Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Tharindu
Contributor

Password Reset | CLI | 1500

Hi Guys,

 

One of our customers lost his admin password for the firewall and requested to reset it. Can anyone help me with the steps or guide?  

TIA

18 Replies
Chris_Atkinson
Employee Employee
Employee

Is there any access to the appliance at all or he lost the password for the only admin account configured?

If this is a centrally managed appliance you can look at: https://support.checkpoint.com/results/sk/sk119633

Alternately if it's locally managed it may need to be factory reset, in the current EA version a new feature has been added to help avoid such scenarios.

 

CCSM R77/R80/ELITE
Tharindu
Contributor

Hi Chris,

 

He only lost the admin password. We believe we can get an SSH session but won't be able to log in.

Also, it's a locally managed firewall. Is there any solution to recover the password without resetting the device?

Tharindu
Contributor

Hi,

It means we have to reset the box right?

TIA

_Val_
Admin
Admin

Yes. Unless you have an another admin account that still works

Tharindu
Contributor

Hi,

Unfortunately, the customer doesn't have any other account.

_Val_
Admin
Admin

Too bad. Any existing backup of that appliance?

Tharindu
Contributor

Hi,

yeah we have 03 month old backup

_Val_
Admin
Admin

Well, this is better than nothing. Perform a factory reset, set up two admin accounts, just in case, and see if you can restore your policies from that backup or not. Plan for an extensive downtime while you do that, or, if you have another appliance handy, try doing it in the lab first, to see if it works.

G_W_Albrecht
Legend Legend
Legend

It will replace the passwd and shadow files. You can change the passwd in backup, see https://community.checkpoint.com/t5/SMB-Gateways-Spark/Replace-expert-password-on-SMB-Appliance/m-p/...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
_Val_
Admin
Admin

Thanks for sharing, I see a way out here 🙂

G_W_Albrecht
Legend Legend
Legend

Another alternative, use USB media during boot: https://community.checkpoint.com/t5/SMB-Gateways-Spark/set-expert-password-hash-using-autoconf-clish...

Not sure if this works on a configured appliance, but could be tested.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
G_W_Albrecht
Legend Legend
Legend

Backup contains the old password...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
_Val_
Admin
Admin

Will it remove the second admin account created on the device; as I suggested above? 

Tharindu
Contributor

Thank you, guys, for your great support. found an another login and we logged into the firewall using that account 

_Val_
Admin
Admin

Fantastic news, thanks for sharing

davidl36
Explorer

why can't there be a reset button like synology which requires physical access to push button to default admin password?

PhoneBoy
Admin
Admin

We don't have a default admin password.
There is an option to perform a factory reset with physical access, however: https://support.checkpoint.com/results/sk/sk98549 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events