NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] preserve state table over reboot?



Title: RE: [FW-1] preserve state table over reboot?

That's a very good question, and I don't know the answer. :)  Read on, though...

Since the state tables are implemented as dynamic hashes in kernel memory, that is awfully hard to do with just one box.  You can dump the table contents in hex using fw tab, but I don't know of a way to re-inject this information.  The most common way of handling this is to configure HA with state table synchronization.  In this manner, as long as one of the boxes stays up, the table is preserved.  If you don't need HA (and you have lots of money :), you could configure a "standby" firewall with no reachable interfaces, and just run a crossover on a dummy network to the "real" firewall, using the "standby" exclusively for state table maintenance.

HTH - please post with further comments.  Thanks!

Dan Hitchcock
CCNP, CCSE, MCSE
Security Analyst
Breakwater Security Associates, Inc.
"Safe Harbor for E-Business"
dhitchcock (at) breakwatersecurity (dot) com
http://www.breakwatersecurity.com
work

The information contained in this email message may be privileged, confidential and protected from disclosure.  If you are not the intended recipient, any dissemination, distribution or copying is strictly prohibited.  If you think you have received this email message in error, please email the sender at [email protected]


-----Original Message-----
From: Bernd Leibing [mailto:[email protected]]
Sent: Friday, December 07, 2001 1:36 AM
To: [email protected]
Subject: [FW-1] preserve state table over reboot?


I'm running FW-1 4.1 SP5 on Redhat Linux,

does anyone know if its possible to save the state table and reread it
after reboot?

Thanks!

Bernd Leibing

===============================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
===============================================

=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
If you have any questions on how to change your
subscription options, email Ron Alcatraz at:
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.