CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-10-21
Junior Member
 
Join Date: 2008-06-11
Posts: 10
Rep Power: 0
darkprince21 has an average reputation (10+)
Default Console password reset

Hi everbody,

How I can reset the console password ?
Reply With Quote
  #2 (permalink)  
Old 2008-10-21
Senior Member
 
Join Date: 2006-03-08
Posts: 122
Rep Power: 3
varera has an average reputation (10+)
Default Re: Console password reset

Quote:
Originally Posted by darkprince21 View Post
Hi everbody,

How I can reset the console password ?
there are 3 different scenarios for this:

admin is lost, but expert is known
admin is known but expert is lost
both passwords are lost.

please specify your case.

If you have access to CP UC, look there for SPLAT Expert Mode Tips guide, it addresses all three cases.
__________________
-------------
Sincerely,
Valeri Loukine
CCMA-0019
Reply With Quote
  #3 (permalink)  
Old 2008-11-04
Junior Member
 
Join Date: 2008-04-30
Posts: 9
Rep Power: 0
kaerez has an average reputation (10+)
Default Re: Console password reset

Quote:
Originally Posted by varera View Post
there are 3 different scenarios for this:

admin is lost, but expert is known
admin is known but expert is lost
both passwords are lost.

please specify your case.

If you have access to CP UC, look there for SPLAT Expert Mode Tips guide, it addresses all three cases.
Not sure what you're talking about... :-)
s-box's do NOT have an expert mode - it's not SPLAT.
If you have another admin user - you can enter that way, if not - then if the appliance is managed by an SMP you can have the op.'s reset it.
If that's out - then only a reset.
Reply With Quote
  #4 (permalink)  
Old 2008-11-04
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 308
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Console password reset

Quote:
Originally Posted by kaerez View Post
If you have another admin user - you can enter that way, if not - then if the appliance is managed by an SMP you can have the op.'s reset it.
How do you do that through the Checkpoint SMS?
The only way I know is do a remote reset but then you can only set a new password by locally connecting to it. And this will only work when you have the 'old' management software running in the background.
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS
Reply With Quote
  #5 (permalink)  
Old 2008-11-05
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Console password reset

Quote:
Originally Posted by varera View Post
look there for SPLAT Expert Mode Tips guide
Valeri, this is Check Point VPN-1 Edge Appliances forum. Edges don't run on SecurePlatform (SPLAT).

Quote:
Originally Posted by msjouw View Post
How do you do that through the Checkpoint SMS?
In Check Point SmartDashboard open your Edge object > Advanced > Configuration Script.
Fill in the following command:
add users name cpugadmin password {S}jj8xLictKC2I adminaccess readwrite vpnaccess true filteroverride false hotspotaccess false rdpaccess false expire never

Install the security policy to you Edge appliance and once the Edge pulled down its new policy you can login as cpugadmin/cpugadmin
The same way you could reset the console password for your admin user.

Why wasn't that clear to everyone?
Reply With Quote
  #6 (permalink)  
Old 2008-11-05
Senior Member
 
Join Date: 2006-03-08
Posts: 122
Rep Power: 3
varera has an average reputation (10+)
Default Re: Console password reset

Quote:
Originally Posted by kaerez View Post
Not sure what you're talking about... :-)
s-box's do NOT have an expert mode - it's not SPLAT.
If you have another admin user - you can enter that way, if not - then if the appliance is managed by an SMP you can have the op.'s reset it.
If that's out - then only a reset.
oops, my bad.

do not know any way other then go to factory default

you nay need to save config script to restore the policy settings. you will need to remove user/pasword part of the script manyally
__________________
-------------
Sincerely,
Valeri Loukine
CCMA-0019
Reply With Quote
  #7 (permalink)  
Old 2008-11-05
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 308
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Console password reset

Dantro,

Very nice..... if it would work.
I get the validation error message Add without Clear at line 1.
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS
Reply With Quote
  #8 (permalink)  
Old 2008-11-05
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Console password reset

So place a clear users
before the add users ... command. Similar to what can be found in a .cfg configuration export.
Reply With Quote
  #9 (permalink)  
Old 2008-11-07
Junior Member
 
Join Date: 2008-11-07
Posts: 1
Rep Power: 0
Sergio Tachini has an average reputation (10+)
Default Management console not recording all logs

i am find that the management console is not recording the logs all the time. It stops recording once or twice a day. Have you come across this?
Reply With Quote
  #10 (permalink)  
Old 2008-11-07
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 308
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Console password reset

Dantro,

As we are using IP40, IP45 and IP60's (edge industrial) in different customer locations, this is sometimes a daunting task. These IP 4x's need a
set users # name cpugadmin password xxxxx etc command
this # is the user ID where for the admin user # = 1
So the Clear before a add is somewhat difficult to do as it also requires taht number. Even worse is that an IP4x will tell you that you cannot change tha password locally as 'This feature is remotely managed
The IP60's do not have these limitations.
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:45.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0