CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-05
BryDwy BryDwy is offline
Junior Member
 
Join Date: 2006-10-07
Location: Illinois
Posts: 16
Rep Power: 0
BryDwy has an average reputation (10+)
Default New Administrator Grayed Out

Our primary Checkpoint Admin recently left the company. Management deleted his account in Checkpoint. Apparently, his account was the only one that had permission to add or delete Administrator accounts because when I am logged into SmartDashboard with my account those options are grayed out. Is there a way to get an account created that does have the correct permissions? We are using NGX R60. Any help would be much appreciated.
Reply With Quote
  #2 (permalink)  
Old 2008-02-05
Tommo Tommo is offline
Junior Member
 
Join Date: 2007-02-23
Posts: 27
Rep Power: 0
Tommo has an average reputation (10+)
Default Re: New Administrator Grayed Out

Hi BryDwy,

Simples way is to do this through cpconfig on the smartcentre.

Depends on version, but, something like this (taken from my splat VM):

Login into the smartcentre (command line) is easiest
run cpconfig
chose administrators (option2)
(admins list is shown)
Do you want to modify this list (Yes)
Do you want to delete an administrator (Yes)
enter the admin name to delete
Are you sure you want to continue (No)
Do you want to add an administrator (Yes)
enter the name
enter a password
confirm the password
Exit cpconfig

Now, log into the smartcentre with the new info. You can then go into the CP admins section, and update the profile for your account (to give you full access)

Hope this helps you out ;-)
Reply With Quote
  #3 (permalink)  
Old 2008-02-05
BryDwy BryDwy is offline
Junior Member
 
Join Date: 2006-10-07
Location: Illinois
Posts: 16
Rep Power: 0
BryDwy has an average reputation (10+)
Default Re: New Administrator Grayed Out

From the information that I have gathered thus far, in NGX R60, you are not able to add administrators through cpconfig except during the initial install. When I follow the steps you layed out it just deletes the account. It does not ask to verify and there is not an option to add an account. The only way to add an administrator account appears to be through SmartDashboard.
Reply With Quote
  #4 (permalink)  
Old 2008-02-05
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: New Administrator Grayed Out

Do you know the password for 'admin'? I think that account cannot be deleted.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #5 (permalink)  
Old 2008-02-05
BryDwy BryDwy is offline
Junior Member
 
Join Date: 2006-10-07
Location: Illinois
Posts: 16
Rep Power: 0
BryDwy has an average reputation (10+)
Default Re: New Administrator Grayed Out

I do not see an account for admin at all. I see no accounts listed when I use cpconfig and there are is only my account when you look in SmartDashBoard
Reply With Quote
  #6 (permalink)  
Old 2008-02-06
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: New Administrator Grayed Out

Quote:
Originally Posted by BryDwy View Post
I do not see an account for admin at all. I see no accounts listed when I use cpconfig and there are is only my account when you look in SmartDashBoard
I find that odd. At a minimum, you should see your account and a special group object named 'cpconfig_administrators'. That group should have the 'admin' account as a member. My SCS is R65 on Windows 2003 now (was previously upgraded from R60 which was also upgraded from R55p before that). The R55 was a new build that I did from scratch so that means the 'admin' account was created in R55p. I cannot modify that account except for changing the password. Which means I cannot reduce it's rights from god mode. Unless this is no longer the case in these newer versions, that account should be there with FULL rights to everything.

I've enlisted the aid of a guy on my company's Help Desk (he has read only in Dashboard). Under his extremely limited login, he can see the objects and open them but every option is grayed out, as one would expect.

Just based on your info, I would say that if you cannot even see these objects (it doesn't matter that you have admin level permissions), then your database may be corrupted.
__________________
There's no place like 127.0.0.1

Last edited by lammbo; 2008-02-06 at 07:40.
Reply With Quote
  #7 (permalink)  
Old 2008-02-06
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: New Administrator Grayed Out

Quote:
Originally Posted by BryDwy View Post
From the information that I have gathered thus far, in NGX R60, you are not able to add administrators through cpconfig except during the initial install.
You may only have one "cpconfig_admin" (unless it was an upgrade). That admin may be deleted and recreated from cpconfig as needed.
Reply With Quote
  #8 (permalink)  
Old 2008-02-06
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: New Administrator Grayed Out

Quote:
Originally Posted by chillyjim View Post
That admin may be deleted and recreated from cpconfig as needed.
So that would mean if the SCS is running on a Windows server and you can log into the server with Administrator permissions on the server, you can run the CPCONFIG GUI and own the admin account... I've used that method to change the Admin password before (when I first started CP) but I didn't know you could add and remove the account - good stuff. TY

Quote:
Originally Posted by BryDwy View Post
Management deleted his account in Checkpoint. Apparently, his account was the only one that had permission to add or delete Administrator accounts....
Have been thinking about this. Please elaborate more on the quoted text. Who is 'Management'?
You say his CP login was deleted, but someone had to be logged in with sufficient permission to delete an admin account (only another admin), unless he deleted himself before leaving (not sure if this is possible).

So that probably leaves an alternate login method where his CP account is tied to AD or something. Can you provide more details please.



chillyjim - can you delete an account you are logged in with?
__________________
There's no place like 127.0.0.1
Reply With Quote
  #9 (permalink)  
Old 2008-02-12
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: New Administrator Grayed Out

Any update on this? This was a good educational case and I would really like to know the outcome/fix.
__________________
There's no place like 127.0.0.1
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:24.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0