- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good afternoon all,
We upgraded our Check Point Management server at the weekend with no problems, well, almost no problems!
Unfortunately we have a superuser account in SmartConsole of an ex-employee and all other accounts being either read only or administrator.
We would like to escalate the privileges of one of the administrator accounts to be SuperUser however I am struggling to figure out how this can be done.
I have access to Clish and Expert mode but I can't see how to change the passwords of the user accounts using either of these options .... HELP!
Which one is your "admin" user? You can use "cpconfig" (for MDS: "mdsconfig") to delete this user and then you can create the "admin" user again and set up the password.
[Expert@mds:0]# mdsconfig
Welcome to Multi-Domain Server Configuration Program
=================================================================
This program will let you re-configure your Multi-Domain Server configuration.
Configuration Options:
----------------------
(1) Leading VIP Interfaces
(2) Licenses
(3) Random Pool
(4) Groups
(5) Certificate's Fingerprint
(6) Administrators
(7) GUI clients
(8) Automatic Start of Multi-Domain Server
(9) P1Shell
(10) Start Multi-Domain Server Password
(11) IPv6 Support for Multi-Domain Server
(12) IPv6 Support for Existing Domain Management Servers
(13) Exit
Enter your choice (1-13): 6
Configuring Administrators...
=============================
Following is a list of the currently defined Administrators
and their Multi-Domain permission levels:
1) user1 Domain Manager
2) user2 Multi-Domain Superuser
3) user3 Domain Manager
4) user4 Domain Manager
5) admin Multi-Domain Superuser
Do you want to add Administrators (y/n) [y] ?
*I used a MDS for example because I am already connected in this. Just an example.
you should be able to change the admin password (the default user) using the cpconfig. Try sk56520.
basicaly you have to delete the user called admin and in the same session you have to immediately add again the user admin. Then you can set a new password without knowing the old one.
This user should be able to do anything....
Can't you use "#fwm -a" to change this password?
This is not the admin password that I am trying to change. This is a SmartConsole user account. The previous admin was a SuperUser but we no longer have that users password. Is there a way to escalate one of the accounts that has Full-Access to Super User status? See attached image.
Which one is your "admin" user? You can use "cpconfig" (for MDS: "mdsconfig") to delete this user and then you can create the "admin" user again and set up the password.
[Expert@mds:0]# mdsconfig
Welcome to Multi-Domain Server Configuration Program
=================================================================
This program will let you re-configure your Multi-Domain Server configuration.
Configuration Options:
----------------------
(1) Leading VIP Interfaces
(2) Licenses
(3) Random Pool
(4) Groups
(5) Certificate's Fingerprint
(6) Administrators
(7) GUI clients
(8) Automatic Start of Multi-Domain Server
(9) P1Shell
(10) Start Multi-Domain Server Password
(11) IPv6 Support for Multi-Domain Server
(12) IPv6 Support for Existing Domain Management Servers
(13) Exit
Enter your choice (1-13): 6
Configuring Administrators...
=============================
Following is a list of the currently defined Administrators
and their Multi-Domain permission levels:
1) user1 Domain Manager
2) user2 Multi-Domain Superuser
3) user3 Domain Manager
4) user4 Domain Manager
5) admin Multi-Domain Superuser
Do you want to add Administrators (y/n) [y] ?
*I used a MDS for example because I am already connected in this. Just an example.
Yep. So long as you have the credentials for the now absent admin.
Otherwise, as long as one of your existing users have permission to edit Gaia config, there was a trick of copy/pasting the non-expert user's password hash instead of the existing one and this should reset your expert-password to the known one.
Than you can proceed changing default user's credentials.
I.e.:
GW8010> set user admin password-hash $1$BBXc[B`B$i?????????.????????Pp0AM1
GW8010> save config
GW8010> set expert-password-hash $1$UcDP?????????????????????L4wUwiF/
GW8010> save config
GW8010> expert
Enter expert password: NewExpertPassword
I'm not sure if I'm missing something here or if I'm not explaining myself properly so apologies in advance.
I have the admin password and I can log into clish and expert mode however this admin password cannot be used to log into SmartConsole. Only the users listed in the image in my last post can log into SmartConsole (none of them are the user "admin")



Open "cpconfig" and go to Administrators, show us the result. Please.
What is the user name listed in cpconfig?
Sorry guys, I had a bit of a brain fart. Followed the suggestions above and got it sorted.
Thanks to all that responded
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 14 | |
| 13 | |
| 7 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY