Firewall Wizards mailing list archives

Re: Sun/Solaris Checkpoint FW-1 Question


From: Steffen Kluge <kluge () fujitsu com au>
Date: Thu, 24 Jun 2004 10:47:29 +1000

On Thu, 2004-06-24 at 03:39, Alex Bihlmaier wrote:
One of my customers is using the Checkpoint FW-1 Firewall and has a
relativly large ruleset. (large as in large for just typing it down)

I want to get a ASCII (or any other format, netfilter, pf) output of the
running rules for backup purposes.

The FW-1 rule set is natively kept in ASCII format already. To back it
up, save the objects.C and *.W files, or better yet the whole FW1
directory (there are other files that may or may not be important in
your case).

For documentation purposes, you might try the fwrules Perl script
(google around or find it on Phoneboy's website). It nicely formats the
rule set and object definitions as HTML page, and can be told to format
into arbitrary templates as well.

Cheers
Steffen.

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: