vsx_util reconfigure

Description

Restores VSX configuration on a VSX Gateway or VSX Cluster Member (for example, after you perform clean install after a system failure).

Syntax

vsx_util reconfigure

Important - Before you run the vsx_util commands:

  • Back up the VSX environment. See sk100395: How to backup and restore VSX gateway.

  • You must close all SmartConsole clients. Failure to do so may result in a database lock error.

  • On a Multi-Domain Security Management Server, you must switch to the context of the Main Domain Management Server that manages the VSX Gateway / VSX Cluster object.

    Use the command "mdsenv <IP Address or Name of Domain Management Server>".

Important - Before you run this command on the Management Server, you must configure specific settings on the cleanly installed VSX Gateway or VSX Cluster Member as they were:

  • IP address of Gaia management interface

  • Enable IPv6 support in Gaia

  • Configure the applicable interfaces (Bond, VLAN, and so on)

  • Configure kernel parameters and their values:

    • $FWDIR/boot/modules/fwkern.conf

    • $FWDIR/boot/modules/vpnkern.conf

    • $PPKDIR/conf/simkern.conf

  • Configure CoreXL:

    • Number of CoreXL Firewall instances (for IPv4 and IPv6) in the context of VS0 (run the cpconfig command and select the option Check Point CoreXL)

    • $FWDIR/conf/fwaffinity.conf

Required Input

  • The applicable VSX Gateway or VSX Cluster object.

  • The one-time Activation Key (SIC activation key).

Comments

  • Execute the command and follow the instructions on the screen.

  • The new VSX Gateway or VSX Cluster Member:

    • Must be a new installation.

      You cannot use a VSX Gateway or VSX Cluster Member with a previous VSX configuration.

    • Must have the same hardware specifications as the original.

      Most importantly, it must have at least the same number of interfaces.

    • Must have the same Gaia OS configuration as the original.

      Most importantly, it must have the same VSX Management IP address.

Limitations

The reconfigure process does not restore the local configuration that was performed on VSX Gateway or VSX Cluster Member itself (because this configuration is not stored on the Management Server).

Important - After the reconfigure process is complete and you rebooted VSX Gateway or VSX Cluster Member, you must manually configure these settings from scratch or from backed up files.

These settings and files are not restored during the reconfigure process and you must manually configure them again:

  • Any OS configuration (for example, DNS, NTP, DHCP, Dynamic Routing, DHCP Relay, and so on).

  • Backup files and Gaia snapshots saved in the past on the VSX Gateway or VSX Cluster Member.

  • Any settings manually defined in various configuration files on the VSX Gateway or VSX Cluster Member.

  • Any Check Point configuration files.

    Note - Some of these files do not exist by default. Some files are configured on each VSX Gateway and VSX Cluster Member, and some files are configured for each Virtual System.