICE  126938 E     1       [16:55:53] 27/4/2023   N    DAService_script    
AUTOUPDATER 121008 E     1       [16:49:18] 27/4/2023   N    AutoUpdaterService.sh
CPVIEWD    104461 E     1       [16:48:23] 27/4/2023   N    cpviewd             
LPD        75565  E     1       [16:46:35] 27/4/2023   N    lpd                 
CPVIEWS    104466 E     1       [16:48:23] 27/4/2023   N    cpview_services     
SXL_STATD  104469 E     1       [16:48:23] 27/4/2023   N    sxl_statd           
MPDAEMON   104496 E     1       [16:48:23] 27/4/2023   N    mpdaemon /opt/CPshrd-R81.10/log/mpdaemon.elg /opt/CPshrd-R81.10/conf/mpdaemon.conf
TP_CONF_SERVICE 104523 E     1       [16:48:23] 27/4/2023   N    tp_conf_service --conf=tp_conf.json --log=error
CXLD       104743 E     1       [16:48:24] 27/4/2023   N    cxld -d             
CI_CLEANUP 104750 E     1       [16:48:24] 27/4/2023   N    avi_del_tmp_files   
CIHS       104757 E     1       [16:48:24] 27/4/2023   N    ci_http_server -j -f /opt/CPsuite-R81.10/fw1/conf/cihs.conf
FWD        104780 E     1       [16:48:24] 27/4/2023   N    fwd                 
SPIKE_DETECTIVE 104787 E     1       [16:48:24] 27/4/2023   N    spike_detective     
DSDEAMON   117031 E     1       [16:49:13] 27/4/2023   Y    dsd                 
[Expert@my-FW:0]# 


To disable https2 or enable https2 

1. Disable HTTP2 Header Length on my-vpn-fwa.mycompany.COM and my-vpn-fwb.mycompany.COM

To disable http2:
ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 IGNORE_ALPN_EXTENSION 1
cpstop;cpstart

To enable http2 again:
ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 IGNORE_ALPN_EXTENSION 0
cpstop;cpstart


VPN TRAC_Client_1 Files

/var/opt/CPsuite-R81.10/fw/conf/trac_client_1.ttm


RSA integration with Checkpoint 
Files are located in /var/ace directory
Must do a cpstop before change files and cpstart after
Initially you need just 2 files sdconf.rec and sdopts.rec file

sdconf.rec, 
sdopts.rec (clientIP)
securID (node secret), 
sdstatus.12 (traffic info between FW and Auth Manager)


Migrate Export of Checkpoint Management Server 

[Expert@CP-MGMT01]# cd $FWDIR/bin/upgrade_tools
[Expert@CP-MGMT01]# pwd
/opt/CPsuite-R80.40/fw1/bin/upgrade_tools
[Expert@CP-MGMT01]# cd $HOME
[Expert@CPMGMT01]# yes | nohup ./migrate export /home/admin/CPMGMT01-090622.tgz
nohup: appending output to 'nohup.out'
[Expert@CP-MGMT01]#

  • cpinfo -y all
  • enabled_blades
  • fw stat
  • cpinfo from gateway and cpinfo / migrate export from management server


Friday, April 21, 2023

Transfer Configuration from one appliance to another

 Checkpoint How To Documentation

Source CP appliance (Existing)
HostName > save configuration <filename>

SCP File to New Hardware

Destination CP Appliance (New)
HostName > set clienv on-failure continue
HostName > load configuration <filename>
HostName > set clienv on-failure stop
HostName > save config



Checkpoint Snapshots and hotfixes

 

Collect:

  • Snapshot - after a fresh installation, before an upgrade, and before a hotfix installation.
  • Scheduled Backup - monthly or weekly, depending how frequently you perform changes in your configuration and policy

Snapshot Management

The snapshot creates a binary image of the entire root (lv_current) disk partition. This includes Check Point products, configuration, and operating system.

The log partition is not included in the snapshot. Therefore, any locally stored Firewall logs will not be saved.

Backup Management

System Backup can be used to backup current system configuration. A backup creates a compressed file that contains the Check Point configuration including the networking and operating system parameters, such as routing and interface configuration etc., but unlike a snapshot, it does not include the operating system, product binaries, and hotfixes.


I've also highlighted in Green where each command is preferable.


Snapshot Management
snapshot

System Backup
backup
How much time does it take ?
30 - 60 minutes
5 - 30 minutes
Size of output file on Security Gateway
5-100 GB
Depends on configuration
Size of output file on Management Server
5-100 GB
5-100 GB
Does it back up Gaia OS configuration ?
Yes
Yes
Does it back up Products configuration ?
Yes
Yes
Does it back up Hotfixes ?
Yes
No (*)
Does it back up Check Point logs?
No
No
Does it support automatic scheduling ?
No
Yes
Can you restore from different version ?
Yes
No
Does it require to close SmartConsole GUI clients ?
No
R7x - No
R80 - Yes
Does it require to stop Check Point services?
No
No
Does it require reboot ?
No
No

 

CP FWM Useful Commands

 Useful command on your management server to determine if there are any issues going on 


#df -h
#free -m
#free -mh
#uptime
#cpstat os
#cpinfo -y all
# clish -c "show installer packages installed"
# cpprod_util FwIsLogServer
#cpprod_util RtIsAnalyzerServer
#cpprod_util RtIsAnalyzerCorrelationUnit
#fw stat
#fwm ver
# cpprod_util FwIsStandAlone
#fwm mds ver
#cpwd_admin list


 -What is the latest smartconsole build number installed?
  in smartconsole > from top left menu > about smartconsole
 
Outputs for these commands for the Mgmt server:
#df -h
[Expert@my_fwm01:0]# df  -h
Filesystem                       Size  Used Avail Use% Mounted on
/dev/mapper/vg_splat-lv_current  300G   21G  280G   7% /
/dev/sda1                        291M   80M  197M  29% /boot
tmpfs                             94G   33M   94G   1% /dev/shm
/dev/mapper/vg_splat-lv_log       13T   19G   13T   1% /var/log
cgroup                            94G     0   94G   0% /sys/fs/cgroup
[Expert@my_fwm01:0]# 



#free -m
[Expert@my_fwm01:0]# free -m
              total        used        free      shared  buff/cache   available
Mem:         191651       11183      154661        3496       25807      175861
Swap:         95464           0       95464
[Expert@my_fwm01:0]#
 



#free -mh
[Expert@my_fwm01:0]# free -mh
              total        used        free      shared  buff/cache   available
Mem:           187G         10G        151G        3.4G         25G        171G
Swap:           93G          0B         93G
[Expert@my_fwm01:0]# 


#uptime
[Expert@my_fwm01:0]# uptime
 19:04:49 up 14 days, 22:03,  6 users,  load average: 0.19, 0.31, 0.37
[Expert@my_fwm01:0]# 


 
#cpstat os
[Expert@my_fwm01:0]# cpstat os
Product Name:                  SVN Foundation
SVN Foundation Version String: R81.10
SVN Foundation Build Number:   996000057
SVN Foundation Status:         OK
OS Name:                       Gaia
OS Major Version:              3
OS Minor Version:              10
OS Build Number:               -
OS SP Major:                   -
OS SP Minor:                   -
OS Version Level:               
Appliance SN:                  XXXXXX
Appliance Name:                Smart-1 XXXXX-L
Appliance Manufacturer:        CheckPoint
[Expert@my_fwm01:0]# 


#cpinfo -y all
[Expert@my_fwm01:0]# cpinfo -y all 
This is Check Point CPinfo Build 914000227 for GAIA
[CPFC]
        No hotfixes..
[IDA]
        No hotfixes..
[MGMT]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[FW1]
        HOTFIX_NGM_DOCTOR_AUTOUPDATE
        HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
        HOTFIX_WEBCONSOLE_AUTOUPDATE
        HOTFIX_GOT_MGMT_AUTOUPDATE
        HOTFIX_GOT_TPCONF_MGMT_AUTOUPDATE
FW1 build number:
This is Check Point Security Management Server R81.10 - Build 011
This is Check Point's software version R81.10 - Build 033
[SecurePlatform]
        HOTFIX_ENDER_V17_AUTOUPDATE
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[AutoUpdater]
        No hotfixes..
[CPinfo]
        No hotfixes..
[SmartLog]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[DIAG]
        No hotfixes..
[Reporting Module]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[CPuepm]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[VSEC]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[CPDepCon]
        No hotfixes..
[CPRepMan]
        HOTFIX_R81_10_JUMBO_HF_MAIN     Take:  87
[SFWR77CMP]
        HOTFIX_R81_10_JHF_COMP  Take:  87
[SFWR80CMP]
        HOTFIX_R81_10_JHF_COMP  Take:  87
[R77CMP]
        No hotfixes..
[R8040CMP]
        HOTFIX_R81_10_JHF_COMP  Take:  87
[MGMTAPI]
        No hotfixes..
[CPUpdates]
        BUNDLE_ENDER_V17_AUTOUPDATE     Take:  21
        BUNDLE_CPVIEWEXPORTER_AUTOUPDATE        Take:  27
        BUNDLE_CPOTELCOL_AUTOUPDATE     Take:  25
        BUNDLE_CORE_FILE_UPLOADER_AUTOUPDATE    Take:  21
        BUNDLE_NGM_DOCTOR_AUTOUPDATE    Take:  15
        BUNDLE_GENERAL_AUTOUPDATE       Take:  13
        BUNDLE_INFRA_AUTOUPDATE Take:  58
        BUNDLE_DEP_INSTALLER_AUTOUPDATE Take:  25
        BUNDLE_TUNNEL_AUTOUPDATE        Take:  66
        BUNDLE_DANA_AUTOUPDATE  Take:  131
        BUNDLE_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE        Take:  19
        BUNDLE_CPSDC_AUTOUPDATE Take:  23
        BUNDLE_R81_10_JUMBO_HF_MAIN     Take:  87
        BUNDLE_DC_CONTENT_AUTOUPDATE    Take:  15
        BUNDLE_WEBCONSOLE_AUTOUPDATE    Take:  76
        BUNDLE_HCP_AUTOUPDATE   Take:  59
        BUNDLE_GOT_MGMT_AUTOUPDATE      Take:  108
        BUNDLE_GOT_TPCONF_MGMT_AUTOUPDATE       Take:  36
        BUNDLE_DC_INFRA_AUTOUPDATE      Take:  30
[itp_wrapper]
        HOTFIX_GOT_MGMT_AUTOUPDATE
[hcp_wrapper]
        HOTFIX_HCP_AUTOUPDATE
[R7540CMP]
        No hotfixes..
[R76CMP]
        No hotfixes..
[SFWR81CMP]
        No hotfixes..
[CPDepInst]
        No hotfixes..
[cpsdc_wrapper]
        HOTFIX_CPSDC_AUTOUPDATE
[sho_wrapper]
        HOTFIX_DANA_AUTOUPDATE
[infinity_onprem_wrapper]
        HOTFIX_TUNNEL_AUTOUPDATE
[core_uploader]
        HOTFIX_CHARON_HF
[CPotelcol]
        HOTFIX_OTLP_GA
[CPviewExporter]
        HOTFIX_OTLP_GA
[Expert@my_fwm01:0]# 



# clish -c "show installer packages installed"
[Expert@my_fwm01:0]# clish -c "show installer packages installed"
**  ************************************************************************* **
**                                 Hotfixes                                   **
**  ************************************************************************* **
Display name                                                                                    Type                      
R81.10 Jumbo Hotfix Accumulator General Availability (Recommended Jumbo Take 78)                Hotfix                    
R81.10 Jumbo Hotfix Accumulator Recommended Jumbo Recommended Jumbo Take 87                     Hotfix                    
**  ************************************************************************* **
**                                  Majors                                    **
**  ************************************************************************* **
Display name                                                                                    Type                      
R81.10 Gaia Fresh Install and upgrade                                                           Major Version             
[Expert@my_fwm01:0]# 

 
# cpprod_util FwIsLogServer
[Expert@my_fwm01:0]# cpprod_util FwIsLogServer

[Expert@my_fwm01:0]# 



#cpprod_util RtIsAnalyzerServer
[Expert@my_fwm01:0]# cpprod_util RtIsAnalyzerServer

[Expert@my_fwm01:0]# 


#cpprod_util RtIsAnalyzerCorrelationUnit
[Expert@my_fwm01:0]# cpprod_util RtIsAnalyzerCorrelationUnit

[Expert@my_fwm01:0]# 
 

Sunday, April 16, 2023

Understand Checkpoint RSA SecurID Authentication

 

RSA SecurID Authentication

SDCONF.REC file is generated from the RSA Authentication Manager for the Firewall MY-VPN-FW01 And it is placed in the /var/ace directory

SDOPTS.REC is a text file that contains Client_IP=100.114.255.29  (this the IP address of the Firewall member. The file is created by the System Admin.

SDSTATUS.12  this file is generated by Checkpoint and it contains information such as token passing successfully to auth manager, it records

SECURID – this is the Secret Node Key that is exchanged between the Security Gateway and RSA SecureID Server.


sdconf.rec (from Auth Manager), sdops.rec (Client_IP), sdstatus.12 (checkpoint generated token passed to RSA manager, and  securID (Secret Node Key)


"Wrong username and password" error when authenticating via SecurID

  • Users cannot authenticate with SecurID after replacing sdconf.rec file with an updated one from the RSA SecurID server, receiving "Wrong username and password" error.
  • "Node Secret mismatch: cleared on server but not on agent" message in the RSA SecurID server logs

The "securid" file (a Secret Node key that is exchanged between the Security gateway and the RSA SecurID Server) is corrupted.  sk106582


The sdopts.rec file will not be invoked

the sdopts.rec file was not being invoked by Firewall-1 because of the presence ofthe sdstatus.12 which is also in the /var/ace directory. The sdstatus.12 file takes precedence. Removing the sdstatus.12 file made the sdopts.rec take effect.

Any modification of these file will require a cpstop and cpstart on the active cluster member.



How to Download a the SDCONF.REC file 

Access –> Authentication Agent -> Generate Configuration File



RSA Authentication Manager (Auth Manager)

Authentication Manager has a WebUI, and it manages users, tokens agents and can produce reports and enforce policies like how many time. The Authentication Manager has a primary and a replica for redundancy. It is available in 2 options, software and appliance form factor. It’s main purpose is to handle user authentication requests, and also to system administration  such as users, tokens, agents, reporting, and policy and database backups 

 

Identity Router

To establish SIC with a new Checkpoint gateway and it's Management Sever

 To establish SIC with a new Checkpoint gateway and it's Management Sever 


1. The Gateway must  have CPD running in E Stat .. to validate it, you can run cpwd_admin list  if it is a T stat, you will not be able to establish SIC

[Expert@MY-VPN-FW01:0]# cpwd_admin list

APP        PID    STAT  #START  START_TIME             MON  COMMAND             
FWK_FORKER 73879  E     1       [21:37:50] 14/4/2023   N    fwk_forker          
FWK_WD     73888  E     1       [21:37:50] 14/4/2023   N    fwk_wd -i 43 -i6 0  
CPVIEWD    74765  E     1       [21:38:08] 14/4/2023   N    cpviewd             
CPVIEWS    74782  E     1       [21:38:08] 14/4/2023   N    cpview_services     
CVIEWAPIS  74787  E     1       [21:38:08] 14/4/2023   N    cpview_api_service  
SXL_STATD  74792  E     1       [21:38:08] 14/4/2023   N    sxl_statd           
CPD        74804  E     1       [21:38:08] 14/4/2023   Y    cpd                 
MPDAEMON   74816  E     1       [21:38:08] 14/4/2023   N    mpdaemon /opt/CPshrd-R81.10/log/mpdaemon.elg /opt/CPshrd-R81.10/conf/mpdaemon.conf
TP_CONF_SERVICE 230716 E     1       [00:24:39] 15/4/2023   N    tp_conf_service --conf=tp_conf.json --log=error
CXLD       75062  E     1       [21:38:10] 14/4/2023   N    cxld -d             
CI_CLEANUP 75078  E     1       [21:38:10] 14/4/2023   N    avi_del_tmp_files   
CIHS       75081  E     1       [21:38:10] 14/4/2023   N    ci_http_server -j -f /opt/CPsuite-R81.10/fw1/conf/cihs.conf
FWD        75105  E     1       [21:38:10] 14/4/2023   N    fwd                 
SPIKE_DETECTIVE 75120  E     1       [21:38:10] 14/4/2023   N    spike_detective     
DSDAEMON   158764 E     1       [01:32:16] 15/4/2023   Y    dsd                 
DASERVICE  100901 E     1       [21:39:35] 14/4/2023   N    DAService_script    
AUTOUPDATER 100918 E     1       [21:39:35] 14/4/2023   N    AutoUpdaterService.sh
CPHAMCSET  124212 E     1       [21:43:27] 14/4/2023   N    cphamcset -d        
WSDNSD     40975  E     1       [00:47:51] 15/4/2023   Y    wsdnsd              
RAD        125442 E     1       [21:43:30] 14/4/2023   N    rad                 
RTMD       125479 E     1       [21:43:31] 14/4/2023   N    rtmd                
LPD        15444  E     1       [04:34:46] 15/4/2023   N    lpd                 
[Expert@MY-VPN-FW01:0]# 

Friday, March 31, 2023

Migrate Export and Migrate Import - Checkpoint Management Server

Process for Migrating to new MGMT appliances:
  

Pre-Requisites

The Firewall Gaia version and JumboHotFix JHF Take of the Checkpoint Primary Management Server where the migrate export is taken from MUST be the same as the  Firewall Gaia version and JumboHotFix JHF Take of the NEW Checkpoint Primary Management Server

The Secondary Management server must ALSO be the same as the  Firewall Gaia version and JumboHotFix JHF Take of the NEW Checkpoint Primary Management Server. It will sync automatically with primary once the name of IPs are the same. 
  • Take a Migrate Export/Backup of the existing Primary
  • Run through the configuration Wizards, set one up as Primary, set one up as a Secondary (use same hostnames and IPs)
  • Do a Migrate Import on the new Primary
  • Swap the cables from the existing Primary with the new Primary* (make sure it says DB synchronized)
  • Power off old Secondary
  • Power on new Secondary
  • Re-establish SIC and make sure DBs synchronize

On Old/Existing Checkpoint Primary Management Server
[Expert@MGMT:0]#cd $FWDIR/bin/upgrade_tools
[Expert@MGMT:0]#yes | nohup ./migrate export /home/admin/bos0105fwm01-033123.tgz 


On NEW Checkpoint Primary Management Server (same Gaia Version and JHF and original FWM). Copy bos0105fwm01-033123.tgz  from old FWM to new FWM

[Expert@MGMT:0] cpstop
[Expert@MGMT:0]# cd $FWDIR/bin/upgrade_tools/
[Expert@MGMT:0]# yes | nohup ./migrate import  /home/admin/bos0105fwm01-033123.tgz 
[Expert@MGMT:0]# cpstart


Below are the command I ran on the test management server MGMT (100.115.22.22) and the output is  CPMGMT011-090622.tgz                                                       


[Expert@MGMT:0]# cd $FWDIR/bin/upgrade_tools
[Expert@MGMT:0]# pwd
/opt/CPsuite-R80.40/fw1/bin/upgrade_tools
[Expert@MGMT:0]# cd $HOME
[Expert@MGMT:0]# yes | nohup ./migrate export /home/admin/CPMGMT011-090622.tgz  
nohup: appending output to 'nohup.out'
[Expert@MGMT:0]#

