- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone.
I have run into a situation that one of the cluster members moved between staging environment to production is no longer allowing me to log in using admin password and there is no longer SIC between it and the management.
Since in staging there was no Syslog server, I have no record of the changed for that unit.
I strongly suspect that the client, for some reason, rerun FTW on that gateway, but no means of confirming that.
I still have LOM access to the unit.
Any suggestions on how to:
1. Reset the Gaia password using LOM (if possible)
2. Retrieve Gaia logs showing what was done on the unit.
The only prove that it was in a good state at some point are the old successful policy installation records in the audit logs.
I still have snapshots, backups and Gaia configs from the unit when it was in a good state and may attempt to recover from those.
Any suggestions on how to accomplish that using LOM console are appreciated.
Thank you,
Vladimir
You can feed the LOM's KVMS interface an ISO image, which it will then present to the system as a DVD in a DVD-ROM drive connected via USB. It is possible to boot from this drive.
Reads from this virtual drive are streamed over the network, so they're pretty high-latency. They can actually perform worse than a real optical drive does. I recommend using a small live CD without a GUI. The CentOS minimal or NetInstall versions should work.
Just an update to put this issue to rest: for some unexplainable reason, authentication is now working and SIC was re-established. I suspect that there was some weird combination of networking issue and Zoom interference with keystrokes path-through at play, since there is nothing in the logs except failed logon attempts.
I dont believe you can reset regular Gaia pw using LOM, at least, I never heard of such a possibility. As far as audit logs, do you see anything in /var/log/audit dir?
Andy
@the_rock , if I could read the /var/log/audit directory, I would be logged-in to the unit in question:)
There are few SKs describing boot from alternate media to reset the password, but to the best of my recollection they are referring to USB drives. I will be looking at the unit tomorrow again to see if there is option to mount remote USB bootable media via LOM to attempt the recovery.
Was wandering if anyone has run into similar situations already.
I realized my stupidity in audit comment as soon as I posted it, DUH : - ). Sorry mate, my bad. K, lets see if anyone may have ran into something similar.
Let us know how it gets solved.
Andy
No problem:)
I'd like to make a suggestion for Check Point to include preconfigured alternative bootable image (CentOS or Ubuntu, if I am not mistaken) in LOM boot from options to facilitate the recovery in these or similar situations.
You can feed the LOM's KVMS interface an ISO image, which it will then present to the system as a DVD in a DVD-ROM drive connected via USB. It is possible to boot from this drive.
Reads from this virtual drive are streamed over the network, so they're pretty high-latency. They can actually perform worse than a real optical drive does. I recommend using a small live CD without a GUI. The CentOS minimal or NetInstall versions should work.
Thank you @Bob_Zimmerman ! I'll give it a shot.
Thanks for sharing @Vladimir
Just an update to put this issue to rest: for some unexplainable reason, authentication is now working and SIC was re-established. I suspect that there was some weird combination of networking issue and Zoom interference with keystrokes path-through at play, since there is nothing in the logs except failed logon attempts.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 41 | |
| 21 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY