Check Point Gaia CLI: Expert Mode, Backup and Restore - 夜莺博客

Check Point Gaia CLI: Expert Mode, Backup and Restore

Check Point security gateways run Gaia OS, and Gaia has two shells with very different rules: Gaia Clish for configuration, and Expert mode for low-level system work. Confusing the two is the source of most failed changes — commands that work in one shell are explicitly unsupported in the other, and configuration changes that are never saved with save config disappear at the next reboot. This guide covers the shell model, the backup and restore commands worth knowing by heart, and the operational discipline that keeps a gateway recoverable.

Clish versus Expert mode

The default shell is clish, a restrictive shell where role-based administration controls which commands are available. Clish is the correct place for anything that is a Gaia configuration item. Expert mode is a permissive bash shell for the tasks clish deliberately hides.

# from clish
expert

# back to clish from Expert mode
exit

Two rules prevent mistakes. First, if a command exists in Gaia Clish, the corresponding low-level command is not supported in Expert mode — for interfaces, use show interface and set interface in clish rather than ifconfig in Expert. Second, Expert mode is not a privilege escalation: it does not grant more rights than the account already has, it grants more configuration surface. The clish role still decides what the account may do.

Because Expert mode is unrestricted, the practical security measure is to set a separate Expert password, since there is no default and the shell is unusable until you configure one:

set expert-password
set expert-password-hash <hash-string>

The salted-hash form is the right choice for automated builds and restore scripts, because it avoids embedding a plaintext password in a provisioning file. Hashes can be generated with cpopenssl passwd.

Running clish commands from Expert mode

clish -c "show interfaces"
clish -f /path/to/commands.txt -i

This is how you script Gaia configuration: build a file of clish commands and feed it through clish -f. It is far more reliable than driving the interactive shell.

Backup: the commands that save a bad night

A Gaia backup contains the Gaia OS configuration and, on a management server, the security management database. It is written as a .tgz archive and can be stored locally or pushed to a remote server.

# local backup
add backup local

# remote backups
add backup scp ip 10.10.10.50 path /backups username cpadmin
add backup ftp ip 10.10.10.60 path /backups username cpadmin
add backup tftp ip 10.10.10.70

# status and inventory
show backup status
show backup last-successful
show backups

Output looks like this:

gaia> add backup local
Creating backup package. Use the command 'show backups' to monitor creation progress.
gaia> show backup status
Performing local backup

One precondition catches people out: before backing up a Security Management Server, close all SmartConsole clients, or the backup will not start. Schedule backups rather than relying on memory, and push them off the device — a backup stored on the gateway you are about to rebuild is not a backup.

Restore

set backup restore local
set backup restore scp ip 10.10.10.50 path /backups file gw1-backup.tgz username cpadmin
set backup restore ftp ip 10.10.10.60 path /backups file gw1-backup.tgz username cpadmin
set backup restore tftp ip 10.10.10.70 file gw1-backup.tgz

A backup restores onto a system with the same software version, Jumbo Hotfix Accumulator and hotfix level as the source. Restoring a backup onto a differently patched gateway is not supported and is a common cause of a gateway that boots into an unexpected state.

For fast recovery of configuration settings alone, Gaia can also export the configuration as a ready-to-run CLI shell script, which is useful for migration and for diffing a golden configuration against a live device.

The save config discipline

After adding, configuring or deleting features, run:

save config

Gaia Clish changes are staged in the running configuration. Without save config, a reboot reverts them — and the resulting "the firewall lost its interface configuration" incident is entirely avoidable. Make it the last line of every change script.

Practical routine

  • Backup before every change window, verify with show backups, and confirm the archive size looks sane.
  • Keep the Expert password in your secrets manager; treat it as a break-glass credential.
  • Record the exact Jumbo HFA level on the box so restore compatibility is never a guessing game.
  • Prefer clish for configuration and Expert mode only for diagnosis, log inspection and OS-level work.
  • Compare practices across vendors: the backup model on Palo Alto configuration backup and the recovery workflow on FortiGate firmware reinstall both solve the same problem with different tools.

原文链接:https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_AdminGuide/Topics-GAG/Expert-Mode.htm