Checkpoint FW Configuration

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • good_guy_id911
    Member
    • Oct 2003
    • 2

    #1

    Checkpoint FW Configuration

    Hi Folks.,

    anyone know how to obtain Checkpoint Firewall COnfiguration file from shell mode.
    What File should I copy ?
    I am using Checkpoint NG running in solaris 5.8 OS.

    Thanks,
    --good_guy_id911--
  • noid
    Fun Enforcement Agent
    • Oct 2001
    • 2394

    #2
    Its driving me crazy that I can't remember the name of the file. Check out www.phoneboy.com and blog.phoneboy.com for what is probably the best and most comprehensive CP FW-1 site on the net. There's more info there than in CP's own SecureKnowledge database.

    I return whatever i wish . Its called FREEDOWM OF RANDOMNESS IN A HECK . CLUSTERED DEFEATED CORn FORUM . Welcome to me

    Comment

    • yankee
      Transmutation
      • May 2003
      • 113

      #3
      I think it's these two files (someone check me on this):

      $FWDIR/conf/objects.C

      and either

      $FWDIR/conf/rulebasename.fws (Windows)
      $FWDIR/conf/rulebasename.W (UNIX)

      They're stored in some sort of CP proprietary scripting language (I think call "inspect script"). To convert it, you may want to look at:

      http://sourceforge.net/projects/cp2fwbuilder/
      Last edited by yankee; October 6, 2003, 12:13.

      Comment

      • noid
        Fun Enforcement Agent
        • Oct 2001
        • 2394

        #4
        it is in its own scripting lang, but its fairly easy to pick out whats happening in the file.

        I return whatever i wish . Its called FREEDOWM OF RANDOMNESS IN A HECK . CLUSTERED DEFEATED CORn FORUM . Welcome to me

        Comment

        • good_guy_id911
          Member
          • Oct 2003
          • 2

          #5
          well, thanks., guys..


          --good_guy_id911--

          Comment

          • kraa26
            Bot Master
            • Aug 2003
            • 36

            #6
            Originally posted by yankee
            I think it's these two files (someone check me on this):

            $FWDIR/conf/objects.C

            and either

            $FWDIR/conf/rulebasename.fws (Windows)
            $FWDIR/conf/rulebasename.W (UNIX)

            They're stored in some sort of CP proprietary scripting language (I think call "inspect script"). To convert it, you may want to look at:

            http://sourceforge.net/projects/cp2fwbuilder/
            Your right.... objects.C is all the NAT'd objects and special objects created in Checkpoint..

            rulebasename.W is your rules... I use these to "toggle" some firewall policies.
            Kraa: You are Slackware Linux. You are the brightest among your peers, but are often mistaken as insane. Your elegant solutions to problems often take a little longer, but require much less effort to complete.

            Comment

            Working...