List of Available Features in Roles

Important:

  • Read the Scalable Platforms Known Limitations in sk148074.

  • Read the R80.20 Known Limitations in sk122486.

  • To learn about the differences between R80.20 and R80.20SP versions, see sk147033.

    To learn about the differences between different Scalable Platform versions, see sk173183.

Feature name in
Gaia Portal

Feature name in
Gaia Clish / Gaia gClish

Description

Affected commands
in Gaia Clish / Gaia gClish

Authentication Servers

aaa-servers

Controls authentication through external RADIUS or TACACS+ server.

set aaa radius-servers *
set aaa tacacs-servers *
delete aaa radius-servers *
delete aaa tacacs-servers *
add aaa radius-servers *
add aaa tacacs-servers *
show aaa radius-servers *
show aaa tacacs-servers *

Advanced VRRP

adv-vrrp

Controls the Advanced Virtual Router Redundancy Protocol (VRRP)

set vrrp *
show vrrp *

Appliance Maintenance

prod-maintain

Controls access to the "Overview" page for Appliance Maintenance.

 

ARP

arp

Controls ARP - dynamic ARP entries, static ARP entries, and proxy ARP entries.

add arp *
delete arp *
set arp *
show arp *

Banner Messages

message

Controls the Banner Message and Message of the Day.

set message *
delete message *
show message *

BGP

bgp

Controls dynamic routing through the Border Gateway Protocol (BGP).

set as *
set router-id *
set bgp *
show route bgp *
show as *
show router-id *
show bgp *

Blades Summary

blades

Shows summary for enabled Software Blades.

 

Certificate Authority

certificate_authority

Controls the Certificate Authority on a Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server..

cpca_client

Change My Password

selfpasswd

Changes your user account password.

set selfpasswd *

Cloning Group

CloningGroup

Controls the configuration of GaiaClosed Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. Cloning Groups.

set cloning-group *
add cloning-group *
delete cloning-group *
join cloning-group *
re-synch cloning-group *
leave cloning-group *
show cloning-group *

Cloning Group Management

CloningGroupManagement

Controls the management of Gaia Cloning Groups.

set cloning-group-management *

ClusterClosed Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing.

cluster

Controls clustering.

add cluster *
set cluster *
delete cluster *
show cluster *

Core Dump

core-dump

Controls core dumps.

set core-dump *
show core-dump *

DHCP Relay

bootp

Controls the Relay of IPv4 DHCP and IPv4 BOOTP messages between DHCP clients and DHCP servers on different IPv4 networks.

set bootp *
show bootp *

DHCP Server

dhcp

Controls the DHCP Server configuration.

set dhcp service *
delete dhcp service *
set dhcp client *
delete dhcp client *
add dhcp client *
set dhcp server *
delete dhcp server *
add dhcp server *
show dhcp service *
show dhcp client *
show dhcp server *

DHCPv6 Relay

dhcp6relay

Controls the Relay of DHCPv6 messages between DHCP clients and DHCP servers on different IPv6 networks.

set ipv6 dhcp6relay *
show ipv6 dhcp6relay *

Display Configuration

configuration

Saves and show the Gaia configuration.

save configuration *
show configuration *

Display Format

format

Controls the format of time, date, and netmask.

set format *
show format *

DNS

dns

Controls the DNS Server configuration.

set dns *
delete dns *
show dns *

Domain Name

domainname

Controls the domain name configuration.

set domainname *
delete domainname
show domainname

Download SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on.

smart-console

Downloads the SmartConsole from the Gaia PortalClosed Web interface for the Check Point Gaia operating system..

N / A

Expert ModeClosed The name of the elevated command line shell that gives full system root permissions in the Check Point Gaia operating system.

expert

Access to the Expert mode shell.

expert

Expert Password

expert-password

Changes the Expert mode password (interactive).

set expert-password

Expert Password Hash

expert-password-hash

Changes the Expert mode password using password hash.

set expert-password-hash *

Extended Commands

command

Controls the ability to define additional Extended Commands for the Gaia ClishClosed The name of the default command line shell in Check Point Gaia operating system. This is a restricted shell (role-based administration controls the number of commands available in the shell)..

add command *
delete command *
show command *
show commands
show extended *

Factory Defaults

fcd

Restores the Gaia OS to Factory Defaults.

set fcd *
show fcd *

Firewall Management

firewall_management

Controls the Login and Logout on a Management Server.

mgmt *

Front Panel

lcd

Controls the front panel LCD available on some Check Point appliances.

set lcd *
show lcd *

Hardware Health

hw-monitor

Controls the hardware sensor monitoring.

show sysenv all
cpstat -f sensors os

High Availability

high-avail-group

Controls the "Overview" page for High Availability.

 

Host Access

host-access

Controls which hosts are allowed to connect to Gaia.

add allowed-client *
delete allowed-client *
show allowed-client *

Host Address

host

Controls known hosts and their IP addresses.

add host *
set host *
delete host *
show host *

Host Name

hostname

Controls the Gaia hostname.

set hostname *
show hostname *

IGMP

igmp

Controls multicast group memberships through the Internet Group Management Protocol (IGMP).

set igmp *
show igmp *

Inactivity timeout

inactto

Controls the inactivity timeout for Gaia Portal and Gaia Clish.

set inactivity-timeout *
show inactivity-timeout *

Inbound Route Filters

import

Controls the IPv4 Inbound Route Filters for RIP, OSPFv2, and BGP IPv4.

set inbound-route-filter *

Inbound Route Filters

import6

Controls the IPv6 Inbound Route Filters for RIPng, OSPFv3, and BGP IPv6.

set ipv6 inbound-route-filter *

Installation

ftw

Runs the Gaia First Time Configuration Wizard.

 

Interface Naming

interface-name

Controls a different name for an existing interface (requires a reboot and reconfiguration of the interface).

set interface-name *

IP Broadcast Helper

iphelper

Controls the forwarding of UDP broadcast traffic to other interfaces.

set iphelper *
show iphelper *

IP Reachability Detection

ipreachdetect

Controls the reachability detection of IP Addresses.

set ip-reachability-detection *
show ip-reachability-detection *

IPv4 Static Routes

static-route

Controls IPv4 static routes.

set static-route *
show route static *

IPv6 Router Discovery

ipv6rdisc6

Controls the IPv6 router discovery.

set ipv6 rdisc6 *
show ipv6 rdisc6 *

IPv6 State

ipv6-state

Controls the IPv6 stack.

set ipv6-state *
show ipv6-state

IPv6 Static Routes

static6

Controls IPv6 static routes.

set ipv6 static-route *
show ipv6 route static *

IPv6 VRRP

vrrp6

Controls the IPv6 Virtual Router Redundancy Protocol (VRRPv3).

set ipv6 vrrp6 *
show ipv6 vrrp6 *

Job Scheduler

cron

Controls scheduled automated tasks that perform actions at a specific time.

add cron *
set cron *
delete cron *
show cron *

License Activation

license_activation

Controls access to the "Activate Licenses" page.

cplic

License Configuration

license

Controls access to the "Manage License" page.

cplic

Lights Out Management (LOM) Configuration

lom

Shows the Lights Out Management (LOM) Configuration.

show lom *

Mail Notification

ssmtp

Controls mail notifications Gaia sends.

set mail-notification *
show mail-notification *

Maintenance

maintenance-group

Controls access to the "Overview" page for Maintenance.

N / A

Management InterfaceClosed (1) Interface on a Gaia Security Gateway or Cluster member, through which Management Server connects to the Security Gateway or Cluster member. (2) Interface on Gaia computer, through which users connect to Gaia Portal or CLI.

management_interface

Controls which interface is used for management (main interface).

set management *
show management *

NDP

neighbor

Controls the IPv6 Neighbour Discovery Protocol.

add neighbor-entry *
set neighbor *
delete neighbor-entry *
show neighbor *

NetFlow Export

netflow

Controls the NetFlow Export.

add netflow *
set netflow *
delete netflow *
show netflow *

Network Access

netaccess

Controls the TELNET access to Gaia.

set net-access *
show net-access *

Network Interfaces

interface

Controls interface configuration:

  • Physical

  • Alias

  • Bond

  • Bridge

  • VLAN

  • PPPoE

  • GRE

set interface *
add interface *
delete interface *
add bonding *
set bonding *
delete bonding *
add bridging *
set bridging *
delete bridging *
add pppoe *
delete pppoe *
set pppoe *
add gre *
delete gre *
show interface *
show interfaces
show bonding *
show bridging *
show pppoe *
show gre *

Network Management

interface-group

Controls access to the "Overview" page for Network Management.

show interface *
show interfaces *
set interface *

NTP

ntp

Controls the Network Time Protocol for synchronizing the Gaia clock.

add ntp *
set ntp *
delete ntp *
show ntp *

OSPF

ospf

Controls IPv4 dynamic routing through the Open Shortest-Path First protocol (OSPFv2).

set ospf *
show ospf *
show route ospf *

OSPF v3

ospf3

Controls IPv6 dynamic routing through the Open Shortest-Path First protocol v3 (OSPFv3).

set ipv6 ospf3 *
set router-id *
show ipv6 ospf3 *
show ipv6 route ospf3 *
show router-id *

Password Policy

password-controls

Controls password and account policies.

set password-controls *
show password-controls *

Performance Optimization

perf

Controls Multi-Queue on a Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources..

set multi-queue *
show multi-queue *

PIM

pim

Controls the Protocol-Independent Multicast (PIM) configuration.

set pim *
show pim *
show mfc *

Policy Based Routing

pbr-combine-static

Controls policy based routing rules and action tables.

set pbr *
set pbrroute *
show pbr *
show pbrroute *

Policy Routing

pbr-routing-group

Controls access to the "Overview" page for Policy Based Routing.

set pbr *
set pbrroute *
show pbr *
show pbrroute *

Prefix Lists and Prefix Trees

prefix

Controls Prefix Lists and Prefix Trees used in routing policy.

set prefix-tree *
set prefix-list *

Proxy Settings

proxy

Controls the Proxy Server configuration.

set proxy *
delete proxy *
show proxy *

RAID Monitoring

raid-monitor

Controls access to the "Overview" page for RAID volumes monitoring.

raidconfig
raid_diagnostic

RIP

rip

Controls dynamic routing through the Routing Information Protocol for IPv4 (RIP).

set rip *
show rip *

RIPng

ripng

Controls dynamic routing through the Routing Information Protocol for IPv6 (RIPng).

set ipv6 ripng *
show ipv6 ripng *

Roles

rba

Controls user roles.

add rba *
delete rba *
show rba *

Route

route

Shows IPv4 and IPv6 routing table.

show route *
show ipv6 route *

Route Aggregation

aggregate

Creates a supernet network from the combination of networks with a common routing prefix.

set aggregate *
show route aggregate *

Route Injection Mechanism

route-injection

Controls the Route Injection Mechanism (RIM).

set kernel-routes *
show route kernel *

Route Map

routemap

Controls route map configuration.

set routemap *
show routemap *
show routemaps *

Route Redistribution

export

Controls advertisement of IPv4 routing information from one protocol to another.

set route-redistribution *

Route Redistribution

export6

Controls advertisement of IPv6 routing information from one protocol to another.

set ipv6 route-redistribution *

Routed ClusterXL

routed-cluster

Controls how the RouteD daemon interacts with ClusterXL on Gaia.

set routed-clusterxl *
show routed-clusterxl *

Router Discovery

rdisc

Controls the ICMP Router Discovery on Gaia.

set rdisc *
show rdisc *

Router Service

router-service-group

Controls access to the "Overview" page for Routing Services.

 

Routing Monitor

show-route-all

Shows summary information about routes.

show route *

Routing Options

route-options

Controls protocol ranks and trace (debug) options.

set routedsyslog *
set trace *
set tracefile *
set max-path-splits *
set nexthop-selection *
set protocol-rank *
set router-options *
show trace *
show routed *
show protocol-rank *
show router-options *

SAM (Accelerator Card)

sam

Deprecated.

show sam *

Scheduled Backup

sceduled_backup

Controls Gaia scheduled backups.

add backup-scheduled *
set backup-scheduled *
delete backup-scheduled *
show backup-scheduled

Scratchpad Configuration

scratchpad

Controls the Scratchpad in the Gaia Portal.

N / A

Security Management GUI Clients

mgmt-gui-clients

Controls the allowed Security Management GUI Clients.

 

Shutdown

reboot_halt

Controls the shutdown and reboot of Gaia.

halt *
reboot *

Snapshot

snapshot

Controls Gaia snapshots.

add snapshot *
set snapshot *
delete snapshot *
show snapshots
show snapshot *

SNMP

snmp

Controls Gaia monitoring through the Simple Network Management Protocol (SNMP).

add snmp *
set snmp *
delete snmp *
show snmp *

Software Updates Policy Management

installer_conf

CPUSEClosed Check Point Upgrade Service Engine for Gaia Operating System. With CPUSE, you can automatically update Check Point products for the Gaia OS, and the Gaia OS itself. For details, see sk92449. - Manage deployment policy and mail notifications for software updates.

Note - See sk92449 for the most updated information.

installer restore_policy *
set installer *
set installer download_mode *
set installer install_mode *
set installer download_mode schedule *
set installer install_mode schedule *

Static Multicast Routes

static-mroute

Controls multicast static routes.

set static-mroute *
show static-mroute *

System Asset

asset

Shows the hardware asset summary.

show asset *

System Backup

backup

Controls Gaia backups.

add backup *
set backup *
backup *
restore *
delete backup *
show backups
show backup *
show restore *

System Configuration

sysconfig

Shows the System Configuration.

show configuration *

System Groups

group

Controls the Gaia user groups, for advanced management of privileges.

add group *
set group *
delete group *
show groups
show group *

System Logging

syslog

Controls system logging.

add syslog *
set syslog *
delete syslog *
show syslog *

System Management

system-group

Controls access to the "Overview" page for System Management.

 

System Status

sysenv

Shows the hardware sensor information.

show sysenv *

TACACS_Enable

tacacs_enable

Controls the TACACS+ configuration.

tacacs_enable *
show tacacs_enable *

Time

clock-date

Controls the time and date configuration.

set clock *
set date *
set time *
set timezone *
show clock *
show date *
show time *
show timezone *

Upgrade

upgrade

Deprecated - use the CPUSE.

upgrade *
add upgrade *
delete upgrade *
show upgrade *

Upgrades (CPUSE)

installer

CPUSE - Controls the software packages.

Note - See sk92449 for the most updated information.

show installer *
show installer available_packages *
show installer available_local_packages *
show installer installed_packages *
show installer package_status *
add installer *
add installer private_url *
installer *
installer download *
installer install *
installer upgrade *
installer uninstall *
installer stop *
installer start *
installer restore_policy *
set installer *
set installer download_mode *
set installer install_mode *
set installer download_mode schedule *
set installer install_mode schedule *

Upgrades (CPUSE)

software-updates-group

Controls access to the "Overview" page for CPUSE.

show installer *
set installer *
installer agent *

User Management

security-access-group

Controls access to the "Overview" page for User Management.

 

Users

user

Controls user accounts.

add user *
set user *
delete user *
show user *
show users *

Version

version

Shows the version of the installed Check Point product, and Gaia build and kernel.

show version *

Virtual-System

virtual-system

Controls VSXClosed Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Security Gateways and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. Virtual Systems (in CLI only).

You must configure all Virtual Systems in SmartConsole only.

add virtual-system *
set virtual-system *
delete virtual-system *
show virtual-system *

VPNT

vpnt

Controls the VPN Tunneling.

add vpn *
set vpn *
delete vpn *

VRRP

vrrp

Controls the IPv4 Virtual Router Redundancy Protocol (VRRPv2) - Monitored Circuit/Simplified VRRP.

set vrrp *
add mcvr *
set mcvr *
delete mcvr *
show vrrp *
show mcvr *

VSX

vsx

Controls the VSX mode (to be used only by Check Point Support only).

set vsx *
show vsx *

Web configuration

web

Controls the Gaia Portal.

set web *
generate web *
show web *