- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
I am having issues in applying the cp commands as it gives me permission denied as follows:
Last login: Tue Aug 15 13:56:27 2023 from 10.21.0.254
-bash: /etc/hcp/conf/.new_hcp_take_installed: Permission denied
rm: cannot remove '/etc/hcp/conf/.new_hcp_take_installed': Permission denied
-bash: /bin/fwaccel_autocomplete.sh: No such file or directory
[Expert@Mgmt]# cphaprob stat
-bash: cphaprob: command not found
[Expert@Mgmt]# cplic print
-bash: cplic: command not found
[Expert@Mgmt]# clish
CLINFR0771 Config lock is owned by ca_ocd_ladmin. Use the command 'lock database override' to acquire the lock.
Mgmt> cpprob stat
CLINFR0329 Invalid command:'cpprob stat'.
Mgmt> cplic print
/tmp/.CPprofile.sh: line 1: /opt/CPshrd-R81.10/scripts/cpprofile_functions.sh: Permission denied
Mgmt>
the user account that i use is the same as the user account of admin with shell : /etc/cli.sh , i tried with the another shell with /bin/bash but in vain too.
There is no authentication raduis configued just accounts to access the WebUI of the firewall. Any ideas ?
Thank you
Turns out the uid in the end when i changed it to 0 instead of 104 uid assigned earlier it worked fine afterwards.
Please look into sk120972
Do you have other admin accounts where this works?
Hello Val,
Yes the default admin account , i just noticed that i changed the account i am using to the same uid for the default admin account and it worked afterwards.
Seems a strange way to make it work , but it worked in the end.
Thank you.
This is not a fix. Something was misconfigured with your non-working account, and now you do not know what exactly. Check the user role it was created with.
the user role that it's assigned too is the same as admin and i thought of changing the uid back to 0 same as admin account , this is where it started working as intended.
As Val said, something efinitely would have been misconfigured with the other account. If default admin account works fine, then its either permission issue or UID.
Andy
Its like below:
Turns out the uid in the end when i changed it to 0 instead of 104 uid assigned earlier it worked fine afterwards.
I am facing same issue with some of the gateways. I login with my ID which is Non-Gaia (non_local) user ID using TACACS authentication. Then elevate privilege to TACP-15 and jump to Expert. As the user doesn't exist in GAIA configuration, I can't set UID 0. This issue is only on few gateways, while in large number of other gateways, it works fine. I am sure there is no difference in configuration of all these gateways.
I welcome any suggestions.
Hi,
I have the same behavior with RADIUS users.
I tried to set "Super User UID" parameter to "0" but still have the problem.
Any idea?
Please look into sk120972
Hello Valery,
thank you for your help. We finally configured the given sk120972 which solved the problem. I can also confirm that it works with both /etc/cli.sh and /bin/bash shells.
We used Cisco ISE in order to pass the 2 parameters: CP-Gaia-User-Role and CP-Gaia-SuperUser-Access.
Any experience with Okta? It seems like it cannot pass more than 1 parameter.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
12 | |
7 | |
6 | |
5 | |
4 | |
4 | |
4 | |
4 | |
4 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY