Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
mischelw
Contributor
Jump to solution

Run Clish commands fail on updated CP1570

I'm trying to run Clish commands, or get a list of assets (so I can find out the model type of the device) and it claims I cannot run an interactive command inside an interactive window (I'm using putty in this case), and should exit expert mode.

I exit expert mode and it claims it doesn't recognize Clish ...

What is going on ? any idea ?

0 Kudos
1 Solution

Accepted Solutions
mischelw
Contributor

All started to work as soon as I activated the license of the device, including it now shows the correct device model type (in my case 1570).

Seems that when the device is not activated it shows a general 1500 type as the hardware is the same, its just a matter of license which gives it identity.

 

Thanks all for trying to assist.

View solution in original post

29 Replies
G_W_Albrecht
Legend Legend
Legend

This does usually work with other 15x0 units ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
mischelw
Contributor

Don't know, I understood that this is the way to get some more info through cli from the device...

0 Kudos
G_W_Albrecht
Legend Legend
Legend

I would use the WebGUI that shows much information first. But i can see none of the CLISH commands that did not work 😎

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
PhoneBoy
Admin
Admin

What is the precise command(s) you are trying to execute?
Keep in mind that clish on the SMB appliances is somewhat different from regular gateways.
Sounds like you are trying to execute show asset, which is not supported on SMB appliances.
You can get similar information from show diag.
Maybe there's a better way to see the precise model number, but you can work it out from show license output as the license string contains the model number.

0 Kudos
mischelw
Contributor

none show command works. funny is that this is what I got from the support team.

Since I'm not getting the full bandwidth I was getting with my old CP790 I want to make sure this is the right model. no simple way to get the model number. in previous versions It was showing in the UI, now it just shows 1500 appliance....

 

Thanks!

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Post a screenshot - it does show the model on my 1550:

1550.png

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
mischelw
Contributor

This is exactly why I'm troubled.... a friend of mine shows as well. this one, doesn't.

I've also upgraded to the latest r80.20.25. same....

0 Kudos
PhoneBoy
Admin
Admin

Sounds like you've changed the default shell to bash (expert mode).
That said, cplic print from that prompt should tell you exactly since it's encoded in the license.
In this example, it's a 1590.

MyGW> cplic print
Host             Expiration  Features            
127.0.0.1        never       CPAP-AP1590 CPWIFI-US CPSB-FW CPSG-C-4-U CPSB-VPN CPSB-SSLVPN-200 CPSB-IA CPSB-ADNC CPSB-ADNC-M CPSB-IPS-S1 CPSB-URLF CPSB-APCL-S1 CPSB-AV CPSB-ABOT-S CPSB-ASPM CPAP-CLOUD-MGMT CK-00-XX-XX-XX-XX-XX

Also, it should show in the UI like so:

Screen Shot 2021-05-18 at 8.34.13 AM.png

The only time I've personally seen issues like this is (the UI not showing the correct model number) is on pre-production units.
Perhaps its a different issue and an RMA might be required here. 

0 Kudos
mischelw
Contributor

Thanks. I didn't activated the license yet, until I'm sure I got the right model.

It is still in trial, so probably see it under the lic is not relevant for me. (BTW, on my friends CP, he is also in trial, but it shows 1590)

0 Kudos
PhoneBoy
Admin
Admin

Regardless, the fact this is not showing the correct device in the UI suggests this device is not burned with the correct data.
Highly recommend an RMA.

0 Kudos
mischelw
Contributor

Funny, out of the box, was sealed by checkpoint...

 

0 Kudos
the_rock
Legend
Legend

So if you go to clish mode and hit tab, do you see all the options come up? If so, does it let you run any of the commands listed there at all?

0 Kudos
mischelw
Contributor

When I enter Clish:

You can't start interactive session from another interactive session.
Exit expert mode and return to clish.

Exit expert and Clish doesn't work at all.

0 Kudos
the_rock
Legend
Legend

Odd...and if you do a reboot of the gateway, is it same problem?

0 Kudos
mischelw
Contributor

Yes

0 Kudos
the_rock
Legend
Legend

Not sure if you seen below, but if not, it might be worth trying temporary workaround:

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

the_rock
Legend
Legend

Can you tell us if below procedure worked?

0 Kudos
mischelw
Contributor

Not sure it is relevant to my specific case, solution is from 2015, my device is from 2021 with latest firware, just too afraid to apply and to break something else...

 

0 Kudos
the_rock
Legend
Legend

Thats true, but, if I were you, I would copy the content of that directory before doing anything though...maybe if you open official TAC case, they can confirm for you? I really dont want to take liberty here and say process would not break anything, as I have no clue if thats a fact.

0 Kudos
mischelw
Contributor

Will do so. thanks!

the_rock
Legend
Legend

Please keep us posted, because I know issues like this can be very frustrating.

mischelw
Contributor

All started to work as soon as I activated the license of the device, including it now shows the correct device model type (in my case 1570).

Seems that when the device is not activated it shows a general 1500 type as the hardware is the same, its just a matter of license which gives it identity.

 

Thanks all for trying to assist.

the_rock
Legend
Legend

Interesting...good to know!!

0 Kudos
G_W_Albrecht
Legend Legend
Legend

I woulddare to not post any issue while exploring an unlicensed device 😎 Come on - you surely know you can not work with a unit that is not activated at all! You could simply use the PnP Eval license for some time, too.

Your guess is good - the license restricts the enabled CPU cores and thruput, this is true! But only the hardware of 1570 and 1590 models is the same, and of 1530 / 1550 models - but not for all four 1500, see for yourself the hardware differences in the data sheet !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
mischelw
Contributor

I was using the trial license, not an unlicensed device (some credit , please !). the idea of the trial license is to check everything works as expected and then you can activate (in case device doesn't meet the expectations, is not usable as expected, etc).

What was misleading is that I have a college with the same device and it was showing 1590 even though it was still in trial license. this is what puzzled me and why I asked here the forum so I can get some insight.

 

I know exactly the difference between models, and that is exactly why I chose the 1570 and not the 1590 to my needs.

G_W_Albrecht
Legend Legend
Legend

Sorry, You did not write that before 😎 - and indeed, with the trial active you can use all features for the restricted time, a model e.g. 1570 is shown and your issues should not have occured at all ! You must be the victim of some bug o.s.e., this is not the standard behaviour !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Tom_Hinoue
Advisor
Advisor

Maybe your college was using an old firmware like R80.20.01/R80.20.02?
I remember the first releases showed CP1550/CP1590 out of the box, since CP1530/CP1570 model was not fully supported back then, which may explain the issue.

It should be from around R80.20.02 or R80.20.05 where the First Time Wizard and the logo in WEB UI expression was changed to [1500], where after activation the correct model (1530/1550/1570/1590) is shown.

Hope it answers your question.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

That is very interesting and explains why model number was not shown - but not the clish command issues that were experienced !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
Tom_Hinoue
Advisor
Advisor

@G_W_Albrecht 
haha, totally missed the original issue after all the comments XD

@mischelw 
but it sounds like to me your experiencing the error (interactive session error) that occurs when trying to run single clish command like "clish -c show version" after entering expert from a existing clish shell...

after login...
1. default shell (clish)
2. enter expert mode
3. run "clish -c show..."

in this case, the clish should run in (1.) (plain console/SSH login), or else bashUser needs to be enabled for running "clish"

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events