Kamis, 19 Desember 2013

Install check point R76

Pasang cable console...
setelah connect lakukan perintah dibawah dengan menyesuaikan IP yang ingin diconfigure sesuai topology.

ISOLINUX 3.83 3.83  Copyright (C) 1994-2009 H. Peter Anvin et al
DMI 0.0 present.Tcorp CDDVDW *HiSpeed*                                     0078
45 structures occupying 1803 bytes.nd configured.
DMI table at 0x000FB590.                                                   0085
Welcome to Check Point Gaia
Press any key to start installation

 Automatic boot in 59 seconds...    Loading kernel.....................................
Loading ramdisk......................................................................................ready.
Linux version 2.6.18-92cp (builder@bulleit) (gcc version 4.1.1 20061011 (Red Hat 4.1.1-30)) #1 SMP Sun Feb 10 22:58:17 IST 2013
BIOS-provided physical RAM map:
 BIOS-e820: 0000000000000000 - 000000000009dc00 (usable)
 BIOS-e820: 000000000009dc00 - 00000000000a0000 (reserved)
 BIOS-e820: 00000000000e0000 - 0000000000100000 (reserved)
 BIOS-e820: 0000000000100000 - 00000000bdda0000 (usable)
 BIOS-e820: 00000000bdda0000 - 00000000bddae000 (ACPI data)
 BIOS-e820: 00000000bddae000 - 00000000bddf0000 (ACPI NVS)
 BIOS-e820: 00000000bddf0000 - 00000000c0000000 (reserved)
 BIOS-e820: 00000000e0000000 - 00000000f0000000 (reserved)
 BIOS-e820: 00000000fee00000 - 00000000fee01000 (reserved)
 BIOS-e820: 00000000fff00000 - 0000000100000000 (reserved)
 BIOS-e820: 0000000100000000 - 0000000140000000 (usable)
Warning only 4GB will be used.
Use a PAE enabled kernel.
2176MB HIGHMEM available.
1920MB LOWMEM available.
found SMP MP-table at 000ff780
Memory for crash kernel (0x0 to 0x0) notwithin permissible range
disabling kdump
Using x86 segment limits to approximate NX protection
DMI present.
Using APIC driver default
ACPI: PM-Timer IO Port: 0x808
ACPI: LAPIC (acpi_id[0x01] lapic_id[0x00] enabled)
Processor #0 7:7 APIC version 20
ACPI: LAPIC (acpi_id[0x02] lapic_id[0x01] enabled)
Processor #1 7:7 APIC version 20
ACPI: LAPIC (acpi_id[0x03] lapic_id[0x82] disabled)
ACPI: LAPIC (acpi_id[0x04] lapic_id[0x83] disabled)
Using ACPI for processor (LAPIC) configuration information
Intel MultiProcessor Specification v1.4
    Virtual Wire compatibility mode.
OEM ID: Intel    Product ID: Eaglelake    APIC at: 0xFEE00000
I/O APIC #2 Version 32 at 0xFEC00000.
Enabling APIC mode:  Flat.  Using 1 I/O APICs
Processors: 2
Allocating PCI resources starting at c2000000 (gap: c0000000:20000000)
Detected 2593.581 MHz processor.
Built 1 zonelists.  Total pages: 1048576
Kernel command line: initrd=ramdisk lang= devfs=nomount ramdisk_size=24336 pci=noacpi console=ttyS0 BOOT_IMAGE=kernel
Enabling fast FPU save and restore... done.
Enabling unmasked SIMD FPU exception support... done.
Initializing CPU#0
PID hash table entries: 4096 (order: 12, 16384 bytes)
Console: colour VGA+ 80x25
Dentry cache hash table entries: 262144 (order: 8, 1048576 bytes)
Inode-cache hash table entries: 131072 (order: 7, 524288 bytes)
Memory: 3062100k/4194304k available (2710k kernel code, 47224k reserved, 1403k data, 284k init, 1144448k highmem)
Checking if this processor honours the WP bit even in supervisor mode... Ok.
Calibrating delay using timer specific routine.. 5189.08 BogoMIPS (lpj=2594540)
kdb version 4.4 by Keith Owens, Scott Lurndal. Copyright SGI, All Rights Reserved
Security Framework v1.0.0 initialized
SELinux:  Initializing.
selinux_register_security:  Registering secondary module capability
Capability LSM initialized as secondary
Mount-cache hash table entries: 512
monitor/mwait feature present.
using mwait in idle threads.
CPU: L1 I cache: 32K, L1 D cache: 32K
CPU: L2 cache: 1024K
CPU: Physical Processor ID: 0
CPU: Processor Core ID: 0
Intel machine check architecture supported.
Intel machine check reporting enabled on CPU#0.
Checking 'hlt' instruction... OK.
SMP alternatives: switching to UP code
ACPI: Core revision 20060707
ACPI: setting ELCR to 0ee0 (from 0ce0)
CPU0: Intel(R) Celeron(R) CPU        E3400  @ 2.60GHz stepping 0a
SMP alternatives: switching to SMP code
Booting processor 1/1 eip 3000
Initializing CPU#1
Calibrating delay using timer specific routine.. 7157.00 BogoMIPS (lpj=3578500)
monitor/mwait feature present.
CPU: L1 I cache: 32K, L1 D cache: 32K
CPU: L2 cache: 1024K
CPU: Physical Processor ID: 0
CPU: Processor Core ID: 1
Intel machine check architecture supported.
Intel machine check reporting enabled on CPU#1.
CPU1: Intel(R) Celeron(R) CPU        E3400  @ 2.60GHz stepping 0a
Total of 2 processors activated (12346.08 BogoMIPS).
ExtINT not setup in hardware but reported by MP table
ENABLING IO-APIC IRQs
..TIMER: vector=0x31 apic1=0 pin1=2 apic2=0 pin2=0
checking TSC synchronization across 2 CPUs: passed.
Brought up 2 CPUs
migration_cost=47
checking if image is initramfs... it is
Freeing initrd memory: 5372k freed
NET: Registered protocol family 16
No dock devices found.
ACPI: bus type pci registered
PCI: Using MMCONFIG
PCI: Buses that can't use MMCONFIG will use type 1 PCI conf access.
Setting up standard PCI resources
ACPI: Interpreter enabled
ACPI: Using PIC for interrupt routing
Linux Plug and Play Support v0.97 (c) Adam Belay
pnp: PnP ACPI init
pnp: PnP ACPI: found 15 devices
usbcore: registered new driver usbfs
usbcore: registered new driver hub
PCI: Probing PCI hardware
PCI quirk: region 0800-087f claimed by ICH6 ACPI/GPIO/TCO
PCI quirk: region 0480-04bf claimed by ICH6 GPIO
PCI: Ignoring BAR0-3 of IDE controller 0000:00:1f.1
PCI: Transparent bridge - 0000:00:1e.0
PCI: Using IRQ router PIIX/ICH [8086/27b8] at 0000:00:1f.0
PCI->APIC IRQ transform: 0000:00:02.0[A] -> IRQ 137
PCI->APIC IRQ transform: 0000:00:1c.0[A] -> IRQ 137
PCI->APIC IRQ transform: 0000:00:1c.1[B] -> IRQ 145
PCI->APIC IRQ transform: 0000:00:1c.2[C] -> IRQ 153
PCI->APIC IRQ transform: 0000:00:1c.3[D] -> IRQ 161
PCI->APIC IRQ transform: 0000:00:1c.4[A] -> IRQ 137
PCI->APIC IRQ transform: 0000:00:1c.5[B] -> IRQ 145
PCI->APIC IRQ transform: 0000:00:1d.0[A] -> IRQ 169
PCI->APIC IRQ transform: 0000:00:1d.1[B] -> IRQ 161
PCI->APIC IRQ transform: 0000:00:1d.7[A] -> IRQ 169
PCI->APIC IRQ transform: 0000:00:1f.1[A] -> IRQ 153
PCI->APIC IRQ transform: 0000:00:1f.2[B] -> IRQ 161
PCI->APIC IRQ transform: 0000:00:1f.3[B] -> IRQ 161
PCI->APIC IRQ transform: 0000:01:00.0[A] -> IRQ 137
PCI->APIC IRQ transform: 0000:02:00.0[A] -> IRQ 145
PCI->APIC IRQ transform: 0000:03:00.0[A] -> IRQ 153
PCI->APIC IRQ transform: 0000:04:00.0[A] -> IRQ 161
PCI->APIC IRQ transform: 0000:05:00.0[A] -> IRQ 137
PCI->APIC IRQ transform: 0000:06:00.0[A] -> IRQ 145
PCI->APIC IRQ transform: 0000:07:01.0[A] -> IRQ 153
PCI->APIC IRQ transform: 0000:07:04.0[A] -> IRQ 145
PCI->APIC IRQ transform: 0000:07:05.0[A] -> IRQ 153
PCI->APIC IRQ transform: 0000:07:06.0[A] -> IRQ 161
PCI->APIC IRQ transform: 0000:07:07.0[A] -> IRQ 137
PCI->APIC IRQ transform: 0000:07:08.0[A] -> IRQ 145
PCI->APIC IRQ transform: 0000:07:09.0[A] -> IRQ 153
PCI->APIC IRQ transform: 0000:09:00.0[A] -> IRQ 145
PCI->APIC IRQ transform: 0000:0b:00.0[A] -> IRQ 161
PCI->APIC IRQ transform: 0000:0d:00.0[A] -> IRQ 145
NetLabel: Initializing
NetLabel:  domain hash size = 128
NetLabel:  protocols = UNLABELED CIPSOv4
NetLabel:  unlabeled traffic allowed by default
pnp: 00:08: ioport range 0xa00-0xa0f has been reserved
pnp: 00:08: ioport range 0xa00-0xa0f has been reserved
PCI: Ignore bogus resource 6 [0:0] of 0000:00:02.0
PCI: Bridge: 0000:00:1c.0
  IO window: 7000-7fff
  MEM window: fe300000-fe3fffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:00:1c.1
  IO window: 8000-8fff
  MEM window: fe400000-fe4fffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:00:1c.2
  IO window: 9000-9fff
  MEM window: fe500000-fe5fffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:00:1c.3
  IO window: a000-afff
  MEM window: fe600000-fe6fffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:00:1c.4
  IO window: b000-bfff
  MEM window: fe700000-fe7fffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:07:01.0
  IO window: disabled.
  MEM window: disabled.
  PREFETCH window: disabled.
PCI: Bridge: 0000:07:04.0
  IO window: c000-cfff
  MEM window: fe900000-fe9fffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:07:05.0
  IO window: disabled.
  MEM window: disabled.
  PREFETCH window: disabled.
PCI: Bridge: 0000:07:06.0
  IO window: d000-dfff
  MEM window: fea00000-feafffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:07:07.0
  IO window: disabled.
  MEM window: disabled.
  PREFETCH window: disabled.
PCI: Bridge: 0000:07:08.0
  IO window: e000-efff
  MEM window: feb00000-febfffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:07:09.0
  IO window: disabled.
  MEM window: disabled.
  PREFETCH window: disabled.
PCI: Bridge: 0000:06:00.0
  IO window: c000-efff
  MEM window: fe900000-febfffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:00:1c.5
  IO window: c000-efff
  MEM window: fe800000-febfffff
  PREFETCH window: disabled.
PCI: Bridge: 0000:00:1e.0
  IO window: disabled.
  MEM window: disabled.
  PREFETCH window: disabled.
NET: Registered protocol family 2
IP route cache hash table entries: 65536 (order: 6, 262144 bytes)
TCP established hash table entries: 262144 (order: 9, 2097152 bytes)
TCP bind hash table entries: 65536 (order: 7, 524288 bytes)
TCP: Hash tables configured (established 262144 bind 65536)
TCP reno registered
apm: BIOS not found.
audit: initializing netlink socket (disabled)
audit(1387450549.523:1): initialized
highmem bounce pool size: 64 pages
Total HugeTLB memory allocated, 0
VFS: Disk quotas dquot_6.5.1
Dquot-cache hash table entries: 1024 (order 0, 4096 bytes)
Initializing Cryptographic API
ksign: Installing public key data
Loading keyring
io scheduler noop registered
io scheduler anticipatory registered
io scheduler deadline registered
io scheduler cfq registered (default)

bypass version 3.0.0
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
assign_interrupt_mode Found MSI capability
pci_hotplug: PCI Hot Plug PCI Core version: 0.5
ACPI: Getting cpuindex for acpiid 0x3
ACPI: Getting cpuindex for acpiid 0x4
Real Time Clock Driver v1.12ac
Non-volatile memory driver v1.2
Linux agpgart interface v0.101 (c) Dave Jones
Serial: 8250/16550 driver $Revision: 1.90 $ 4 ports, IRQ sharing enabled
▒serial8250: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
serial8250: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
00:06: ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
00:07: ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
RAMDISK driver initialized: 16 RAM disks of 24336K size 4096 blocksize
Uniform Multi-Platform E-IDE driver Revision: 7.00alpha2
ide: Assuming 33MHz system bus speed for PIO modes; override with idebus=xx
ICH7: IDE controller at PCI slot 0000:00:1f.1
ICH7: chipset revision 1
ICH7: not 100% native mode: will probe irqs later
    ide0: BM-DMA at 0xffa0-0xffa7, BIOS settings: hda:pio, hdb:pio
    ide1: BM-DMA at 0xffa8-0xffaf, BIOS settings: hdc:pio, hdd:pio
ide-floppy driver 0.99.newide
usbcore: registered new driver hiddev
usbcore: registered new driver usbhid
drivers/usb/input/hid-core.c: v2.6:USB HID core driver
PNP: No PS/2 controller found. Probing ports directly.
serio: i8042 KBD port at 0x60,0x64 irq 1
serio: i8042 AUX port at 0x60,0x64 irq 12
mice: PS/2 mouse device common for all mice
md: md driver 0.90.3 MAX_MD_DEVS=256, MD_SB_DISKS=27
md: bitmap version 4.39
TCP bic registered
Initializing IPsec netlink socket
NET: Registered protocol family 1
NET: Registered protocol family 17
Using IPI No-Shortcut mode
ACPI: (supports<6>Time: tsc clocksource has been installed.
 S0 S1 S3 S4 S5)
Freeing unused kernel memory: 284k freed
Write protecting the kernel read-only data: 473k
Starting installation process


                +----------+ Starting Installation +----------+
                |                                             |
                | Please wait while installation starts...    |
                |                                             |
                +---------------------------------------------+



                              Check Point Gaia R76
sending termination signals...done
sending kill signals...done
ACPI: Getting cpuindex for acpiid 0x3
ACPI: Getting cpuindex for acpiid 0x4
▒  Reading all physical volumes.  This may take a while...
  Found volume group "vg_splat" using metadata type lvm2
  3 logical volume(s) in volume group "vg_splat" now active
Setting clock  (utc): Thu Dec 19 11:10:20 UTC 2013 [  OK  ]
Starting udev: [  OK  ]
Setting hostname cpmodule:  [  OK  ]
Setting up Logical Volume Management:   3 logical volume(s) in volume group "vg_splat" now active
[  OK  ]
Checking filesystems
Checking all file systems.
[/sbin/fsck.ext3 (1) -- /] fsck.ext3 -a /dev/mapper/vg_splat-lv_current
/dev/mapper/vg_splat-lv_current: clean, 27039/8388608 files, 1066633/8388608 blockso-detecting USB Mass Storage Devices ..
[/sbin/fsck.ext3 (1) -- /boot] fsck.ext3 -a /dev/sda1                      0078
/boot: clean, 87/38152 files, 37571/152584 blocks                          0085
[/sbin/fsck.ext3 (1) -- /var/log] fsck.ext3 -a /dev/mapper/vg_splat-lv_log
/dev/mapper/vg_splat-lv_log: clean, 92/15728640 files, 539321/15728640 blocks
[  OK  ]
INIT: Entering runlevel: 3
Applying Intel CPU microcode update: [  OK  ]
Starting sysstat:  Calling the system activity data collector (sadc):
[  OK  ]
Running UP accel driver check.
IP series driver not present
Starting background readahead: [  OK  ]
Checking for hardware changes [  OK  ]
Configuring ipv6 kernel support:  [  OK  ]
Starting kdump:[  OK  ]
Inserting ipsctlmod.2.6.18.cp.i686: [  OK  ]
Starting wrp:
[  OK  ]
Starting auditd: [  OK  ]
Starting system logger: [  OK  ]
Starting kernel logger: [  OK  ]
Fulcrum switch not installed
Creating initial configuration database...
Generating a 2048 bit RSA private key
.....................................+++
..............................................+++
writing new private key to '/web/conf/server.key'
-----
992 bindings were imported
Generating vrfs:  [  OK  ]
Configuring NetAccess:  [  OK  ]
Generating NTP configuration:  [  OK  ]
Generating Time Zone configuration:  [  OK  ]
Generating domain name configuration:  [  OK  ]
Generating keyboard mapping configuration:  [  OK  ]
Generating hostname configuration:  [  OK  ]
Update Interfaces in Database:  0 bindings were imported
[  OK  ]
Configuring Interfaces:  [  OK  ]
Generating /etc/monitor_mode:  [  OK  ]
Generating /etc/fonic_pairs:  [  OK  ]
Configuring NDP:  [  OK  ]
Generating hosts.conf:  [  OK  ]
Generating resolv.conf:  [  OK  ]
Generating dhclient.conf:  [  OK  ]
Generating pwcontrol.conf [  OK  ]
Generating passwd + shadow [  OK  ]
Generating group + gshadow [  OK  ]
Generating routed.conf [  OK  ]
Generating routed0.conf [  OK  ]
Generating extended commands:  [  OK  ]
Generating MOTD:  [  OK  ]
Generating banner message:  [  OK  ]
Generating /etc/raddb/server:  [  OK  ]
Generating TACACS+ configuration:  [  OK  ]
Generating /etc/msmtp.conf:  [  OK  ]
Generating /etc/pam.d/system-auth:  [  OK  ]
Generating /etc/sysconfig/external.if:  [  OK  ]
Generating /etc/lldpd.conf:  [  OK  ]
Generating DHCP server configuration:  Write DSTATE called
ServerConfigured = 1
DdnsConfigured = 0
[  OK  ]
Generating /etc/adjust_radius:  [  OK  ]
Running /bin/arp_xlate:  [  OK  ]
Generating SNMP configuration:  [  OK  ]
Generating Job Scheduler configuration:  [  OK  ]
Updating general configuraion file:  [  OK  ]
Updating syslogd configuration:  Reloading syslogd...[  OK  ]
Reloading klogd...[  OK  ]
[  OK  ]
Updating httpd2 configuration:  [  OK  ]
 Updating httpd-ssl configuration:  [  OK  ]
Applying NetFlow configuration [  OK  ]
Configuring PPPoE:  [  OK  ]
CPshell initialization:  [  OK  ]
Initializing CP Process Manager..
Starting cp_pm_rl2:  [  OK  ]
Starting cp_pm_rl3:  [  OK  ]
Starting cp_pm_rl4:  [  OK  ]
Starting acpi daemon: [  OK  ]
Generating SSH1 RSA host key: [  OK  ]
Generating SSH2 RSA host key: [  OK  ]
Generating SSH2 DSA host key: [  OK  ]
Starting sshd: [  OK  ]
Starting arp:
Starting xinetd: [  OK  ]
Starting bp_init:  [  OK  ]
Starting bypass_off:  [  OK  ]
Starting crond: [  OK  ]
Starting cpri_d:  cpridstart: Starting cprid
[1] 7327
[  OK  ]
Starting cpboot:  cpstart: Power-Up self tests passed successfully
cpstart: Product VPN-1 not configured , please use 'cpconfig' to configure it.

cpstart: Product FloodGate-1 not configured , please use 'cpconfig' to configure it.


cpstart: Starting product - SVN Foundation

SVN Foundation: Starting cpWatchDog
SVN Foundation: Starting cpd
SVN Foundation started

cpstart: Starting product - SmartView Monitor

SmartView Monitor: Not active

cpstart: Starting product - Deployment Agent

cpwd_admin:
Process DASERVICE started successfully (pid=7502)


*****************************************************************************************************
Warning: You are required to deploy a Software Blade license instead of your NGX license.
For more details go to http://www.checkpoint.com/software-blades
or contact Account Services.
*****************************************************************************************************
[  OK  ]
Starting cpboot_refetch:  [  OK  ]
Inserting vrrp_lkm.2.6.18.cp.i686: [  OK  ]
This system is for authorized use only.
login: admin
Password:
In order to configure your system, please access the Web UI and finish the First Time Wizard.
gw-3868b6> set ex
expert-password      - Set expert password
expert-password-hash - Set expert password md5 salted hash
gw-3868b6> set expert-password
Enter new expert password:
Enter new expert password (again):
gw-3868b6> expert
Enter expert password:

Warning! All configuration should be done through clish
You are in expert mode now.

[Expert@gw-3868b6:0]# fw ver
This is Check Point VPN-1(TM) & FireWall-1(R) R76 - Build 380
[Expert@gw-3868b6:0]# halt

INIT: Sending processes the TERM signal
[Expert@gw-3868b6:0]# Stopping sshd: [  OK  ]
Stopping arp:
Stopping xinetd: [  OK  ]
Stopping acpi daemon: [  OK  ]
Stopping crond: [  OK  ]
CPshell shutdown:  [  OK  ]
Stopping auditd: [  OK  ]
Shutting down kernel logger: [  OK  ]
Shutting down system logger: [  OK  ]
Starting killall:  [  OK  ]
Sending all processes the TERM s
Sending all processes the KILL signal...
Saving random seed:
Syncing hardware clock to system time
Turning off swap:
Unmounting file systems:
mount: /proc is busy
Halting system...
System halted.

0 komentar:

Posting Komentar