- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi everyone,
I found an interesting part of documentation regarding the Integer Kernel Parameters and String Kernel Parameters.
It is possible with a command to show a list of all the parameters and string and the values that have been set.
This is stated in: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Conten...
These are the steps for Integer parameters:
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms (Maestro and Chassis), you must connect to the applicable Security Group. |
|||
|
2 |
Log in to the Expert mode. |
|||
|
3 |
Make sure you can get the list of the available integer kernel parameters and their values without errors:
|
|||
|
4 |
If in the previous step there were no errors, get the list of the available integer kernel parameters and their values, and save the list to a file:
|
|||
|
5 |
Analyze the output file:
|
For string it is similar:
|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. Note - On Scalable Platforms (Maestro and Chassis), you must connect to the applicable Security Group. |
|||
|
2 |
Log in to the Expert mode. |
|||
|
3 |
Make sure you can get the list of the available integer kernel parameters and their values without errors:
|
|||
|
4 |
If in the previous step there were no errors, get the list of the available string kernel parameters and their values, and save the list to a file:
|
|||
|
5 |
Analyze the output file:
|
I have tried step 3 on a few gateways but it get's stuck on different parameter and does not proceed with the rest.
Step 4 output file contains only an error.
Anyone has an idea how to generate the full list and skip the ones that give an error?
Expample:
(I cut out the above parameters)
bypass_on_enhanced_ssl_inspection = 0
bypass_reverse_dns_rad_request = 1
ccc_in_separate_daemon = 0
ccc_policy_timestamp = 0
Get operation failed: failed to get parameter ccl_correct_dr_between_chassis
get: Operation failed
xargs: fw: terminated by signal
Different gateway:
fwconn_tracker_monitor = 'default'
fwha_azure_default_mac = '12:34:56:78:9a:bc'
fwha_group_of_bonds_str = ''
Get operation failed: failed to get parameter fwha_mbs_amw_policy_time_formated_str
get: Operation failed
xargs: fw: terminated by signal 9
Good stuff!
I also tried few fiewalls in the lab and get below on step 3, I guess its expected?
Andy
inline_zp_script = ''
kiss_branch_name = 'unknown'
kiss_flofiler_active = ''
kiss_memory_report_filter = '*'
Get operation failed: failed to get parameter mgmt_forwarding_tcp_ports_list_string
get: Operation failed
xargs: fw: terminated by signal 9
This is also documented here which is a bit more updated: sk33156: Creating a file with all the kernel parameters and their values
I had customer ask me once if it was possible to say run command that would clearly show all kernel parameters and what the impact would be having them turned on. I brought that up to their Sales person as well, but not sure something like that exists.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY