Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
israelfds95
MVP Gold
MVP Gold

Smart-1 6000-L: Installation Recovery Using VGA Access

Imagine the following situation: you are assigned to upgrade a Smart-1 6000-L appliance to R82 Jumbo Hotfix Take 91. You prepare your USB flash drive using Isomorphic Tool in BIOS mode, following sk65205. Everything is ready, and you proceed to the maintenance activity.

Once onsite, you perform all recommended preparation steps, including collecting a System Backup and a Migrate Export. However, when arriving at the datacenter, you face an issue with the appliance console port. The console is not responding, and authentication is not possible. You then attempt to access the LOM, but it is also unreachable, and you are unable to configure an IP address either through clish or ipmitool.

At this point, everything seems lost.

Then, you receive a suggestion that this appliance model might work using a VGA monitor and USB keyboard directly connected to the appliance. Fortunately, the customer had a VGA monitor, cable, and keyboard available in the datacenter.

Video output works, and the bootable USB flash drive is recognized. However, selecting Option 2 (Appliance) during boot does not display anything on the screen. After additional testing, you try the "4 -Open Server VGA" option, and it works successfully.

This post is intended to share this experience and provide useful operational knowledge for anyone who may face a similar situation in the future.

Below, I will describe the scenario with images and examples to help others troubleshoot the same issue if encountered.

sk65205 – Shows which appliance models require the USB flash drive to be formatted using Isomorphic Tool.

 

israelfds95_0-1779203209956.png

 

israelfds95_1-1779203209957.png

 

Front view of the appliance.

israelfds95_2-1779203210005.png

 

I recommend using the official Getting Started Guide for Smart-1 6000-L/XL Appliances as a reference:

https://sc1.checkpoint.com/documents/Smart1_6000_L_XL_GSG/English/CP_Smart-1_6000-L-XL_Appliances_Ge...

This document provides a complete overview of all appliance ports and hardware interfaces.

israelfds95_3-1779203210046.png

 

Connect the VGA monitor cable to the appliance VGA port, connect the USB keyboard, and insert the bootable USB flash drive into one of the USB ports.

israelfds95_4-1779203210121.png

 

Select the option:

“4 - Open Server with VGA”

NOTE: When selecting Option 2 (Appliance), the installation progress screen is not displayed, preventing the installation process from continuing properly.

israelfds95_5-1779203210179.png

Below is the view showing that, after selecting “4 - Open Server with VGA”, video output works correctly during the installation process, making it possible to complete the installation normally.

israelfds95_6-1779203210214.png

 

After completing the first stage of the installation, connect to the Smart-1 Mgmt port and access the WebUI through:

https://192.168.1.1

Run the appropriate First Time Wizard and continue with the installation process normally.

After completing the initial configuration, I uploaded the previously collected Migrate Export file and performed the corresponding import procedure. Then, I applied the license and finalized the upgrade successfully.

 

 

(1)
4 Replies
PhoneBoy
Admin
Admin

Nice to know you can still do FTW via VGA and Keyboard if needed (at least on models that have it).
Personally, I would have gone with an old school console cable. 🙂

israelfds95
MVP Gold
MVP Gold

So, me too, but the appliances weren't responding to the traditional console, and they weren't responding to LOM in any way either. That was the only option in this case.

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

"Check Point appliance (any model)" switches the output from VGA to serial, which is why it appears to not display anything.

0 Kudos
israelfds95
MVP Gold
MVP Gold

As I explained, the console (serial port) wasn't responding to commands, so it wasn't possible to perform actions using a console, neither the console nor the LOM. Therefore, the only option was "Open Server VGA," which in my view was strange because the Smart-1 6000-L is a Check Point appliance, not an open server (even knowing that it will generally be hardware that virtualizes SMS, so conceptually it can be considered an Open Server, but the Smart-1 is a Check Point appliance). Anyway, the situation here used VGA simply because in no way (quite strangely, actually) were the serial console and LOM operating correctly, making it impossible to issue commands.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events