<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CLI on Embedded Gaia in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14408#M1019</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there many people here that use the CLI much on the small boxes like the 1100 / 1400 series?&lt;/P&gt;&lt;P&gt;I have created my own database for preping a base config for normal GAIA and have been working the last copuple of days to get the syntax on all commands we need to set the standard settings and maybe add interfaces / static routes etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was working on a job where I don't have a Internet Connection configured as the box is connected between a MPLS-trunk and some local network with a DMZ and a local LAN.&lt;/P&gt;&lt;P&gt;First thing I ran into, you cannot set a default route except for the one in the internet connection.&lt;/P&gt;&lt;P&gt;Second thing, by default the LAN ports are part of a switch, so to use&amp;nbsp; each port as a separate network port you remove the switch, then set interfaces' IP addresses however here I get an error: The settings overlap with those of another network or bridge&lt;/P&gt;&lt;P&gt;Third I cannot find the way to prepare the box for doing SIC from management (when adding a SMB cluster member you need to set SIC during the ADD process, you cannot use first connect.&lt;/P&gt;&lt;P&gt;Commands used each with their appropriate options:&lt;/P&gt;&lt;P&gt;connect security-management&amp;nbsp;&lt;/P&gt;&lt;P&gt;set log-server-configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;After this I checked through the GUI and there was nothing filled in the SIC part, so how do I setup the 1400 so it will accept a SIC request? I know on the Edge it was:&lt;/P&gt;&lt;P&gt;set smp server registrationkey &amp;lt;password&amp;gt; gatewayid &amp;lt;GW-Name&amp;gt; connect enabled&lt;/P&gt;&lt;P&gt;However that is no longer there.&lt;/P&gt;&lt;P&gt;There are multiple other things I ran into that do not work the way they are supposed to, but those are all already in the case I openend for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version I worked with is 77.20.70&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Apr 2018 21:32:45 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2018-04-11T21:32:45Z</dc:date>
    <item>
      <title>CLI on Embedded Gaia</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14408#M1019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there many people here that use the CLI much on the small boxes like the 1100 / 1400 series?&lt;/P&gt;&lt;P&gt;I have created my own database for preping a base config for normal GAIA and have been working the last copuple of days to get the syntax on all commands we need to set the standard settings and maybe add interfaces / static routes etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was working on a job where I don't have a Internet Connection configured as the box is connected between a MPLS-trunk and some local network with a DMZ and a local LAN.&lt;/P&gt;&lt;P&gt;First thing I ran into, you cannot set a default route except for the one in the internet connection.&lt;/P&gt;&lt;P&gt;Second thing, by default the LAN ports are part of a switch, so to use&amp;nbsp; each port as a separate network port you remove the switch, then set interfaces' IP addresses however here I get an error: The settings overlap with those of another network or bridge&lt;/P&gt;&lt;P&gt;Third I cannot find the way to prepare the box for doing SIC from management (when adding a SMB cluster member you need to set SIC during the ADD process, you cannot use first connect.&lt;/P&gt;&lt;P&gt;Commands used each with their appropriate options:&lt;/P&gt;&lt;P&gt;connect security-management&amp;nbsp;&lt;/P&gt;&lt;P&gt;set log-server-configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;After this I checked through the GUI and there was nothing filled in the SIC part, so how do I setup the 1400 so it will accept a SIC request? I know on the Edge it was:&lt;/P&gt;&lt;P&gt;set smp server registrationkey &amp;lt;password&amp;gt; gatewayid &amp;lt;GW-Name&amp;gt; connect enabled&lt;/P&gt;&lt;P&gt;However that is no longer there.&lt;/P&gt;&lt;P&gt;There are multiple other things I ran into that do not work the way they are supposed to, but those are all already in the case I openend for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version I worked with is 77.20.70&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 21:32:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14408#M1019</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-04-11T21:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: CLI on Embedded Gaia</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14409#M1020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For your last question, there is a script called sic_init.sh (available in Expert mode) that appears to allow you to set the SIC password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 10:58:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14409#M1020</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-12T10:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: CLI on Embedded Gaia</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14410#M1021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Damien, with that I found the most simple command to get the SIC Password set:&lt;/P&gt;&lt;P&gt;fw sic_init &amp;lt;password&amp;gt;&lt;/P&gt;&lt;P&gt;Which can be run from clish as well, so yep this one saved the day.&lt;/P&gt;&lt;P&gt;all the other issues I found are quite problematic but also there for most I found workarounds. Like when you remove the LAN1_Switch from the command line you need to reboot before you can assign IP's to any of the interfaces, so we came with a set of commands to execute before upgrading to the latest firmware, then (automatic) reboot and then continue with the set interface ipa-address commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 16:56:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14410#M1021</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-04-12T16:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: CLI on Embedded Gaia</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14411#M1022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to add that i have published much about autoconf.clish here already - see for example &lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2634-usb-first-time-config-using-autoconfclish-files-how-it-is-written"&gt;&lt;EM&gt;USB First Time Config using autoconf.clish files&amp;nbsp; - How it is written&lt;/EM&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2018 07:17:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-on-Embedded-Gaia/m-p/14411#M1022</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-19T07:17:34Z</dc:date>
    </item>
  </channel>
</rss>

