<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connecting to vSEC in AWS using WinSCP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6937#M299</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In Gaia, various OS-level configuration files are maintained in a central configuration database.&lt;/P&gt;&lt;P&gt;You manipulate that database using the WebUI and clish, which in turn talks to confd, which updates the various configuration files periodically.&lt;/P&gt;&lt;P&gt;If you use&amp;nbsp;a Linux command like&amp;nbsp;chsh to change the shell, it only updates the OS configuration file, not the Gaia configuration.&lt;/P&gt;&lt;P&gt;As such, those changes are subject to get overwritten.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Oct 2017 16:26:21 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-10-02T16:26:21Z</dc:date>
    <item>
      <title>Connecting to vSEC in AWS using WinSCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6934#M296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had to extract the cpinfo from the vSEC on AWS.&lt;/P&gt;&lt;P&gt;For some reason, using # chsh -s /bin/bash , while successfully changing the shell in session, had no effect for WinSCP, as it continue to complain about shell every time I was trying to connect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running cpinfo with -z option on vSEC did not produce the compressed file.&lt;/P&gt;&lt;P&gt;had to compress it manually, move it to /var/CPbackup/backups/ and download via WebUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was not sure about the integrity of the resultant file and ended up enabling&lt;/P&gt;&lt;P&gt;"Global Properties/Security Management/Improve product experience by sending information to Check Point" and running cpinfo on vSEC again with upload to SR parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While this approach is acceptable in the lab, it hardly is optimal for production environments.&lt;/P&gt;&lt;P&gt;It would be nice to have the option of uploading cpinfo from selected vSECs to SR without changing Global Settings and pushing policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if there is a better solution than the one I've ended-up using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Oct 2017 17:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6934#M296</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-10-01T17:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to vSEC in AWS using WinSCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6935#M297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to change the shell a user uses (eg for SCP), you need to do it in the Gaia WebUI or in clish.&lt;/P&gt;&lt;P&gt;In clish, the commands are:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG style="font-family: 'andale mono', monospace;"&gt;set user username shell /bin/bash&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;STRONG style="font-family: 'andale mono', monospace;"&gt;save config&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Oct 2017 18:30:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6935#M297</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-01T18:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to vSEC in AWS using WinSCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6936#M298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Can you explain the difference between the effect of changing shell using chsh -s /bin/bash and set username shell /bin/bash &amp;nbsp;for SCP and when each of those is preferable?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was a discussion some time ago about creating a dedicated account for scp access, but there were caveats as to its ability to access the files created by different users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Oct 2017 21:07:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6936#M298</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-10-01T21:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to vSEC in AWS using WinSCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6937#M299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In Gaia, various OS-level configuration files are maintained in a central configuration database.&lt;/P&gt;&lt;P&gt;You manipulate that database using the WebUI and clish, which in turn talks to confd, which updates the various configuration files periodically.&lt;/P&gt;&lt;P&gt;If you use&amp;nbsp;a Linux command like&amp;nbsp;chsh to change the shell, it only updates the OS configuration file, not the Gaia configuration.&lt;/P&gt;&lt;P&gt;As such, those changes are subject to get overwritten.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Oct 2017 16:26:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6937#M299</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-02T16:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to vSEC in AWS using WinSCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6938#M300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to understand what conditions would cause the changes in shell to be overridden.&amp;nbsp; I have not used the CLISH commands only the Linux chsh command haven't had an issue, yet.&amp;nbsp; Now I am a little concerned.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Oct 2017 18:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6938#M300</guid>
      <dc:creator>Eduardo_Aguila</dc:creator>
      <dc:date>2017-10-02T18:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to vSEC in AWS using WinSCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6939#M301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Two specific ones I can think of:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Anything you do in the Gaia WebUI around user accounts&lt;/P&gt;&lt;P&gt;2. A reboot (all config files are refreshed)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Oct 2017 18:19:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6939#M301</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-02T18:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to vSEC in AWS using WinSCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6940#M302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience, managing on-premises appliances we've never had any issues with using chsh. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First time I have encountered it was connecting to AWS vSEC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlad@eversecgroup.com&lt;/P&gt;&lt;P&gt;+1.973.558.2738&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Oct 2017 18:20:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Connecting-to-vSEC-in-AWS-using-WinSCP/m-p/6940#M302</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-10-02T18:20:50Z</dc:date>
    </item>
  </channel>
</rss>