[Expert@MGMT:0]]# ls -lt
total 2180396
-rw-rw---- 1 admin root  1026123583 Sep  6 10:48 
CPMGMT011-090622.tgz
[Expert@MGMT:0]#
 

The operations will look like this:
 
# cpstop
# cd /opt/CPsuite-R77/fw1/bin/upgrade_tools
# ./migrate export /var/log/migrate-export/sms-mig-export-20160414
 
You are required to close all clients to Security Management Server
or execute 'cpstop' before the Export operation begins.
 
Do you want to continue? (y/n) [n]?
 
Copying required files...
Compressing files...
 
The operation completed successfully.
 
Location of archive with exported database: /var/log/migrate-export/sms-mig-export-20160414.tgz
 
#cpstart
 


Run through the configuration Wizards, set one up as Primary, set one up as a Secondary (use same hostnames and IPs)

  • Connect your laptop RJ45 connection to the Checkpoint Appliance Mgmt Interface. By default, this IP address is 192.168.1.1/24.
  • Add and IPv4 IP address to the RJ45 adaptor on your laptop to 192.168.1.2 and subnet mask 255.255.255.0
  • From your laptop you should be able to ping the 192.168.1.1 and from the Checkpoint Appliance you should be able to ping the laptop IP address 192.168.1.2. 
  • If you cannot ping you may want to connect your laptop USB to Serial connection to Checkpoint appliance and login to the appliance. By default the login username and password is admin 
  • Open browser and go to https://192.168.1.1



 



Reference

Migrate Export    sk133312 - How to run a 'migrate export' or 'migrate import' command that survives a closed/timed-out SSH session

Abstract

When you run a 'migrate export' or 'migrate import' command, the command is tied to the current CLI session. When the current CLI session ends (the SSH connection times out, or is closed), the 'migrate' process is halted/canceled. 

This can also happen when the exported management database is very large (30GB or more): for example, the export of a management database of 30GB can take 3 to 4 hours to complete. This means that the CLI session (SSH session) must stay active for 3 to 4 hours.

Solution

To make sure the 'migrate export' command survives these scenarios and continues to run successfully in the background, run the command with the following syntax:


[Expert@MGMT:0]# cd $FWDIR/bin/upgrade_tools/
[Expert@MGMT:0]# yes | nohup ./migrate export [options] /<full path>/<name of exported file without any extension>

To make sure the 'migrate import' command survives these scenarios and continues to run successfully in the background, run it with the following syntax:

[Expert@MGMT:0]# cd $FWDIR/bin/upgrade_tools/
[Expert@MGMT:0]# yes | nohup ./migrate import [options] /<full path>/<name of exported file>.tgz


Migrate Export
cd $FWDIR/bin/upgrade_tools
yes | nohup ./migrate export /home/admin/bos0105fwm01-033123.tgz 


Migrate Import
cpstop
cd $FWDIR/bin/upgrade_tools/
yes | nohup ./migrate import [options] /<full path>/<name of exported file>.tgz
yes | nohup ./migrate import  /home/admin/bos0105fwm01-033123.tgz 
cpstart




In Boston DC … Upgrade Checkpoint Firewall bos0102fwm01 from R80.40 to 81.10 
1.      Snapshot back up of Firewall Management Primary  bos0102fwm01
2.      Export snapshots
3.      Migrate Export - 
3.      Install - Fresh Install and upgrade packages R80.40 to 81.10
4.      Verify Update package / Fix errors if any.
5.      Once successfully verify.
6.      Select Upgrade (not Install update)
7.      After R81.10 install completes,
8.      Run Deployment Agent - DeploymentAgent_000002205_1
9.      Install JHF – 64  (Will be installed after secondary is upgraded)
10.     Push policy –  to   Internet Firewalls, VPN etc