List of Available Features in Roles

Table: List of Available Features in Roles

Feature name in
Gaia Portal

Feature name in
Gaia Clish

Description

Affected commands
in Gaia Clish

Authentication Servers

aaa-servers

Configure authentication through external RADIUS or TACACS+ server.

set aaa radius-servers *
set aaa tacacs-servers *
delete aaa radius-servers *
delete aaa tacacs-servers *
add aaa radius-servers *
add aaa tacacs-servers *
show aaa radius-servers *
show aaa tacacs-servers *

Advanced VRRP

adv-vrrp

Configure the Advanced Virtual Router Redundancy Protocol (VRRP)

set vrrp *
show vrrp *

Appliance Maintenance

prod-maintain

Overview page for Appliance Maintenance.

 

ARP

arp

Control static ARP entries and proxy ARP entries. Control dynamic ARP entries.

add arp *
delete arp *
set arp *
show arp *

Banner Messages

message

Control Banner Message and Message of the Day.

set message *
delete message *
show message *

BGP

bgp

Configure dynamic routing through the Border Gateway Protocol (BGP).

set as *
set router-id *
set bgp *
show route bgp *
show as *
show router-id *
show bgp *

Blades Summary

blades

Show summary for enabled Software Blades.

 

cdt

cdt

Central Deployment Tool

show cdt *
set cdt *
start cdt *

Certificate Authority

certificate_authority

Control Certificate Authority.

cpca_client

Change My Password

selfpasswd

Change your user account password.

set selfpasswd *

Cloning Group

CloningGroup

Control GaiaClosed Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. Cloning Groups.

set cloning-group *
add cloning-group *
delete cloning-group *
join cloning-group *
re-synch cloning-group *
leave cloning-group *
show cloning-group *

Cloning Group Management

CloningGroupManagement

Control management of Gaia Cloning Groups.

set cloning-group-management *

Cloud Config

cloud-config

Control of Zero Touch.

show cloud-config *
set cloud-config *
delete cloud-config *

ClusterClosed Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing.

cluster

Control clustering.

add cluster *
set cluster *
delete cluster *
show cluster *

Core Dump

core-dump

Control core dumps.

set core-dump *
show core-dump *

DHCP Relay

bootp

Control Relay of IPv4 DHCP and IPv4 BOOTP messages between DHCP clients and DHCP servers on different IPv4 Network.

set bootp *
show bootp *

DHCP Server

dhcp

Control DHCP Server on Gaia.

set dhcp service *
delete dhcp service *
set dhcp client *
delete dhcp client *
add dhcp client *
set dhcp server *
delete dhcp server *
add dhcp server *
show dhcp service *
show dhcp client *
show dhcp server *

DHCPv6 Relay

dhcp6relay

Control Relay of DHCPv6 messages between DHCP clients and DHCP servers on different IPv6 Network.

set ipv6 dhcp6relay *
show ipv6 dhcp6relay *

Display Configuration

configuration

Save and show Gaia configuration.

save configuration *
show configuration *

Display Format

format

Control how the system displays time, date and netmask.

set format *
show format *

DNS

dns

Control DNS servers on Gaia.

set dns *
delete dns *
show dns *

Domain Name

domainname

Control the domain name on Gaia.

set domainname *
delete domainname
show domainname

Download SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on.

smart-console

Download SmartConsole from Gaia PortalClosed Web interface for the Check Point Gaia operating system..

N / A

Expert ModeClosed The name of the elevated command line shell that gives full system root permissions in the Check Point Gaia operating system.

expert

Access to the Expert mode shell.

expert

Expert Password

expert-password

Change the Expert mode password (interactive).

set expert-password

Expert Password Hash

expert-password-hash

Change the Expert mode password using password hash.

set expert-password-hash *

Extended Commands

command

Control the ability to define additional Extended Commands for the Gaia ClishClosed The name of the default command line shell in Check Point Gaia operating system. This is a restricted shell (role-based administration controls the number of commands available in the shell)..

add command *
delete command *
show command *
show commands
show extended *

Factory Defaults

fcd

Restore Gaia OS to Factory Defaults.

set fcd *
show fcd *

Firewall Management

firewall_management

Control Login and Logout from Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server..

mgmt *

Front Panel

lcd

Control the front panel LCD display available on some Check Point appliances.

set lcd *
show lcd *

Hardware Health

hw-monitor

Hardware sensor monitoring.

show sysenv all
cpstat -f sensors os

High Availability

high-avail-group

Overview page for High Availability.

 

Host Access

host-access

Control which hosts are allowed to connect to Gaia.

add allowed-client *
delete allowed-client *
show allowed-client *

Host Address

host

Control known hosts and their IP addresses on Gaia.

add host *
set host *
delete host *
show host *

Host Name

hostname

Control the Gaia hostname.

set hostname *
show hostname *

IGMP

igmp

Control multicast group memberships through the Internet Group Management Protocol (IGMP).

set igmp *
show igmp *

Inactivity timeout

inactto

Control inactivity timeout for Gaia Portal and Gaia Clish.

set inactivity-timeout *
show inactivity-timeout *

Inbound Route Filters

import

Configure IPv4 Inbound Route Filters for RIP, OSPFv2, and BGP IPv4.

set inbound-route-filter *

Inbound Route Filters

import6

Configure IPv6 Inbound Route Filters for RIPng, OSPFv3, and BGP IPv6.

set ipv6 inbound-route-filter *

Installation

ftw

Run the Gaia First Time Configuration Wizard.

 

Interface Naming

interface-name

Set a different name for an existing interface (requires a reboot and reconfiguration of the interface)

set interface-name *

IP Broadcast Helper

iphelper

Control forwarding of UDP broadcast traffic to other interfaces.

set iphelper *
show iphelper *

IP Reachability Detection

ipreachdetect

Control reachability of IP Addresses.

set ip-reachability-detection *
show ip-reachability-detection *

IPv4 Static Routes

static-route

Configure IPv4 static routes on Gaia.

set static-route *
show route static *

IPv6 Router Discovery

ipv6rdisc6

Control IPv6 router discovery.

set ipv6 rdisc6 *
show ipv6 rdisc6 *

IPv6 State

ipv6-state

Control IPv6 stack on Gaia.

set ipv6-state *
show ipv6-state

IPv6 Static Routes

static6

Control IPv6 static routes on Gaia.

set ipv6 static-route *
show ipv6 route static *

IPv6 VRRP

vrrp6

Control the IPv6 Virtual Router Redundancy Protocol (VRRPv3).

set ipv6 vrrp6 *
show ipv6 vrrp6 *

Job Scheduler

cron

Control scheduled automated tasks that perform actions at a specific time.

add cron *
set cron *
delete cron *
show cron *

License Activation

license_activation

Access to "Activate Licenses".

cplic

License Configuration

license

Access to "Manage License".

cplic

Lights Out Management (LOM) Configuration

lom

Show Lights Out Management (LOM) Configuration.

show lom *

Mail Notification

ssmtp

Control mail notifications sent by Gaia.

set mail-notification *
show mail-notification *

Maintenance

maintenance-group

Overview page for Maintenance.

N / A

Management InterfaceClosed (1) Interface on a Gaia Security Gateway or Cluster member, through which Management Server connects to the Security Gateway or Cluster member. (2) Interface on Gaia computer, through which users connect to Gaia Portal or CLI.

management_interface

Control which interface is used for management (main interface).

set management *
show management *

NDP

neighbor

Control IPv6 Neighbor Discovery Protocol.

add neighbor-entry *
set neighbor *
delete neighbor-entry *
show neighbor *

NetFlow Export

netflow

Control NetFlow Export on Gaia.

add netflow *
set netflow *
delete netflow *
show netflow *

Network Access

netaccess

Control TELNET access to Gaia.

set net-access *
show net-access *

Network Interfaces

interface

Control Physical interfaces, Aliases, Bridges, Bonds, VLANs, PPPoE.

set interface *
add interface *
delete interface *
add bonding *
set bonding *
delete bonding *
add bridging *
set bridging *
delete bridging *
add pppoe *
delete pppoe *
set pppoe *
add gre *
delete gre *
show interface *
show interfaces
show bonding *
show bridging *
show pppoe *
show gre *

Network Management

interface-group

Overview page for Network Management.

show interface *
show interfaces *
set interface *

NTP

ntp

Control Network Time Protocol for synchronizing the Gaia clock.

add ntp *
set ntp *
delete ntp *
show ntp *

OSPF

ospf

Control IPv4 dynamic routing through the Open Shortest-Path First protocol (OSPFv2).

set ospf *
show ospf *
show route ospf *

OSPF v3

ospf3

Control IPv6 dynamic routing through the Open Shortest-Path First protocol v3 (OSPFv3).

set ipv6 ospf3 *
set router-id *
show ipv6 ospf3 *
show ipv6 route ospf3 *
show router-id *

Password Policy

password-controls

Control password and account policies on Gaia.

set password-controls *
show password-controls *

Performance Optimization

perf

Control Multi-Queue on Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources..

set multi-queue *
show multi-queue *

PIM

pim

Control Protocol-Independent Multicast (PIM).

set pim *
show pim *
show mfc *

Policy Based Routing

pbr-combine-static

Control policy based routing rules and action tables.

set pbr *
set pbrroute *
show pbr *
show pbrroute *

Policy Routing

pbr-routing-group

Overview page for Policy Based Routing.

set pbr *
set pbrroute *
show pbr *
show pbrroute *

Prefix Lists and Prefix Trees

prefix

Control Prefix Lists and Prefix Trees used in routing policy.

set prefix-tree *
set prefix-list *

Proxy Settings

proxy

Control Proxy server on Gaia.

set proxy *
delete proxy *
show proxy *

RAID Monitoring

raid-monitor

Overview page for RAID volumes monitoring.

raidconfig
raid_diagnostic

RIP

rip

Control dynamic routing through the Routing Information Protocol for IPv4 (RIP).

set rip *
show rip *

RIPng

ripng

Control dynamic routing through the Routing Information Protocol for IPv6 (RIPng).

set ipv6 ripng *
show ipv6 ripng *

Roles

rba

Control user roles on Gaia.

add rba *
delete rba *
show rba *

Route

route

Show IPv4 and IPv6 routing table on Gaia.

show route *
show ipv6 route *

Route Aggregation

aggregate

Create a supernet network from the combination of networks with a common routing prefix.

set aggregate *
show route aggregate *

Route Injection Mechanism

route-injection

Control the Route Injection Mechanism (RIM) on Gaia.

set kernel-routes *
show route kernel *

Route Map

routemap

Configure route maps on Gaia.

set routemap *
show routemap *
show routemaps *

Route Redistribution

export

Control advertisement of IPv4 routing information from one protocol to another.

set route-redistribution *

Route Redistribution

export6

Control advertisement of IPv6 routing information from one protocol to another.

set ipv6 route-redistribution *

Routed ClusterXL

routed-cluster

Control how RouteD daemon interacts with ClusterXL on Gaia.

set routed-clusterxl *
show routed-clusterxl *

Router Discovery

rdisc

Control ICMP Router Discovery on Gaia.

set rdisc *
show rdisc *

Router Service

router-service-group

Overview page for Routing Services.

 

Routing Monitor

show-route-all

View summary information about routes on Gaia.

show route *

Routing Options

route-options

Configure protocol ranks and trace (debug) options on Gaia.

set routedsyslog *
set trace *
set tracefile *
set max-path-splits *
set nexthop-selection *
set protocol-rank *
set router-options *
show trace *
show routed *
show protocol-rank *
show router-options *

SAM (Accelerator Card)

sam

Deprecated - SAM card is not supported. Monitor Security Acceleration Module for information on usage and connections.

show sam *

Scheduled Backup

scheduled_backup

Create scheduled backups of the Gaia for events of data loss.

add backup-scheduled *
set backup-scheduled *
delete backup-scheduled *
show backup-scheduled

Scratchpad Configuration

scratchpad

Control Scratchpad in Gaia Portal.

N / A

Security Management GUI Clients

mgmt-gui-clients

Control allowed Security Management GUI Clients.

 

Shutdown

reboot_halt

Shut down and reboot the Gaia.

halt *
reboot *

Snapshot

snapshot

Create full backups (snapshots) of the Gaia.

add snapshot *
set snapshot *
delete snapshot *
show snapshots
show snapshot *

SNMP

snmp

Control Gaia monitoring through the Simple Network Management Protocol (SNMP).

add snmp *
set snmp *
delete snmp *
show snmp *

Software Updates Policy Management

installer_conf

CPUSEClosed Check Point Upgrade Service Engine for Gaia Operating System. With CPUSE, you can automatically update Check Point products for the Gaia OS, and the Gaia OS itself. - Manage deployment policy and mail notifications for software updates.

For more information, see sk92449.

installer restore_policy *
set installer *
set installer download_mode *
set installer install_mode *
set installer download_mode schedule *
set installer install_mode schedule *

Static Multicast Routes

static-mroute

Configure multicast static routes on Gaia.

set static-mroute *
show static-mroute *

System Asset

asset

Show hardware asset summary.

show asset *

System Backup

backup

Create backup of the Gaia system for events of data loss.

add backup *
set backup *
backup *
restore *
delete backup *
show backups
show backup *
show restore *

System Configuration

sysconfig

System Configuration.

show configuration *

System Groups

group

Control Gaia OS user groups, for advanced management of privileges.

add group *
set group *
delete group *
show groups
show group *

System Logging

syslog

Control system logging on Gaia.

add syslog *
set syslog *
delete syslog *
show syslog *

System Management

system-group

Overview page for System Management.

 

System Status

sysenv

Hardware sensor monitoring.

show sysenv *

TACACS_Enable

tacacs_enable

Control TACACS+ mechanism on Gaia.

tacacs_enable *
show tacacs_enable *

Time

clock-date

Configure the time and date of the Gaia system.

set clock *
set date *
set time *
set timezone *
show clock *
show date *
show time *
show timezone *

Upgrade

upgrade

Upgrade the Gaia. Deprecated - use the CPUSE instead.

upgrade *
add upgrade *
delete upgrade *
show upgrade *

Upgrades (CPUSE)

installer

CPUSE - Show the update packages status and manage package downloads and installations on Gaia.

For more information, see sk92449.

show installer *
add installer *
installer *
set installer *

Upgrades (CPUSE)

software-updates-group

Overview page for CPUSE.

For more information, see sk92449.

show installer *
set installer *
installer agent *

User Management

security-access-group

Overview page for User Management.

 

Users

user

Control user accounts on Gaia.

add user *
set user *
delete user *
show user *
show users *

Version

version

Shows the version of the installed Check Point product, and Gaia build and kernel.

show version *

Virtual-System

virtual-system

Control VSXClosed Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Security Gateways and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. Virtual Systems (CLI only). You must configure all Virtual Systems in SmartConsole only.

add virtual-system *
set virtual-system *
delete virtual-system *
show virtual-system *

VPNT

vpnt

Control VPN Tunneling on Gaia.

add vpn *
set vpn *
delete vpn *

VRRP

vrrp

Control the IPv4 Virtual Router Redundancy Protocol (VRRPv2) - Monitored Circuit/Simplified VRRP.

set vrrp *
add mcvr *
set mcvr *
delete mcvr *
show vrrp *
show mcvr *

VSX

vsx

Enable or Disable the VSX mode (to be used only by Check Point Support only).

set vsx *
show vsx *

Web configuration

web

Control Gaia Portal.

set web *
generate web *
show web *