- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
HI All,
When I login into Security gateway over SSH I am taking to directly to expert prompt login as showing below:
*************************************************************************
[Expert@nwseg1-pd-fw01:0]# pwd
/home/_nonlocl
But when I change to clish and give expert password throwing wrong password. Firewall is integrated with RADIUS (ISE)
My ISE team told I will use same password for login. Am I am landing on expert level, how I can verify I have expert level access.
When I check our community when I land on nonlocal doesn't get into expert level
"Expert" is really just BASH with root-level permissions. You can't go from BASH into clish, then back into BASH.
To confirm you have root privileges, run 'whoami'. It should show you are 'admin'.
As @Bob_Zimmerman saud, you can run whoami and verify that. By the way, you can always change the mode by below command.
Lets assume admin username is simply admin, command would be as below:
chsh -s /etc/cli.sh admin
You can also do it from web UI from below screen:
[Expert@quantum-firewall:0]# whoami
admin
[Expert@quantum-firewall:0]#
"Expert" is really just BASH with root-level permissions. You can't go from BASH into clish, then back into BASH.
To confirm you have root privileges, run 'whoami'. It should show you are 'admin'.
" You can't go from BASH into clish, then back into BASH"
- Is that a limitation of an account via Radius or TACACS? On a local account (i.e Admin), if I set the 'Shell' to '/bin/bash', it does land in BASH upon a SSH login. Typing 'clish' puts me into clish mode. If you type 'exit' it does take you back to the shell. (I.e. have to exit twice to end the SSH session if in direct clish mode).
Am I missing something? I have inquiry for either TACAC or Radius to avoid 'sharing' the 'expert' password (i.e Admin users direct to BASH; read only users direct to clish) so curious myself if there is some limitations to consider.
@ramakrishnan If you are doing Radius, what is the Super User UID you have set under "User Management => Authentication Servers =>"Radius Servers Advance Configuration". Is it 96 or 0?
You can leave clish, but you can't start another BASH session. That is, you can't log in to BASH, then run 'clish' to get into clish, then run 'expert' to get back into BASH. People try that all the time and are confused when they can "no longer get into expert mode".
As @Bob_Zimmerman saud, you can run whoami and verify that. By the way, you can always change the mode by below command.
Lets assume admin username is simply admin, command would be as below:
chsh -s /etc/cli.sh admin
You can also do it from web UI from below screen:
[Expert@quantum-firewall:0]# whoami
admin
[Expert@quantum-firewall:0]#
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY