Never hear of this one before…. Thought I knew where all the logs were kept.
# cd $MDS_TEMPLATE/log
# pwd
/opt/CPsuite-R75.40VS/fw1/log
Never hear of this one before…. Thought I knew where all the logs were kept.
# cd $MDS_TEMPLATE/log
# pwd
/opt/CPsuite-R75.40VS/fw1/log
[ FYI, this is work in progress I haven’t found the answer yet. Just sharing info]
So we got Smart-1 appliances with 12 TB on them and I noticed GAIA only can see 2TB. Hmmmmmm I says to myself. Called a friend and they are having same problem. Hmmmm.
Well our lab is limited and I lost our Smart-1 to production so I can’t run tests as I would like, but here is the information I have.
The problem is that GAIA can only recognize 1K block sizes:
[Expert@smartlog]# fdisk -l
Disk /dev/cciss/c0d0: 513.6 GB, 513618945024 bytes 255 heads, 63 sectors/track, 62443 cylinders Units = cylinders of 16065 * 512 = 8225280 bytes
Device Boot Start End Blocks Id System
/dev/cciss/c0d0p1 * 1 19 152586 83 Linux
/dev/cciss/c0d0p2 20 2303 18346230 82 Linux swap /Solaris
/dev/cciss/c0d0p3 2304 62443 483074550 8e Linux LVM
[Expert@smartlog]# dumpe2fs /dev/cciss/c0d0p1
dumpe2fs 1.39 (29-May-2006)
Filesystem volume name: /boot
Last mounted on: <not available>
Filesystem UUID: 25910e70-451a-4d36-bf0f-0914c002b582
Filesystem magic number: 0xEF53
Filesystem revision #: 1 (dynamic)
Filesystem features: has_journal resize_inode dir_index filetype needs_recovery sparse_super
Default mount options: user_xattr acl
Filesystem state: clean
Errors behavior: Continue
Filesystem OS type: Linux
Inode count: 38152
Block count: 152584
Reserved block count: 7629
Free blocks: 128672
Free inodes: 38101
First block: 1
Block size: 1024
Fragment size: 1024
Reserved GDT blocks: 256
Blocks per group: 8192
Fragments per group: 8192
Inodes per group: 2008
Inode blocks per group: 251
and according to Wiki: http://en.wikipedia.org/wiki/Ext3
You can only get 2TB disks partitions.
Good news bad news.
Good news: You can use LVM to manually build up a 16TB disks by installing GAIA on the 2TB partition and then manually creating another 12TB partion with LVM and expanding the 2TB to include the 12 TB. Haven’t tried it…One site just made 6 2TB partitions and linked them with lvm.
Bad news: If I’m paying $1 gazillion for a Smart-1, it should see all the disk and memory I can physically jam into the box. Disaster recovery, build cycles, upgrades, migrations will be a nightmare with manually having to custom build the box every time.
RUMOR: I hear a rumor that if you re-install on this same platform, GAIA does not wipe out some unique UID on the disk pack and it will crash. You have to use the RAID tools to wipe the disk. Email me for more info. I just got this via the grapevine.
One time a Unix demigod yelled at me in public because I was writing my shell script in bash instead of /bin/sh. You’d think I drew a comic strip of {can’t speak of this religious figure because it has incited wars}. I mean it was like religion. I’ve been damaged goods ever since. Now I write my scripts in sh just because I’m afraid he’ll be lurking around the corner.
So in VSX and maybe its a GAIA thing, if you write your scripts in /bin/sh, you’ll notice you can’t access ‘vsenv’. The reason is the profile didn’t execute the /etc/profile.d/vsenv.sh script that inserts VSX functions into your /bin/sh environment.
So your scripts need to include:
#!/bin/sh
./etc/profile.d/CP.sh
. /etc/profile.d/vsenv.sh
Forgive me for my sins,
dreez
clishFound out that a new GAIA admin user in adminRole cannot execute external SPLAT commands in expert OR GAIA mode (cpstat, fwstat, tcpdump).
Pingtool saved my bacon.
Adding new admin user to CheckPoint Gaia with expert permissions
Make sure you ‘save config’
NOTE: you can add mutiple users with the duplicate UID 0 and it works.
So thats how you can create a raw admin mirror account.
If you need to create a read-only GAIA admin account that has SOME limited admin access this is the secret sauce to add to the above admin ( with UID 0 and GUID 0):
GAIA:
After reading this you can ‘role’ your own admin!
PS: Note if you:
add rba role testrole domain-type System all-features
You CANNOT delete individual features. Weird. You have to delete the whole role. Only if you add individual features you can take out one at a time.
THanks again!
dreez
Welcome back from the holidays people.
Here in Minneapolis its 40’s and raining and ugly. Kinda like London fog. It is suppose to be -30F below and 20 inches of snow!
So I decided to sit inside and work on updates to my cheat sheet. I now have GAIA and VSX in my sheet.
Notice that I rarely use GAIA unless I have to. I’m a died in wool SPLAT person. So my GAIA commands are limited. The only reason to use GAIA is if you are a routing geek and do dynamic routing on the firewall….which is insane in my opinion….but to each their own.
VSX on the other hand is really cool. I’m thinking everything will be in VSX someday.
I’m trying to build this uber SmartLog server. Running into problems that I hope to resolve and share. I’ve crashed R75.45 and found really obvious bugs where the counters don’t work. They sent me patches so maybe in R75.60??? you’ll get them too. Just a heads up.
Have a great 2013!!!
dreez
"The most difficult thing is the decision to act, the rest is merely tenacity." -Amelia Earhart
These are stories from my travels. Generally I like to write stories about local people that I meet and also brag about living the retirement dream with my #1 wife Gaby. She is also my only wife.