<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HowTo - Creating an scpuser account on Gaia Clish in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5819#M211</link>
    <description>&lt;DIV&gt;
&lt;P&gt;&lt;IMG style="width: auto; height: auto; display: block; margin-left: auto; margin-right: auto;" class="image-1 j-img-centered jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58360_pastedImage_3.png" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;While reviewing Check Point installations I often encounter setups where the shell of the &lt;STRONG&gt;admin&lt;/STRONG&gt; user account was changed to &lt;STRONG&gt;/bin/bash&lt;/STRONG&gt; in order to allow copying documents via &lt;EM&gt;scp&lt;/EM&gt; to and from Check Point Gaia systems.&lt;/P&gt;
&lt;P&gt;This is because the &lt;STRONG&gt;scponly shell&lt;/STRONG&gt; isn't known.&lt;/P&gt;
&lt;P&gt;Follow these steps to create an &lt;STRONG&gt;scpuser&lt;/STRONG&gt; for copying documents securely without compromising your admin account.&lt;/P&gt;
&lt;P&gt;[ R7x ]&lt;/P&gt;
&lt;LI-CODE lang="c"&gt;add user scpuser uid 2600 homedir /home/scpuser
set user scpuser shell /usr/bin/scponly
set user scpuser password
save config‍‍‍‍‍‍‍‍&lt;/LI-CODE&gt;
&lt;P&gt;[ R8x ]&lt;/P&gt;
&lt;LI-CODE lang="c"&gt;add user scpuser uid 2600 homedir /home/scpuser
set user scpuser realname Scpuser
add rba role scpRole domain-type System readwrite-features expert
add rba user scpuser roles scpRole
set user scpuser gid 100 shell /usr/bin/scponly
set user scpuser password
save config‍‍‍‍‍‍‍‍‍‍‍‍‍‍&lt;/LI-CODE&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 23 Apr 2026 07:13:04 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2026-04-23T07:13:04Z</dc:date>
    <item>
      <title>HowTo - Creating an scpuser account on Gaia Clish</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5819#M211</link>
      <description>&lt;DIV&gt;
&lt;P&gt;&lt;IMG style="width: auto; height: auto; display: block; margin-left: auto; margin-right: auto;" class="image-1 j-img-centered jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58360_pastedImage_3.png" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;While reviewing Check Point installations I often encounter setups where the shell of the &lt;STRONG&gt;admin&lt;/STRONG&gt; user account was changed to &lt;STRONG&gt;/bin/bash&lt;/STRONG&gt; in order to allow copying documents via &lt;EM&gt;scp&lt;/EM&gt; to and from Check Point Gaia systems.&lt;/P&gt;
&lt;P&gt;This is because the &lt;STRONG&gt;scponly shell&lt;/STRONG&gt; isn't known.&lt;/P&gt;
&lt;P&gt;Follow these steps to create an &lt;STRONG&gt;scpuser&lt;/STRONG&gt; for copying documents securely without compromising your admin account.&lt;/P&gt;
&lt;P&gt;[ R7x ]&lt;/P&gt;
&lt;LI-CODE lang="c"&gt;add user scpuser uid 2600 homedir /home/scpuser
set user scpuser shell /usr/bin/scponly
set user scpuser password
save config‍‍‍‍‍‍‍‍&lt;/LI-CODE&gt;
&lt;P&gt;[ R8x ]&lt;/P&gt;
&lt;LI-CODE lang="c"&gt;add user scpuser uid 2600 homedir /home/scpuser
set user scpuser realname Scpuser
add rba role scpRole domain-type System readwrite-features expert
add rba user scpuser roles scpRole
set user scpuser gid 100 shell /usr/bin/scponly
set user scpuser password
save config‍‍‍‍‍‍‍‍‍‍‍‍‍‍&lt;/LI-CODE&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 23 Apr 2026 07:13:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5819#M211</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2026-04-23T07:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo - Creating an scpuser account on Gaia Clish</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5820#M212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good tip, but I'm going to move it to the &lt;A href="https://community.checkpoint.com/community/infinity-general/appliances-and-gaia?sr=search&amp;amp;searchId=12a9c53d-212e-45ec-be2d-434e5ee01d24&amp;amp;searchIndex=1" target="_blank"&gt;https://community.checkpoint.com/community/infinity-general/appliances-and-gaia?sr=search&amp;amp;searchId=12a9c53d-212e-45ec-be2d-434e5ee01d24&amp;amp;searchIndex=1&lt;/A&gt;‌ forum &lt;IMG id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 08:57:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5820#M212</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-21T08:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo - Creating an scpuser account on Gaia Clish</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5821#M213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Indeed it is very good tip, however you have to tweak little bit group permissions I believe... The reason is that if you create a capture with tcpdump (with admin user) and then try to download it via scp (using scpuser) you will not be allowed. I have faced something similar recently.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Sep 2017 13:51:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5821#M213</guid>
      <dc:creator>Astardzhiev</dc:creator>
      <dc:date>2017-09-04T13:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo - Creating an scpuser account on Gaia Clish</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5822#M214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've adopted an old-school approach to the inability to read/write.&amp;nbsp; When creating the home directory for the scp user, I make sure to `chmod g+s` that directory.&amp;nbsp;&amp;nbsp; This causes all subsequent files created there to be created with the group assigned to the directory rather than the group of the creating user.&amp;nbsp; Then when a tcpdump or similar is created, I specify the scp user's home directory as the path for the file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Similarly, I only scp to the scp user's home directory and then move files around with the expert user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Sep 2017 13:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5822#M214</guid>
      <dc:creator>Quinn_Yost</dc:creator>
      <dc:date>2017-09-05T13:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo - Creating an scpuser account on Gaia Clish</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5823#M215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Enabling&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;SFTP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This alternative example describes how to enable SFTP access on a Security Gateway using the default “admin” account. Note: a Security Policy must already contain a rule that allows connections via SSH.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. Connect via command line using the default “admin" account&lt;BR /&gt;2. Navigate to expert mode&lt;BR /&gt;3. Backup the current /etc/ssh/sshd_config file&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color: #3366ff;"&gt;cp /etc/ssh/sshd_config /etc/ssh/sshd_config_original&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Edit the current /etc/ssh/sshd_config file:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vi /etc/ssh/sshd_config&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;5. Below the sftp line&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3366ff;"&gt;#Subsystem sftp /usr/libexec/openssh/sftp-server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3366ff;"&gt;Subsystem sftp internal-sftp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;6. Save the changes and exit from vi editor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7. Restart the SSHD daemon&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #3366ff;"&gt;/sbin/service sshd restart&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;8. Now you can connect with the gateway with an SFTP client using TCP port 22.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Oct 2017 20:07:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/5823#M215</guid>
      <dc:creator>Markusevc</dc:creator>
      <dc:date>2017-10-14T20:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo - Creating an scpuser account on Gaia Clish</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/53316#M4046</link>
      <description>&lt;P&gt;Thanks Danny.&lt;/P&gt;&lt;P&gt;That helps.&lt;/P&gt;&lt;P&gt;Wow R80.xx really changes a few stuffs &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 13:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/53316#M4046</guid>
      <dc:creator>Alex_Lam1</dc:creator>
      <dc:date>2019-05-13T13:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo - Creating an scpuser account on Gaia Clish</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/62845#M4804</link>
      <description>But what to do with permissions? Do you allow scpuser read access to /var/log? Do you create a specific folder, that belongs to scpuser? Manually setting permissions might be cumbersome.</description>
      <pubDate>Mon, 16 Sep 2019 08:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/62845#M4804</guid>
      <dc:creator>Denis_Spirin</dc:creator>
      <dc:date>2019-09-16T08:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: HowTo - Creating an scpuser account on Gaia Clish</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/62857#M4806</link>
      <description>&lt;P&gt;This is a real relevation for Mac OS users - now we can connect using Cyberduck instead of WinSCP !&lt;/P&gt;
&lt;P&gt;Is this sftp server also available on Embedded GAiA units ?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 07:22:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HowTo-Creating-an-scpuser-account-on-Gaia-Clish/m-p/62857#M4806</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-17T07:22:01Z</dc:date>
    </item>
  </channel>
</rss>

