Firewall Kernel Parameters
To change the internal default behavior of Firewall or to configure special advanced settings for Firewall, you can use Firewall kernel parameters.
The names of applicable Firewall kernel parameters and their values appear in various SK articles in Check Point Support Center, and provided by Check Point Support.
|
Type |
Name |
|---|---|
|
Integer |
|
|
String |
|
Working with Integer Kernel Parameters
|
|
Important - This change does not survive reboot. |
|
Step |
Instructions |
||||
|---|---|---|---|---|---|
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
||||
|
2 |
Log in to Gaia Clish or the Expert mode. Note - On Scalable Platforms, you must run the applicable commands in Gaia gClish or the Expert mode of the applicable Security Group. |
||||
|
3 |
Configure the new value for an integer kernel parameter:
Example:
|
||||
|
4 |
Make sure the new value is configured.
Example:
|
To make a kernel parameter configuration permanent (to survive reboot), you must edit the configuration file:
|
|
The exact parameters appear in various SK articles in Check Point Support Center, and provided by Check Point Support.
|
Step |
Instructions |
|||||
|---|---|---|---|---|---|---|
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
|||||
|
2 |
Log in to the Expert mode. |
|||||
|
3 |
Back up the current configuration file, if it exists:
|
|||||
|
4 |
Configure the required Firewall kernel parameter with the assigned value in the exact format specified below.
Example:
|
|||||
|
5 |
Examine the configuration file.
|
|||||
|
6 |
Reboot.
|
|||||
|
7 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
|||||
|
8 |
Log in to Gaia Clish or the Expert mode. Note - On Scalable Platforms, you must run the applicable commands in Gaia gClish or the Expert mode of the applicable Security Group. |
|||||
|
9 |
Make sure the new value of the kernel parameter is configured.
|
For more information, see sk26202: Changing the kernel global parameters for Check Point Security Gateway.
|
Step |
Instructions |
||||
|---|---|---|---|---|---|
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
||||
|
2 |
Log in to the Expert mode. |
||||
|
3 |
See if the configuration file already exists.
|
||||
|
4 |
If this file already exists, skip to Step 5. If this file does not exist, then create it manually and then skip to Step 6.
|
||||
|
5 |
Back up the current configuration file.
|
||||
|
6 |
Edit the current configuration file. The same syntax applies to the Security Gateway / each Cluster Member and the Scalable Platform Security Group:
|
||||
|
7 |
Add the required Firewall kernel parameter with the assigned value in the exact format specified below.
|
||||
|
8 |
Save the changes in the file and exit the editor. |
||||
|
9 |
On the Scalable Platform Security Group, copy the updated configuration file to all other Security Group Members
|
||||
|
10 |
Reboot.
|
||||
|
11 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
||||
|
12 |
Log in to Gaia Clish or the Expert mode. Note - On Scalable Platforms, you must run the applicable commands in Gaia gClish or the Expert mode of the applicable Security Group. |
||||
|
13 |
Make sure the new value of the kernel parameter is configured.
|
Working with String Kernel Parameters
|
Step |
Instructions |
||||
|---|---|---|---|---|---|
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
||||
|
2 |
Log in to Gaia Clish or the Expert mode. Note - On Scalable Platforms, you must run the applicable commands in Gaia gClish or the Expert mode of the applicable Security Group. |
||||
|
3 |
Get the current value of a string kernel parameter:
Example:
|
|
|
Important - This change does not survive reboot. |
|
Step |
Instructions |
|||||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
|||||||||
|
2 |
Log in to Gaia Clish or the Expert mode. Note - On Scalable Platforms, you must run the applicable commands in Gaia gClish or the Expert mode of the applicable Security Group. |
|||||||||
|
3 |
Configure the new value for a string kernel parameter.
Example:
|
|||||||||
|
4 |
Make sure the new value is configured.
Example:
|
To make a kernel parameter configuration permanent (to survive reboot), you must edit one of the applicable configuration file:
|
|
The exact parameters appear in various SK articles in Check Point Support Center, and provided by Check Point Support.
|
Step |
Instructions |
|||||||
|---|---|---|---|---|---|---|---|---|
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
|||||||
|
2 |
Log in to the Expert mode. |
|||||||
|
3 |
Back up the current configuration file, if it exists:
|
|||||||
|
4 |
Configure the required Firewall kernel parameter with the assigned value in the exact format specified below.
Example:
|
|||||||
|
5 |
Examine the configuration file.
|
|||||||
|
6 |
Reboot.
|
|||||||
|
7 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
|||||||
|
8 |
Log in to Gaia Clish or the Expert mode. Note - On Scalable Platforms, you must run the applicable commands in Gaia gClish or the Expert mode of the applicable Security Group. |
|||||||
|
9 |
Make sure the new value of the kernel parameter is configured.
|
For more information, see sk26202: Changing the kernel global parameters for Check Point Security Gateway.
|
Step |
Instructions |
||||||
|---|---|---|---|---|---|---|---|
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
||||||
|
2 |
Log in to the Expert mode. |
||||||
|
3 |
See if the configuration file already exists.
|
||||||
|
4 |
If this file already exists, skip to Step 5. If this file does not exist, then create it manually and then skip to Step 6.
|
||||||
|
5 |
Back up the current configuration file.
|
||||||
|
6 |
Edit the current configuration file. The same syntax applies to the Security Gateway / each Cluster Member and the Scalable Platform Security Group:
|
||||||
|
7 |
Add the required kernel parameter with the assigned value in the exact format specified below.
or
|
||||||
|
8 |
Save the changes in the file and exit the editor. |
||||||
|
9 |
On the Scalable Platform Security Group, copy the updated configuration file to all other Security Group Members:
|
||||||
|
10 |
Reboot.
|
||||||
|
11 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
||||||
|
12 |
Log in to Gaia Clish or the Expert mode. Note - On Scalable Platforms, you must run the applicable commands in Gaia gClish or the Expert mode of the applicable Security Group. |
||||||
|
13 |
Make sure the new value of the kernel parameter is configured.
|
|
|
Important - This change does not survive reboot. |
|
Step |
Instructions |
|||||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
1 |
Connect to the command line on your Security Gateway or Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
|||||||||
|
2 |
Log in to Gaia Clish or the Expert mode. Note - On Scalable Platforms, you must run the applicable commands in Gaia gClish or the Expert mode of the applicable Security Group. |
|||||||||
|
3 |
Clear the current value from a string kernel parameter:
Example:
|
|||||||||
|
4 |
Make sure the value is cleared (the new value is empty):
Example:
|
Viewing the List of All Kernel Parameters and Their Values
|
Step |
Instructions |
|
|---|---|---|
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms, you must connect to the Gaia Portal of the applicable Security Group. |
|
|
2 |
Log in to the Expert mode. |
|
|
3 |
Reset the kernel debug options:
|
|
|
3 |
Allocate the kernel debug buffer:
|
|
|
3 |
Start the kernel debug in the background:
|
|
|
3 |
Enable the special kernel parameter to print the current values of all kernel parameters:
|
|
|
3 |
Wait for 30 seconds. |
|
|
3 |
Reset the kernel debug options:
|
|
|
4 |
Refer to the output file:
|