Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
riyalsandeep1
Participant
Jump to solution

how to change admin passwords for multiple firewall at a time. is there a script

looking to change admin password for around 70 + firewalls. is there a script to change from management server.  

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Changing the password programmatically will likely mean executing the following clish commands:

set user admin password-hash thehash
save config

Documented here: https://support.checkpoint.com/results/sk/sk92347
thehash comes from the output of cp_openssl passwd -1 

To automate the execution on lots of firewalls, you can use something like https://community.checkpoint.com/t5/SmartConsole-Extensions/Execute-Commands-Simultaneously-SmartCon... 

View solution in original post

5 Replies
PhoneBoy
Admin
Admin

Changing the password programmatically will likely mean executing the following clish commands:

set user admin password-hash thehash
save config

Documented here: https://support.checkpoint.com/results/sk/sk92347
thehash comes from the output of cp_openssl passwd -1 

To automate the execution on lots of firewalls, you can use something like https://community.checkpoint.com/t5/SmartConsole-Extensions/Execute-Commands-Simultaneously-SmartCon... 

riyalsandeep1
Participant

thank you!! do we have any cli/api command that we can run via management server?

0 Kudos
PhoneBoy
Admin
Admin

You can use something like the following from the management: https://community.checkpoint.com/t5/API-CLI-Discussion/Central-Script-to-run-command-on-multiple-gat...
See also https://support.checkpoint.com/results/sk/sk101047 

Gaia has an API also: https://sc1.checkpoint.com/documents/latest/GaiaAPIs/index.html#introduction 
And yes, you should be able to set a password that way.
You can make these API calls from the management.

There may be other examples in the community.

0 Kudos
Hugo_vd_Kooij
Advisor

Mind you this will fail on SMB devices. Unless you create the hash on the same version SMB device. THere are some Secure Knowledge articles about this and you have to piece them together to get the proper picture so you know what works and what does not work.

As a practical hint. If you roll out a number of SMB devices make sure you have one or two to tinker with yourself as admin as there are practical limitations you rather find out in the lab then in the field.

<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>
0 Kudos
PhoneBoy
Admin
Admin

I think I ran into this issue recently…

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events