- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi All,
Does anyone know how to configure the GAIA setting under the AWS auto-scaling group or Azure VMSS?
the GAIA setting should have below configuration
1. SNMPv2 community string
2. NTP
3. GAIA user
4. Install with the latest jumbo hotfix
Hi,
You can execute this by adding a custom bash script to be run by the CME using the autoprovision script's -cg flag
To configure the CME run on the management server:
#autoprov-cfg set template -tn "<template_name>" -cg <path_to_script>
You would want to create a bash script to run your required clish commands, for example:
#!/bin/bash
clish -c 'set ntp server primary 8.8.8.8 version 4'
clish -c 'save config'
Setting the above will run the script anytime a new instance is created.
Hope this helps
Hi,
1. Yes - The script needs to be located in the management server
2. To my knowledge you can only use the flag once, so only 1 script, you will have to put all the configurations in one file.
3. Generally, when you deploy new instances they come with the latest recommended jumbo hotfix normally, so this shouldn't be much of an issue.
Hi,
You can use the flag with a single script.
You can find information on it in the link for CME admin guide:
JHF: You can find information on how to install latest JHFs in the same admin guide here:
Although we do change the images for gateways to include JHFs but using auto-HF will increase your control on JHF versions.
Hi,
You can execute this by adding a custom bash script to be run by the CME using the autoprovision script's -cg flag
To configure the CME run on the management server:
#autoprov-cfg set template -tn "<template_name>" -cg <path_to_script>
You would want to create a bash script to run your required clish commands, for example:
#!/bin/bash
clish -c 'set ntp server primary 8.8.8.8 version 4'
clish -c 'save config'
Setting the above will run the script anytime a new instance is created.
Hope this helps
Hi Edan,
Thanks for your promptly reply.
May I know the "<path to script>" means the the script path located in SMS disk? Can I use the multiple scripts with the same flag? like
#autoprov-cfg set template -tn "<template_name>" -cg <path_to_script-1> -cg <path_to_script-2> -cg <path_to_script-3>
Furthermore, how can we provision the CGNS instance together with the latest jumbo hotfix install?
Hi,
1. Yes - The script needs to be located in the management server
2. To my knowledge you can only use the flag once, so only 1 script, you will have to put all the configurations in one file.
3. Generally, when you deploy new instances they come with the latest recommended jumbo hotfix normally, so this shouldn't be much of an issue.
Hi,
You can use the flag with a single script.
You can find information on it in the link for CME admin guide:
JHF: You can find information on how to install latest JHFs in the same admin guide here:
Although we do change the images for gateways to include JHFs but using auto-HF will increase your control on JHF versions.
Hi all,
I have created the script and added to the autoprov_cfg template and found it is not able to configure the gateway
[Expert@cp-mgmt:0]# autoprov_cfg show templates
gwlb-configuration:
anti-bot: true
anti-virus: true
application-control: true
aws-automatic-policy: true
custom-gateway-script: "/home/admin/setup_script2.sh"
ips: true
for the script, it is like this
#!/bin/bash
clish -c 'lock database override'
clish -c 'add allowed-client host ipv4-address 138.19.226.116'
clish -c 'add allowed-client host ipv4-address 183.178.46.193'
clish -c 'save config'
where is the log and how to diagnose the problem?
i got this message from the Smart Console, Does anyone know what is the problem?
/tmp/rconfd-temp-script-8ry5k3: /bin/setup_script2.sh: /bin/bash^M: bad interpreter: No such file or directory
fixed the script problem with "sed -i -e 's/\r$//' scriptname.sh"
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 7 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY