- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Checkmates;
We are searching for a way to use a USB to give to field operators at remote sites in order to provision a gateway out in the field.
This would be a disaster recovery scenario where they would grab a replacement gateway from their local office and we would provide them with a USB stick with all code jumbos and full configuration on it.
These would be GWs running the full Gaia not the embedded ones.
I have been trying to use Isomorphic in Advance mode and using the config_system template but this only seems to like entries used in the 1st time wizard. trying to add other entries such as additional interfaces has failed.
I also tried doing the "additional OS Configuration" This seems to get further but if there are add commands in the config, it seems to bail out.
Is this even possible to do a complete automated rebuild and restore to a gateway from a USB stick ?
Anyone have a running example of either a script or template file that includes a full configuration.
Thanks
-pat
Create a snapshot, move the (exported) snapshot to a USB device and you should be good to go.
The snapshot itself contains the os config, the product config as well as installed hotfixes with a few limitations that you can read about here. So for example, you are going to loose locally saved logs, this could be circumvented via additional methods. But my guess is that this is not as relevant as you are writing a about something like an "emergency" solution/USB stick.
We are doing this at the moment with isomorphic prepared USB-device to do a rollout for 60 appliances without the need for onsite going for a Check Point specialist.
You don't need to touch the appliance, You can bring it with the USB-device onsite, put it in, boot twice and after the configuration the appliance is up with "initial_policy" and ready to get connected to smartcenter.
Have a look at my document. I hope anything is described and understandable.
Hello Patrick,
yes, this is a limitation. There are some commands we are adding later running a script via Smartconsole to the gateway. But this is not a problem for us, most of the commands are running fine.
If you do a testdrive with a serial console attached to the appliance you can see the failing command in the second stage.
There is no log written to the USB-device, but you can log your putty-session or what else tool you are using for serial connection.
For us this is the best solution, we don‘t need to unpack the appliance, configure, repack and bring onsite... They are delivered direct to the production location and installed from one of the normal users onsite.
Wolfgang
Another nice way for first time configuration is Zerotouch Installation
Since R80.20 this is available too for GAiA Gateways, not only SMB-devices. But you have to touch once the appliance and enable it and you need a Internet connection. Maybee it’s default enabled in one of the next releases. Zerotouch is described in sk116375.
Wolfgang
Backing up Gaia system level configuration
Hello Jozko,
problem with that solution...you have to touch the device and you have to run the first time install wizzard before.
I really agree with Patrick, a real zerotouch procedure would be very nice and helpfully for new installs and replacements.
Wolfgang
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 41 | |
| 21 | |
| 9 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY