sk120193 - Gaia Fast Deployment (Blink)

Gaia Fast Deployment (Blink)

Solution

Table of Contents:

Introduction

Fast Deployment (Blink) deployment flow and images let customers do a multi-step upgrade or clean install with one image.

Blink images already contain a specific base version (for example, R81.10), a designated role (for example, Security Gateway), and more hotfixes / Jumbo Hotfix Accumulators.

With this image, you can onboard new appliances/upgrade existing appliances with one package.

You can see and install Blink images in Gaia Portal or with Gaia Clish commands.

Basic Usage

Important Note: Fast Deployment (Blink) mechanism is intended only for Check Point appliances and Open Servers on which Check Point software has been installed.

  1. Connect to the appliance with a web browser and log in.

The First Time Configuration Wizard opens:

  1. Select the option Install from Check Point cloud:

  2. After configuring the external interface, the installation table shows a list of supported images.

The latest images use Blink mechanism to install the version.

The selected Blink image is downloaded and deployed on the appliance:

Blink packages installation is equivalent to the Major version installation:

  1. You see all the packages by categories and, by default, it shows the recommended packages only.

Note: Use the filter button near the help icon and select the packages you wish to see:

  1. Find the related package in the Blink section in CPUSE packages list:

  2. For offline packages, manually import the package to CPUSE by clicking on Import Package on the top-right corner of the page:

  3. To download a package from the list, right-click on the related package that is Available for Download and click on Download.

  4. After the download completes, right-click on the package and click on Clean Install or Upgrade(if available):

  5. Installation/Upgrade starts, and you can follow the installation from CPUSE WebUI or CLI.

Advanced Usage (command line)

Installation Instructions

Important Note: If the appliance is not after a clean install (the First Time Configuration Wizard has been run already), the "--reimage" flag needs to be used (see the "answers.xml" section).

Fast Deployment (Blink) image contains:

  1. The root partition of a pre-installed Check Point appliance
  2. Simplified First Time Configuration Wizard (will be used in case of attended installation)
  3. Installation logic

The main files in the Fast Deployment (Blink) image are:

Directory / File Description
BlinkInstaller Main executable file that extracts and installs all the packages.
CheckPoint_Gaia_fd.tgz This is the actual installation image.
installation_logic Directory that contains internal installation logic:
- answers.xml - User's configuration file for unattended installation.

- fd_wizard_gateway.sh - ( Internal) Shell script for unattended First Time Configuration Wizard.

- fd_wizard_gateway.sh.sha256 - ( Internal) Check Point Signature file for the fd_wizard_gateway.sh script.

Note: The "answers.xml" file is the only file that a user is allowed to modify - refer to the section "answers.xml".
manifest.xml XML-based file that represents the structure of the Blink package ( internal).
user_updates Directory that may contain user shell scripts and binary files that should be executed and installed during the main installation process (after the reboot).
The "answers.xml" file has to be edited to contain the name of the main shell script that will be executed (refer to the section "answers.xml").

answers.xml

This is an XML-based file (located in the "installation_logic" directory) that contains user's configuration for unattended installation.

<properties xmlVersion="1.1">
    <installation>
        <reboot_delay>10</reboot_delay>
    </installation>
    <machine_configuration>
        <perform>false</perform>
        <hostname>GWOBJECT_NAME_FIELD</hostname>
        <password_hash>PASSWORD_HASH_FIELD</password_hash>
        <maintenance_hash>Maintenance_HASH_FIELD</maintenance_hash>
        <network>
            <ipv4addr>IPV4_FIELD</ipv4addr>
            <masklength>IPV4_MASKLENGTH_FIELD</masklength>
            <interface>IPV4_INTERFACE_FIELD</interface>
            <default_gw>DEFAULTGW_FIELD</default_gw>
            <ipv6addr>IPV6_FIELD</ipv6addr>
            <ipv6mask>IPV6_MASKLENGTH_FIELD</ipv6mask>
            <ipv6default_gw>IPV6_DEFAULTGW_FIELD</ipv6default_gw>
        </network>
        <role_configuration>
            <gateway>
                <!--  activation_key must be in base64 encoding -->
                <activation_key>SIC_BASED64_FIELD</activation_key>
                <cluster>false</cluster>
            </gateway>
            <management>
                <credentials>
                    <use_gaia_admin>true</use_gaia_admin>
                    <!--  Relevant only if use_gaia_admin is false -->
                    <admin_name>MGMT_ADMIN_FIELD</admin_name>
                    <!--  admin_password must be in base64 encoding -->
                    <admin_password>MGMT_PASS_BASED64_FIELD</admin_password>
                </credentials>
            </management>
        </role_configuration>
        <send_data_to_usercenter>true</send_data_to_usercenter>
        <enable_download_from_checkpoint>true</enable_download_from_checkpoint>
    </machine_configuration>
    <user_updates>
        <entry_point>install_content.sh</entry_point>
    </user_updates>
    <logging>
        <file_level>DEBUG</file_level>
        <screen_level>NORMAL</screen_level>
        <sys_log_level>NEVER</sys_log_level>
        <colors>true</colors>
    </logging>
</properties>

Downloads

Fast Deployment Image (Blink) Utility

Blink Utility - the main utility that extracts the Blink Image and other packages, and installs them. Starting from R80.20, Blink Utility is a part of release.

