<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blink, anyone ? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28688#M98073</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We successfully started using Blink!&lt;/P&gt;&lt;P&gt;We did build some wrappers around it but with these wrappers, it has worked extremely well. The only issue, if you can even call it an issue, revolves around the original "factory image" remaining. Though we don't really see a need to "factory reset" a gateway any longer, since it can re-Blink'd at any time. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The wrappers we built:&lt;/P&gt;&lt;P&gt;1) Fresh re-image with R77.30 w/ basic pre-built clish commands (ie, password, snmp, ntp, etc..)&lt;/P&gt;&lt;P&gt;2) Fresh re-image with R80.10 w/ basic&amp;nbsp;&lt;SPAN&gt;pre-built clish commands&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3) Upgrade/re-image from R77.30 to R80.10 while re-applying clish statements dynamically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did need to build "two" sets of wrappers for each, as we needed to handle clusters vs single GW installs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our internal process already requires new or firewall replacements be built with option 1 or 2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Option 3, we successfully proved this with a few remote site upgrades and plan to perform all upgrades using this method with Cavaets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you ever tried to fresh re-image a 2200 (via usbboot), run first-time wizard, then Jumbo HotFix, you will be happy to hear we have averaged Blink completing all these steps within 8 mins on this model.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cavaet: Our company best practice is to avoid any customization's of files in expert mode. Making it much easier for us to deploy or re-deploy firewalls using only the saved CLISH configurations. While we are using this method for upgrading from R77.30 to R80.10, keep in mind those expert mode customization's are not retained.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Jun 2018 18:57:31 GMT</pubDate>
    <dc:creator>Jose_Rivera</dc:creator>
    <dc:date>2018-06-07T18:57:31Z</dc:date>
    <item>
      <title>Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28672#M98057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class=""&gt;The &lt;EM&gt;sk120193 Blink - Gaia Fast Deployment&lt;/EM&gt; gives details and tools for easy deployment of &lt;EM&gt;cleanly installed&lt;/EM&gt; Check Point R77.30 or R80.10 &lt;STRONG&gt;Security Gateways. &lt;/STRONG&gt;Has anyone used this method already and what were the experiences with it, also compared to deployment with isomorpic ?&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Feb 2018 14:15:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28672#M98057</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-02-08T14:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28673#M98058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With Blink you can deploy your gateway (including Jumbo HF) in ~&lt;STRONG&gt;5 minutes&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Images are available in the SK with or without the Jumbo HF.&lt;/P&gt;&lt;P&gt;Blinks also provides you the option to download the latest updates for Anti-Bot, Application control, URL Filtering and CPUSE Deployment Agent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Feb 2018 14:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28673#M98058</guid>
      <dc:creator>Anat_Eytan-Davi</dc:creator>
      <dc:date>2018-02-08T14:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28674#M98059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the comment - but i would be very interested in feeedback from people who have used this new method in deployment already.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Feb 2018 15:19:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28674#M98059</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-02-08T15:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28675#M98060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm waiting for someone to &lt;A href="https://www.youtube.com/watch?v=ByPrDPbdRhc"&gt;blink&lt;/A&gt;...&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="j-img-floatstart image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62935_angelcu.jpg" style="width: 320px; height: 181px; float: left;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, I would like to try it out soon during a replacement of gateways. Sound pretty good and easy.&amp;nbsp;I just would like to read some more technical details about this whole process. Of course, the best way is just to try it myself, but I don't have spare appliances for now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;I&amp;nbsp;wonder what happens with the installation files that I copy to the gateway during and after installation if I use&amp;nbsp;&lt;SPAN style="font-size: 13px; font-family: terminal, monaco, monospace;"&gt;--reimage --delete-old-partition&lt;/SPAN&gt; keys. I thinking about the following scenario we received a new appliance with some image, maybe it was already initialized, I want to fully reinstall the image to R77.30+Take_292. So, I put all required files into&amp;nbsp;/var/log/blink directory and start it with&amp;nbsp;&lt;SPAN&gt;&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 13px;"&gt;--reimage --delete-old-partition keys&lt;/SPAN&gt;. As I understand it should fully reinstall the image, as if I started new installation from USB. It should delete old partitions and not leave any snapshot. So are the blink files transferred somewhere or just nothing happens to the whole &lt;SPAN style="font-size: 13px; font-family: terminal, monaco, monospace;"&gt;/var/log&lt;/SPAN&gt; directory? What happens to the initial and extracted files (&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 13px;"&gt;/var/log/blink/launcher/files&lt;/SPAN&gt;) after installation? There is information about new blink partitions (Remove blink new partition: &lt;SPAN style="font-size: 13px; font-family: terminal, monaco, monospace;"&gt;lv_remove vg_splat lv_fcd_new&lt;/SPAN&gt;), then&amp;nbsp;what should happen with them after normal installation?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Feb 2018 17:52:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28675#M98060</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-02-08T17:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28676#M98061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeah, I'm not going to look at that youtube video, I would &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you create a new directory &lt;STRONG&gt;/var/log/MyDir&lt;/STRONG&gt;, copy the files and run blink from there with the parameters &lt;STRONG&gt;--reimage --delete-old-partition&lt;/STRONG&gt;, then it would extract the &lt;STRONG&gt;blink_image_&amp;lt;version&amp;gt;.tgz&lt;/STRONG&gt; and &lt;STRONG&gt;blink_updates_&amp;lt;version&amp;gt;.tgz&lt;/STRONG&gt; files to the &lt;STRONG&gt;/var/log/blink/launcher/files/&lt;/STRONG&gt; directory. When the &lt;STRONG&gt;BlinkInstaller&lt;/STRONG&gt; engine runs it merges &lt;STRONG&gt;/var/log&lt;/STRONG&gt; so you'll still have &lt;STRONG&gt;/var/log/MyDir&lt;/STRONG&gt; and &lt;STRONG&gt;/var/log/blink/launcher/files&lt;/STRONG&gt; at the end of&amp;nbsp; the run.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When blink is run without any flags, the default is to NOT create a snapshot. The -&lt;STRONG&gt;-keep-old-partition&lt;/STRONG&gt; flag overrides the default behavior. When blink is run with only the&amp;nbsp; &lt;STRONG&gt;--reimage&lt;/STRONG&gt; flag, then it defaults to creates a snapshot which is shown as a partition (see highlight below). These are the snapshots after 3 blink runs.The final one with the the &lt;STRONG&gt;--reimage --delete-old-partition&lt;/STRONG&gt; flag set didn't create a new snapshot and doesn't touch the previous snapshots.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier\ new, courier, monospace;"&gt;# lvs&lt;BR /&gt;&amp;nbsp; LV&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VG&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Attr&amp;nbsp;&amp;nbsp; LSize&amp;nbsp; Origin Snap%&amp;nbsp; Move Log Copy%&lt;BR /&gt;&amp;nbsp; hwdiag&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vg_splat -wi-a-&amp;nbsp; 1.00G&lt;BR /&gt;&amp;nbsp; &lt;STRONG style="color: #339966;"&gt;lv_Blink_R80.10_198 vg_splat -wi-a- 32.00G [from ./blink --keep-old-partition]&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &lt;STRONG style="color: #3366ff;"&gt;lv_Blink_R80.10_373 vg_splat -wi-a- 32.00G [from ./blink --reimage]&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; lv_current&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vg_splat -wi-ao 32.00G&lt;BR /&gt;&amp;nbsp; lv_fcd_GAIA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vg_splat -wi-a-&amp;nbsp; 6.00G&lt;BR /&gt;&amp;nbsp; lv_log&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vg_splat -wi-ao 60.00G&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth,&lt;/P&gt;&lt;P&gt;bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Feb 2018 00:55:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28676#M98061</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2018-02-09T00:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28677#M98062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These details are very interesting - but i was interested more in user experience with blink and how it shines compared with isomorphic USB deployment &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Feb 2018 10:17:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28677#M98062</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-02-09T10:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28678#M98063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I plan to Try it in the lab tomorrow with same questions you have&lt;/P&gt;&lt;P&gt;Will&amp;nbsp;let you know&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Feb 2018 13:28:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28678#M98063</guid>
      <dc:creator>Noel_Taylor</dc:creator>
      <dc:date>2018-02-10T13:28:17Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28679#M98064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Until you have some feedback from other users, I can tell you that I have used both Blink and ISOMorphic many times, but I am biased since they are developed in my group &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I can shed some light about the differences between both:&lt;/P&gt;&lt;P&gt;ISOMorphic will format your HD and reinstall the ISO just like a new appliance. ISOMorphic works on all machine roles since it uses the same ISO for all installations.&lt;/P&gt;&lt;P&gt;Blink on the other hand creates a new partition with the new image already installed and customized as a GW. You cannot use Blink&amp;nbsp;for any machine role other that a GW (for now), and the HD is not reformatted. Blink is much faster - it will take you ~5 minutes plus the reboot time, while ISOMorphic can take more than 30 minutes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps, and I am looking forward to hear some more feedback on this thread.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tsahi&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Feb 2018 17:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28679#M98064</guid>
      <dc:creator>Tsahi_Etziony</dc:creator>
      <dc:date>2018-02-11T17:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28680#M98065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I always read about 5 minutes for installation.&lt;/P&gt;&lt;P&gt;And how long takes the preparation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Feb 2018 17:29:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28680#M98065</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2018-02-11T17:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28681#M98066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on how you plan to use the image.&amp;nbsp;If you want to use a USB flash drive, the preparation will be just the time it takes to copy the image to the drive. If you want to copy the image to the machine, then the preparation will be the time it takes you to do that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In ISOMorphic you need to use the ISOMorphic tool to format the flash drive, but with Blink you don't need to do that. The flash drive option is just for storage of the image file.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 11 Feb 2018 17:37:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28681#M98066</guid>
      <dc:creator>Tsahi_Etziony</dc:creator>
      <dc:date>2018-02-11T17:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28682#M98067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Tsahi - these are very interesting details indeed!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Feb 2018 09:19:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28682#M98067</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-02-12T09:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28683#M98068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still no one is discussing his practical experience here - what a pity...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 09:45:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28683#M98068</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-05-30T09:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28684#M98069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't have practical experience&amp;nbsp;yet &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 09:59:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28684#M98069</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2018-05-30T09:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28685#M98070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Quick comment about practical experience --&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used this tool on 10+ gateways in my environment and I found it super helpful.&amp;nbsp; This tool is a great way to image a box - especially if you don't have physical access to the gateway, and shipping/creating a usb stick at the site is a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have used this to "upgrade" R75.46 boxes as well as "upgrade" R77.20 boxes that had hotfixes that we couldn't remove cleanly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think once this tool becomes more integrated with the rest of the management suite - CDT &amp;amp; Zero-touch -&amp;nbsp;Gaia deployments and hardware replacements won't really require much attention.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:35:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28685#M98070</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2018-06-07T15:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28686#M98071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been playing around with Blink over the past few weeks getting ready to roll out our R77.30 -&amp;gt; R80.10 upgrade.&amp;nbsp; &amp;nbsp;We have custom scripts and configurations that I want to preserve and also automate as much as possible so that it's a one-click type of deployment.&amp;nbsp; So, in my lab I extracted the the 80.10 image and dropped in the update file into the appropriate directory (per the SK).&amp;nbsp; Then I started building out the user_updates directory.&amp;nbsp; I dropped a .tgz file containing our custom scripts and created a pre script that would go gather various configuration bits including a clish save configuration.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use the --reimage flag then and install_content.sh will import that config back in when done.&amp;nbsp; &amp;nbsp;I did a demo to one of our managers yesterday.&amp;nbsp; 2.5 mins + 2 reboots + SIC + policy install and we have a gateway go from 77.30 to 80.10.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bits I"m working on next are more complicated upgrades where the gateway has non-standard CoreXL settings for example.&amp;nbsp; Also need to validate any other differences between 77 and 80 such as the cluster ID mechanism which changed again.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, blink in and of itself is pretty awesome so far.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 16:02:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28686#M98071</guid>
      <dc:creator>Ivan_Moore</dc:creator>
      <dc:date>2018-06-07T16:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28687#M98072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry Guenther, hope I am not hijacking this as I haven't used Blink yet but Tsahi referenced this thread for any opinion about blink.&lt;/P&gt;&lt;P&gt;I would have liked to have a mechanism to quickly&amp;nbsp;fire up lab firewalls&amp;nbsp;which we'd run on open servers in virtualized environments. Alas, OpenServers are not supported by blink&amp;nbsp;yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;The Blink configuration mechanism seems to be a&amp;nbsp;discontinuation of the previously used config_system syntax and the fact they're using different syntax is creating the need for us "users" to read into and decide to use one or the other and thus increases adoption efforts.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;STRONG&gt;In my dreams, I would have liked one unified configuration syntax that is compatible with clish, config_system and Blink&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;and I can't see why this shouldn't have been possible.&amp;nbsp;Now we've got three syntactic representations of first-time and ongoing configuration instructions that couldn't be more different even though they have got a huge overlap in terms of what they do.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;PS: For anyone who like me wasn't quite clear about the different use cases/scenarios for both methods see these videos:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/videos/6335"&gt;Overview of ISOmorphic and Blink&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.youtube.com/watch?list=PLMAKXIJBvfAhtnNlHqO7-G4iJkTbb9nVj&amp;amp;time_continue=196&amp;amp;v=Kd3E42tsJSc" title="https://www.youtube.com/watch?list=PLMAKXIJBvfAhtnNlHqO7-G4iJkTbb9nVj&amp;amp;time_continue=196&amp;amp;v=Kd3E42tsJSc"&gt;Check Point Deployment Tools; DIY Check Point security appliance images using ISOmorphic - YouTube&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 17:09:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28687#M98072</guid>
      <dc:creator>Albert_Wilkes</dc:creator>
      <dc:date>2018-06-07T17:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28688#M98073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We successfully started using Blink!&lt;/P&gt;&lt;P&gt;We did build some wrappers around it but with these wrappers, it has worked extremely well. The only issue, if you can even call it an issue, revolves around the original "factory image" remaining. Though we don't really see a need to "factory reset" a gateway any longer, since it can re-Blink'd at any time. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The wrappers we built:&lt;/P&gt;&lt;P&gt;1) Fresh re-image with R77.30 w/ basic pre-built clish commands (ie, password, snmp, ntp, etc..)&lt;/P&gt;&lt;P&gt;2) Fresh re-image with R80.10 w/ basic&amp;nbsp;&lt;SPAN&gt;pre-built clish commands&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3) Upgrade/re-image from R77.30 to R80.10 while re-applying clish statements dynamically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did need to build "two" sets of wrappers for each, as we needed to handle clusters vs single GW installs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our internal process already requires new or firewall replacements be built with option 1 or 2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Option 3, we successfully proved this with a few remote site upgrades and plan to perform all upgrades using this method with Cavaets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you ever tried to fresh re-image a 2200 (via usbboot), run first-time wizard, then Jumbo HotFix, you will be happy to hear we have averaged Blink completing all these steps within 8 mins on this model.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cavaet: Our company best practice is to avoid any customization's of files in expert mode. Making it much easier for us to deploy or re-deploy firewalls using only the saved CLISH configurations. While we are using this method for upgrading from R77.30 to R80.10, keep in mind those expert mode customization's are not retained.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 18:57:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28688#M98073</guid>
      <dc:creator>Jose_Rivera</dc:creator>
      <dc:date>2018-06-07T18:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28689#M98074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you like to quickly&amp;nbsp;fire up lab firewalls&amp;nbsp;which will run on open servers in virtualized environments, you better use VM templates &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Either build them yourself or get it e.g. here: &lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=55898&amp;amp;from=wizard" target="_blank"&gt;R80.10 vSEC Virtual Edition (VE) Gateway in Network Mode - VMWare OVF template &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 06:34:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28689#M98074</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-06-08T06:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28690#M98075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for sharing your experience !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 06:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28690#M98075</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-06-08T06:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Blink, anyone ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28691#M98076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested Blink in lab environment.&lt;/P&gt;&lt;P&gt;- it's working well and it's very fast (probably depending on&amp;nbsp;hardware capabilities since Blink extracts into a new LV)&lt;/P&gt;&lt;P&gt;- I managed to upgrade a cluster in R80.10 from R77.30 in less than 15 minutes, including reboots (using Blink in addition to CDT). This way to proceed is not supported but shows that something is possible &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;. I'm looking forward the day when our admins will be able to announce our customers a 30mins maintenance window to upgrade a cluster!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a MSSP we are always looking for better ways to industrialize and shorten our operations. Beeing able to apply customized configurations (scripts, specific parameters, ...) at any step of our installation/upgrade/recovery processes is very important for us.&lt;/P&gt;&lt;P&gt;We have hundreds of gateways : less manual operations, the better. Blink may be a very good tool for such purposes in the future.&lt;/P&gt;&lt;P&gt;There are some limitations especially&amp;nbsp;management servers deployments that are not supported yet but I heard that R&amp;amp;D is working on a Blink image for management servers.&lt;/P&gt;&lt;P&gt;In my opinion Blink, CDT and CPUSE can't be separated and I don't see any reason for Blink, CDT and CPUSE not to be merged in the future and I have not doubt that R&amp;amp;D is working on it! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 08:48:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Blink-anyone/m-p/28691#M98076</guid>
      <dc:creator>Juan_Carlos</dc:creator>
      <dc:date>2018-06-08T08:48:17Z</dc:date>
    </item>
  </channel>
</rss>

