sk180183 - Moving to the context of a Security Group Member or adding a new Security Group Member fails
Moving to the context of a Security Group Member or adding a new Security Group Member fails
Product: Maestro HyperScale Firewall, Scalable Chassis
Version: R80.20SP (EOS), R80.30SP (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2025-08-12
Symptoms
- When you add a new Security Group Member (SGM) to a Security Group, the procedure takes a long time or is stuck.
- When you move between the Security Group Members with the
member(orm) command, the system uses the "root" user, not the "admin user" for this internal SSH connection.
Cause
The entry order in the /etc/passwd file is wrong - the "root" user entry appears above the "admin" user entry.
The "admin" user entry must always appear above the "root" user entry.
Solution
This problem was fixed. The fix is included from:
- Check Point R82
- Jumbo Hotfix Accumulator for R81.20 - from Take 111
- Jumbo Hotfix Accumulator for R81.10 - from Take 177
If you choose not to upgrade, change the order of entries in the /etc/passwd file. Do this for all SGMs.
Connect to the command line on the Security Group.
Log in.
If the default shell is Gaia gClish, then go to the Expert mode:
expertBack up the current
/etc/passwdfile:g_all cp -v /etc/passwd{,_BKP}Edit the current
/etc/passwdfile:vi /etc/passwdMake sure the "admin" user entry appears above the "root" user entry.
Example:
admin:x:0:0::/home/admin:/bin/bash monitor:x:102:100:Monitor:/home/monitor:/etc/cli.sh root:x:0:0:root:/root:/sbin/nologin test:x:0:0:Test:/home/test/:/bin/gclish _lldpd:x:103:101:LLDP daemon:/home/_lldpd:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin postfix:x:1001:1001:Postfix:/home/postfix:/sbin/nologin rpm:x:37:37::/var/lib/rpm:/sbin/nologin shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown pcap:x:77:77::/var/arpwatch:/sbin/nologin halt:x:7:0:halt:/sbin:/sbin/halt cp_postgres:x:1008:0:Postgres:/home/cp_postgres:/bin/sh cp_extensions:x:8086:1:CP Extensions:/home/cp_extensions:/bin/sh _nonlocl:x:96:100:Non-local user:/home/_nonlocl:/etc/cli.sh vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin cpep_user:x:1500:1500::/home/cpep_user:/sbin/nologin sshd:x:74:74:Privilege-separated:/var/empty/sshd:/sbin/nologinSave the changes in the file and exit Vi editor.
Copy the modified file to all Security Group Members:
asg_cp2blades /etc/passwdClose all SSH sessions to the Security Group and all Security Group Members.
Connect to the command line on the Security Group.
Log in.
If the default shell is Gaia gClish, then go to the Expert mode:
expert
- Get the current user:
whoami
The output must show the username with which you logged in to the command line on the Security Group.
14. Use the member command to move to the context of a different Security Group Member:
member <ID of Security Group Member>
- Get the current user:
whoami
The output must show the username with which you logged in to the command line on the Security Group and not the "root" user.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
- Access Level: General
- Status: Approved by TAC
- Date Created: 2022-10-27
- Last Modified: 2025-08-12