Description Link to download
Blink Utility version 1.1 (TGZ)

Fast Deployment Image (Blink) Images - the Gaia OS images

Security Management Fast Deployment Image GA Images

Version Date Download Link
R82 (GA Take 777) 21 Oct 2024 (TGZ)
R81.20 (GA Take 631) 21 Nov 2022 (TGZ)
R81.10 (GA Take 335) 06 Jul 2021 (TGZ)
R81 (GA Take 392) 22 Oct 2020 (TGZ)
R80.40 (GA Take 294) 28 Jan 2020 (TGZ)
R80.30 (GA Take 200) 06 Jun 2019 (TGZ)
R80.20 (GA Take 117) 15 Oct 2019 (TGZ)
R80.10 (GA Take 479) (except Smart-1 525/5150) 05 Apr 2020 (TGZ)
R80.10 for Smart-1 525/5150 appliance 17 Sep 2018 (TGZ)

Limitations

ID Symptoms
- Standalone installations are not supported.
- Default value for "Management GUI Clients" property is set to " Any".
DP-2884 Using Blink images to downgrade the Gaia OS from kernel 3.10 to 2.6.18 is prohibited.
- Use the " revert to snapshot" option to return to the previous version.
DP-1644 Reimage: Blink reimage is blocked from running on VSX Gateways.
PMTR-41564 You can install Blink images on VSX Gateways only if Blink images are R80.40 and higher.
- No automatic Cleanup in case of un-normal progress interruption (power problem, early reboot, etc...).
In case interruption, perform the following (in the Expert mode):
1. Unmount the blink new partitions with this command:

umount /mnt/fcd/proc /mnt/fcd/sys /mnt/fcd/dev /mnt/fcd/var/log /mnt/fcd/tmp /mnt/fcd /mnt/BlinkPlugAndPlay_usb

2. Remove the blink new partition with this command:

lvremove /dev/vg_splat/lv_fcd_new

3. Run the process again.
- Blink does not support Secondary Security Management Servers in the Management High Availability configuration.
Note: This limitation does not apply to Multi-Domain Security Management Servers.

Revision History

Date Description
07 Sep 2025 Improved formatting
01 Jul 2025 Resolved limitation "Bond Configuration is not preserved during Blink installation"
21 Oct 2024 Added support for R82
31 Oct 2023 Updated the answers.xml version 1.1 default file
14 Aug 2023 Updated Limitation section
17 Jan 2023 Updated Limitation section
15 Jan 2023 Revised article. Added Basic Usage and Advanced Usage sections
05 Nov 2020 Updated the Supported deployments section
22 Oct 2020 Added support for R81
05 Apr 2020 Added Security Gateway and Management images for R80.10 (GA Take 479)
28 Jan 2020 Added support for R80.40
19 Dec 2019 Added PMTR-47403 to the list of Limitations
11 Dec 2019 Added support for Upgrade of R80.30 Security Gateways
13 Nov 2019 Added Security Gateway and Management images for R80.20 with R80.20 Jumbo Hotfix Take 118
02 Oct 2019 Added Security Gateway and Management images for R80.20 with R80.20 Jumbo Hotfix Take 103
23 Sep 2010 R80.20 Security Gateway image was updated to Take 117
06 June 2019 Added support for R80.30
26 May 2019 Added "Blink image installation" section
27 Mar 2019 List of Known Limitations was updated
18 Dec 2018 Added R80.20 Security Gateway and Security Management images
14 Oct 2018 Security Gateway Images have been replaced
17 Sep 2018 Added Blink Security Management Images and new answers.xml file instructions
18 Jul 2018 Added the "Deploying Check Point NG Firewalls just got easier with the Blink utility" video
14 May 2018 Added Blink Image for R80.10 Jumbo Hotfix Take 103 and R77.30 Jumbo Hotfix Take 302
07 May 2018 Updated the " How to use the Blink mechanism" section
19 Mar 2018 Added Blink Image for R80.10 Jumbo Hotfix Take 70
24 Jan 2018 All images were updated to support appliances with a software RAID
21 Jan 2018 Added Blink Image for R80.10 (GA Take 462)
31 Dec 2017 First release of this article