- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi
after upgrade of a smart-1 appliance from R81.10 to R81.20 following appeared.
Warning! Grub default password hasn't been changed. Sign in to clish and use 'set grub2-password' to change it.
Breaking News: HCP version updated! To see an overview of your machine health, run 'hcp -r all'. For further information please see sk171436
Seems to be new that there is now a need to setup a grub-password. Could not see any details in R81.20 admin guide.
Regards
[Expert@SMS:0]# hcp -v
HCP Take: 58
HCP RPM Build: hcp-1-592021.i386
[Expert@fSMS:0]# cpstat mg
Product Name: Check Point Security Management Server
Major version: 6
Minor version: 0
Build number: 997000440
Is started: 1
Active status: active
I have upgraded my ESX VMs from R81.10 to R81.20 and had the same warning both on SMS and GW !
Reason: See R81.20 (Titan) Release Notes: Software Changes
This section describes behavior changes from previous versions.
Gaia - The password for the Gaia GRUB (boot loader - maintenance mode) is a dedicated password (separated from the Expert mode password). You can configure the Gaia GRUB password during the Gaia First Time Configuration Wizard, or after the Gaia installation.
--> This is a new feature as the former expert pass also was the grub / maintenance mode PW...
More info can be found in admin guide :
if grub password has not been set post upgrade ,we recommend it is set post upgrade , via the clish/webui tools .
Hm, thats very odd, because I updated my R81.10 lab, though it was VM only, not smart-1, but never noticed that at all. Hope someone from CP can comment. Also did brand new R81.10 lab (mgmt + single gateway) and never seen it there either.
Andy
I have upgraded my ESX VMs from R81.10 to R81.20 and had the same warning both on SMS and GW !
Reason: See R81.20 (Titan) Release Notes: Software Changes
This section describes behavior changes from previous versions.
Gaia - The password for the Gaia GRUB (boot loader - maintenance mode) is a dedicated password (separated from the Expert mode password). You can configure the Gaia GRUB password during the Gaia First Time Configuration Wizard, or after the Gaia installation.
--> This is a new feature as the former expert pass also was the grub / maintenance mode PW...
Thats weird then why I never got that when I upgraded my VM...unless it happens ONLY when you upgrade physical appliance?
ok, so 'can' sounds like optional and not mandatory.
Thanks,
Regards
More info can be found in admin guide :
if grub password has not been set post upgrade ,we recommend it is set post upgrade , via the clish/webui tools .
The wording is GRUB default password has not been changed, what is the default password for it?
Why do you require the default password ?
You should set the password via available commands in clish/webui or during FTW.
if system is not available to set password and you require to enter maintenance mode/revert to snapshot via grub , please open support case , and they can assist .
I remember when setting up brand new R81.20, it asked me to set grub password, so I just used same password as expert. Never had to use it, but it can be set with followint command in clish:
quantum-firewall> set grub
grub2-password - Set user admin Grub2 password by plain text
grub2-password-hash - Set user admin Grub2 password by salted hash
quantum-firewall> set grub2-password
quantum-firewall> set grub2-password
Enter new grub2 password:
Enter new grub2 password (again):
quantum-firewall> save config
quantum-firewall> exit
[Expert@quantum-firewall:0]#
Is this something that can be set/scripted by the mgmt_cli command in batch mode?
This is a new level of security, now you have:
It does make sense to differentiate here, but you can use the same PW for all if you want (less hassle for Lab deployments)
Agree! Thats what I do in my lab as well.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
6 | |
4 | |
4 | |
4 | |
4 | |
2 | |
2 | |
2 | |
2 |
Wed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksWed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY