Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sajenthiran_Mic
Contributor

LOM settings - Direct acces onto Remote Console

We have multiple  5000 Appliance and to have a more direct way to access "Remote Console". Currently we have to login per https on to the LOM  - Management Interface. And start JViewer to access Remote Console.

I am looking for alternative.  I used  on openserver to use vnc to access directly the Remote console Window!!

How can i start the "Remote Console" using different Tool? I would prefer not to use a Webbrowser...

11 Replies
Vladimir
Champion
Champion

@Sajenthiran_Mic , the function of LOM is to provide the control of the appliance even in powerdown state, so long as it is power cords are connected. It is not simply a redirect of the console, but a means of hardware diagnostics, remote ISO mounting and rebuild, etc.

Console redirect is only one of its functions and in Check Point's case it does rely on .jnlp download and execution.

If you are simply looking to have remote console access with no advanced management capabilities, I suggest using Console Servers such as the one of the models described here:

https://www.perle.com/products/iolan-sds-terminal-server.shtml

Which will allow you to configure custom SSH port redirect to the console of the appliances.

On a side note, it is a high time for Check Point to redesign the LOM modules to allow SSH redirect to serial, remove Java dependency and replace it with HTML5 interface. 

Tommy_Forrest
Advisor

LOM is so helpful.  But dang.

It's 2019.  Why are we still being forced to use Java for stuff like this?

JozkoMrkvicka
Leader
Leader

Yes, we are living in 2019 and LOM is still only 100 MB interface ...

Not to mention, that the newest Smart-1 devices don't have LOM interface at all. The documentation says this "feature" will be added later ... ridiculous...

Kind regards,
Jozko Mrkvicka
0 Kudos
Tommy_Forrest
Advisor

I mean, a 100MB interface in-and-of-itself isn't a giant gaping security hole.

And a browser doesn't care if it is a 100MB interface.  At least it (unlike Java in modern browsers) will still work.

0 Kudos
JozkoMrkvicka
Leader
Leader

LOM can be used to mount ISO and perform a clean installation using LOM interface. If this is a case, you will upload 3 GB file over 100 MB interface.... just calculate how long it will take 🙂

Kind regards,
Jozko Mrkvicka
0 Kudos
Tommy_Forrest
Advisor

About 4 minutes.

0 Kudos
Daniel_Kavan
Advisor

It's 2022 .....and still using Java Console.    The windows security team has removed Oracle Java 8 & I can no longer remote in.   Is there any Java alternative?  So far testing with Temurin JDK 17 & JRE 11 with no luck.  html5 would be great.

0 Kudos
Dolev
Employee
Employee

0 Kudos
Tommy_Forrest
Advisor

The new Quantum series appliances will either ship with the new LOM card or you can order it if it is an older Quantum appliance (support for the new LOM card came out with the Quantum series gateways, but Check Point was a little slow getting them and many of the early Quantum gateways didn't come with the new LOM card automagically).

The new LOM cards support HTML5.

Chris_Atkinson
Employee
Employee

Depending on your appliance model you may still have to use Java, but not necessarily Oracle per sk147153.

Daniel_Kavan
Advisor

Thanks everyone.   I was able to get in with IcedTea and Java 8.

http://icedtea.wildebeest.org/download/icedtea-web-binaries/1.8/windows/

Temurin AdoptOpenJDK 8 JRE

 

 

0 Kudos