Avatar of ICresswell
ICresswell

asked on 

Cisco Security Manager revision control

We are in the process of migrating our network from checkpoint to cisco and I was wondering if there is anything similar on CSM to Checkpoints Revision control where the config can be reversed up if there is a problem with any change?
Hardware FirewallsRoutersCisco

Avatar of undefined
Last Comment
Ernie Beek
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Well, with cisco any changes made to the configuration are effective immediately. The ASA stores them in the running config. If anything breaks because of the changes, reload the firewall and it will reboot using the startup config.
When saving configuration changes, what you do is copying the running config to the startup config.
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

One nice feature is, when configuring the ASA remotly, the use of the command reload in xx.
This will cause the firewall to reboot in xx minutes. If you make any changes that lock you out, just wait for xx minutes. Then the ASA will reboot and load it's startup config so you can connect again.
Avatar of ICresswell
ICresswell

ASKER

Thanks erniebeek, although my experience has been that when a policy is pushed down to the router or firewall the config is written and saved to the device.
As a test I made a small change to the config from the CSM and did a reload in 10 on the router but once reloaded the change was still there.
I am pushing the changes down via "submit and deploy", is there a different way to push the changes down that does not cause it to write the config?
ASKER CERTIFIED SOLUTION
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of ICresswell
ICresswell

ASKER

excellent, thanks very much!
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Gald I could help, thx for the points :)
Avatar of ICresswell
ICresswell

ASKER

my only concern with the configuration archive is if you submit a config that accidentally denies access you can't get on to recover the configuration whereas with reload in x at least you always knew you could gain access if you made a mistake.
Avatar of Ernie Beek
Ernie Beek
Flag of Netherlands image

Correct, haven't found a way in CSM to do that yet :-~
Routers
Routers

A router is a networking device that forwards data packets between computer networks. Routers perform the "traffic directing" functions on the Internet. The most familiar type of routers are home and small office cable or DSL routers that simply pass data, such as web pages, email, IM, and videos between computers and the Internet. More sophisticated routers, such as enterprise routers, connect large business or ISP networks up to the powerful core routers that forward data at high speed along the optical fiber lines of the Internet backbone. Though routers are typically dedicated hardware devices, use of software-based routers has grown increasingly common.

49K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo