> Source: [sk120193](https://support.checkpoint.com/results/sk/sk120193)

# sk120193 - Gaia Fast Deployment (Blink)

| Property | Value |
|----------|-------|
| Solution ID | sk120193 |
| Date Created | 2017-09-05 |
| Last Modified | 2026-09-08 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server, Check Point Firewall |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.10, R82.20, R81 (EOS), R82.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.20 |
| OS | Gaia |

## Solution

**Table of Contents:**

* Introduction
* Basic Usage
* Advanced Usage (Command Line)
  * Installation Instructions
  * answers.xml
    * File Description
    * The *answers.xml* - default file (XML v1.1)
    * The *answers.xml* - for old Blink Security Gateway images (XML v1.0)
* Downloads
* Limitations
* Revision History

Click Here to Show the Entire Article

Introduction {#Introduction}
----------------------------

**Fast Deployment (Blink)**deployment flow and images let customers do a multi-step upgrade or clean install with one image.

Blink images already contain a specific base version (for example, R81.10), a designated role (for example, Security Gateway), and more hotfixes / Jumbo Hotfix Accumulators.

With this image, you can onboard new appliances/upgrade existing appliances with one package.

You can see and install Blink images in Gaia Portal or with Gaia Clish commands.

Basic Usage {#Basic Usage}
--------------------------

**Important Note:** Fast Deployment (Blink) mechanism is intended only for Check Point appliances and Open Servers on which Check Point software has been installed.

* **To deploy a new appliance through the First Time Wizard**

  1. Connect to the appliance with a web browser and log in.

     The First Time Configuration Wizard opens:

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/b1202410291738241.jpg)
  2. Select the option **Install from Check Point cloud:**

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/b2202410301312371.jpg)
  3. After configuring the external interface, the installation table shows a list of supported images.

     The latest images use Blink mechanism to install the version.

     The selected Blink image is downloaded and deployed on the appliance:

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/b3202410301313022.jpg)
* **Using Blink with CPUSE (Clean Install / Upgrade)**

  Blink packages installation is equivalent to the Major version installation:
  1. You see all the packages by categories and, by default, it shows the recommended packages only.

     **Note:** Use the filter button near the help icon and select the packages you wish to see:

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/b4202410301313323.jpg)
  2. Find the related package in the Blink section in CPUSE packages list:

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/b5202410301313594.jpg)
     1. For offline packages, manually import the package to CPUSE by clicking on **Import Package** on the top-right corner of the page:

        ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/b6202410301314235.jpg)
     2. To download a package from the list, right-click on the related package that is **Available for Download** and click on **Download**.

  3. After the download completes, right-click on the package and click on **Clean Install** or **Upgrade**(if available):

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/b7202410301316096.jpg)
  4. Installation/Upgrade starts, and you can follow the installation from CPUSE WebUI or CLI.

Advanced Usage (command line) {#Advanced Usage}
-----------------------------------------------

Show / Hide this Section   


### Installation Instructions {#Installation Instructions}

Show / Hide this Section   

**Important Note:** If the appliance is not after a clean install (the First Time Configuration Wizard has been run already), the "`--reimage`" flag needs to be used (see the "answers.xml" section).

Fast Deployment (Blink) image contains:

1. The root partition of a pre-installed Check Point appliance
2. Simplified First Time Configuration Wizard (will be used in case of attended installation)
3. Installation logic

The main files in the Fast Deployment (Blink) image are:

|--------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Directory / File         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| *BlinkInstaller*         | Main executable file that extracts and installs all the packages.                                                                                                                                                                                                                                                                                                                                                                                                                     |
| *CheckPoint_Gaia_fd.tgz* | This is the actual installation image.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| *installation_logic*     | Directory that contains ***internal*** installation logic: * `answers.xml` - User's configuration file for unattended installation. * `fd_wizard_gateway.sh` - (**Internal**) Shell script for unattended First Time Configuration Wizard. * `fd_wizard_gateway.sh.sha256` - (**Internal** ) Check Point Signature file for the `fd_wizard_gateway.sh` script. Note: The "`answers.xml`" file is the only file that a user is allowed to modify - refer to the section "answers.xml". |
| *manifest.xml*           | XML-based file that represents the structure of the Blink package (***internal***).                                                                                                                                                                                                                                                                                                                                                                                                   |
| *user_updates*           | Directory that may contain user shell scripts and binary files that should be executed and installed during the main installation process (after the reboot). The "`answers.xml`" file has to be edited to contain the name of the main shell script that will be executed (refer to the section "answers.xml").                                                                                                                                                                      |

**Important Note:** Blink mechanism is intended only Check Point appliances and Open Servers on which Check Point software has been installed.

**Action plan (basic mode only):**

1. Download all the required (and optional) files from the "Downloads" section.
2. Transfer all the files to the appliance (to a newly created directory).
3. Execute the Blink utility (reboot will be performed automatically).
4. Connect with your web browser to the Check Point appliance to complete the First Time Configuration Wizard.

**Detailed instructions:**

1. Download all the required (and optional) files from the "Downloads" section to your computer:

   1. Download the Blink utility
   2. Download the Blink image
   3. (Optional) Download the Blink Image updates package
2. Connect to the command line on the Check Point appliance / server.

3. Log in to the Expert mode.

4. Create some directory on the `/var/log/` partition (largest partition):

   `[Expert@HostName:0]# mkdir -v /var/log/MyDIR`
5. Transfer all the files from your computer to the newly created directory on the appliance.

   * Either transfer the files over SCP (recommended).

     Note: This requires changing the default shell of the admin user from `/etc/cli.sh` to `/bin/bash` (by running the Gaia Clish command "`set user admin shell /bin/bash`" - refer to the Gaia Administration Guide for your version).
   * Or transfer the files to a USB storage device and mount it on Gaia OS.

     Note: This requires working in the Expert mode. In addition, refer to [sk31657](https://support.checkpoint.com/results/sk/sk31657).
6. Go to the newly created directory:

   `[Expert@HostName:0]# cd /var/log/MyDIR`
7. Unpack the Blink utility package:

   `[Expert@HostName:0]# tar -zxvf blink.tgz`
8. Assign the execute permission to the Blink utility:

   `[Expert@HostName:0]# chmod -v +x blink`
9. Execute the Blink utility by running the desired basic flow:

   `[Expert@HostName:0]# ./blink [-i <path to Blink Image>] [-b <path to Blink Image updates package>] [-u <path to user TGZ file>] [-a <path to answers.xml file>] [-d <output directory>] [-x]`
   > where:
   >
   > |--------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
   > | Argument                                   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
   > | `-i <path to Blink Image>`                 | Specifies the path to the *Blink image*. If this path is not specified explicitly, then Blink will search in the current working directory for a file with prefix "`blink_image`".                                                                                                                                                                                                                                                                                                                                                                                    |
   > | `-b <path to Blink Image updates package>` | Specifies the path to the *Blink Image updates* package ("`blink_updates_<OSVERSION>.tgz`"). If this path is not specified explicitly, then Blink will search in the current working directory for a file "`blades_updates_<OSVERSION>.tgz`".                                                                                                                                                                                                                                                                                                                         |
   > | `-u <path to user TGZ file>`               | Specifies the path to the user TGZ file that contains user shell scripts and binary files that should be executed and installed during the main installation process. If this path is not specified explicitly, then Blink will search in the current working directory for a file "`blink_custom_content.tgz`". Note: The package "`blink_custom_content.tgz`" must contain the main shell script as specified in the "`answers.xml`" configuration file (by default, Blink will search for the script "`install_content.sh`" - refer to the section "answers.xml"). |
   > | `-a <path to answers.xml file>`            | Specifies the path to the user's configuration file for unattended installation (if needed). Refer to section "answers.xml".                                                                                                                                                                                                                                                                                                                                                                                                                                          |
   > | `-d <output directory>`                    | Specifies the output directory, into which the Blink image and all the other packages should be extracted. If this path is not specified explicitly, then the Blink image and all the other packages will be extracted into the "`/var/log/blink/launcher/files`" directory.                                                                                                                                                                                                                                                                                          |
   > | `-x`                                       | Specifies that Blink image should be *only* extracted, skipping the installation. This option is for advanced users that wish to configure an unattended installation - refer to ***Step 9*** below.                                                                                                                                                                                                                                                                                                                                                                  |
   > | `--reimage`                                | Using this flag will allow installation on appliances that are already configured (performed First Time Wizard). By default, a snapshot of the old partition is saved, unless the "`--delete-old-partition`" flag is supplied.                                                                                                                                                                                                                                                                                                                                        |
   > | `--delete-old-partition`                   | Removes the old partition. Does not override the "`--keep-old-partition`" flag.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
   > | `--keep-old-partition`                     | A snapshot of the old partition is saved if this flag is on.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

   *Example commands and their results:*
   1. Extract the Blink image and Blink Image updates package into a temporary directory and start the main installation process, keeping the old partition as a snapshot:

      `[Expert@HostName:0]# ./blink [-i <path to Blink Image>] [-b <path to Blink Image updates package>] [-u <path to user TGZ file>] [-a <path to answers.xml file>] --keep-old-partition`
      > 1. A temporary directory `/var/log/blink/launcher/files` will be created.
      >
      > 2. The Blink Image will be extracted to the `/var/log/blink/launcher/files/` directory.
      >
      > 3. The Blink Image updates package `blink_updates_<OSVERSION>.tgz` will be copied to the `/var/log/blink/launcher/files/blades_updates/` directory.
      >
      > 4. The user update shell script and binary files will be copied to the `/var/log/blink/launcher/files/user_updates/` directory.
      >
      > 5. The main installation process will be started.
      >
      > 6. A snapshot of the old partition will be saved.

   2. Extract the Blink image and Blink Image updates package into a specified directory and start the main installation process, on an already configured appliance, and NOT saving the old partition as snapshot:

      `[Expert@HostName:0]# ./blink [-i <path to Blink Image>] [-b <path to Blink Image updates package>] [-u <path to user TGZ file>] [-a <path to answers.xml file>] -d <output directory> --reimage --delete-old-partition`
      > 1. The Blink Image will be extracted in the specified output directory.
      >
      > 2. The Blink Image updates package "`blink_updates_<OSVERSION>.tgz`" will be copied to the specified output directory.
      >
      > 3. The user update shell script and binary files will be copied to the specified output directory.
      >
      > 4. The main installation process will be started.
      >
      > 5. Validation for a configured appliance will be skipped.
      >
      > 6. A snapshot of the old partition will NOT be created.

   3. Extract the Blink image into a a specified directory and do NOT start the main installation process:

      `[Expert@HostName:0]# ./blink [-i <path to Blink Image>] -x -d <output directory>`
      > 1. The Blink Image will be extracted to the specified output directory.
      >
      >    If the output directory is not specified, then it will be extracted to the temporary directory `/var/log/blink/launcher/files/`.
      > 2. The main installation process will *NOT* be started.

10. For advanced users that wish to configure custom settings:

    1. Extract and configure the Blink image:

       1. Extract all the files from the Blink image (to get access to the internal configuration files) - either to the temporary directory "`/var/log/blink/launcher/files/`", or to the specified directory:

          `[Expert@HostName:0]# ./blink [-i <path to Blink Image>] -x [-d <output directory>]`
       2. Configure the desired settings in the "`installation_logic/answers.xml`" file - refer to the "answers.xml" section.

    2. Add the *Blink Image updates* package:

       1. Add the package "`blades_updates/blink_updates_<OSVERSION>.tgz`"

    3. Extract the desired user packages:

       1. Extract the desired user packages to the "`user_updates`" directory.

          Note: If the main user shell script is not called "`install_content.sh`", then make sure it matches the script defined in the "`installation_logic/answers.xml`" file (refer to the section "answers.xml").
    4. Start the main installation process:

       `[Expert@HostName:0]# cd /path/to/extracted/Blink_Image/`

       `[Expert@HostName:0]# ./BlinkInstaller`
    {#How to use the Blink mechanism - Step 9}
{#How to use the Blink mechanism - Step 9}
11. You can monitor the Blink installation process in two ways (until the appliance is rebooted automatically):

    * Query the current state by running *one* of these commands:

      `[Expert@HostName:0]# ./BlinkInstaller -status {json | full | id}`

      where:
      >
      > |---------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
      > | Option                          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                       |
      > | `./BlinkInstaller -status json` | Returns the last recorded status in JSON format. *Example:* > ``` > [Expert@HostName:0]# ./BlinkInstaller -status json > { >    "isCompleted" : "true", >    "stageEndTime" : "5:0:4", >    "stageID" : "finish_message", >    "stageName" : "BlinkInstaller Installation", >    "stageStartTime" : "4:56:39", >    "state" : "Success", >    "statusDescription" : "The installation has finished successfully and is pending reboot!" > } > ``` |
      > | `./BlinkInstaller -status full` | Returns the last recorded status in a single-string representation. *Example:* > ` [Expert@HostName:0]# ./BlinkInstaller -status full` > ` BlinkInstaller Installation - The installation has finished successfully and is pending reboot! - Success [Started at: 4:56:39] [Ended at:5:0:4] `                                                                                                                                                     |
      > | `./BlinkInstaller -status id`   | Returns the last status recorded identifier as a string. *Example:* > ` [Expert@HostName:0]# ./BlinkInstaller -status id` > ` finish_message `                                                                                                                                                                                                                                                                                                    |

    * Check the output log and status files:

      * `/var/log/blink/logs_<DATE>/Main_log.elg`

      * `/var/log/blink/status.txt`

12. Reboot will be performed automatically.

13. Connect with your web browser to the Check Point appliance to complete the First Time Configuration Wizard (basic mode only).

    > *Example of First Time Configuration Wizard after attended installation:*
    >
    > [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/Blink-6.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120193/Blink-6.png)

### answers.xml {#Answer.xml}

Show / Hide this Section   

* **File Description:** This is an XML-based file (located in the "`installation_logic`" directory) that contains user's configuration for unattended installation.
  {#File Description}
{#File Description}
* **The *answers.xml* - default file (XML v1.1)**

  Show / Hide this Section   

  * **Default File (XML v1.1):**

    ```

    <properties xmlVersion="1.1">
    	<installation>
    		<reboot_delay>10</reboot_delay>
    	</installation>
    	<machine_configuration>
    		<perform>false</perform>
    		<hostname>GWOBJECT_NAME_FIELD</hostname>
    		<password_hash>PASSWORD_HASH_FIELD</password_hash>
    		<maintenance_hash>Maintenance_HASH_FIELD</maintenance_hash>
    		<network>
    			<ipv4addr>IPV4_FIELD</ipv4addr>
    			<masklength>IPV4_MASKLENGTH_FIELD</masklength>
    			<interface>IPV4_INTERFACE_FIELD</interface>
    			<default_gw>DEFAULTGW_FIELD</default_gw>
    			<ipv6addr>IPV6_FIELD</ipv6addr>
    			<ipv6mask>IPV6_MASKLENGTH_FIELD</ipv6mask>
    			<ipv6default_gw>IPV6_DEFAULTGW_FIELD</ipv6default_gw>
    		</network>
    		<role_configuration>
    			<gateway>
    				<!--  activation_key must be in base64 encoding -->
    				<activation_key>SIC_BASED64_FIELD</activation_key>
    				<cluster>false</cluster>
    			</gateway>
    			<management>
    				<credentials>
    					<use_gaia_admin>true</use_gaia_admin>
    					<!--  Relevant only if use_gaia_admin is false -->
    					<admin_name>MGMT_ADMIN_FIELD</admin_name>
    					<!--  admin_password must be in base64 encoding -->
    					<admin_password>MGMT_PASS_BASED64_FIELD</admin_password>
    				</credentials>
    			</management>
    		</role_configuration>
    		<send_data_to_usercenter>true</send_data_to_usercenter>
    		<enable_download_from_checkpoint>true</enable_download_from_checkpoint>
    	</machine_configuration>
    	<user_updates>
    		<entry_point>install_content.sh</entry_point>
    	</user_updates>
    	
    	<!--
    	logging - Used in order to filter the logs saved to files, displayed on the screen or sent to the syslog.
    	Supported logging levels: DEBUG, NORMAL, ERROR, ALWAYS, NEVER
    	Colors - Should be set to true for displaying log messages in color on the screen.
    	-->
    	<logging>
    		<file_level>DEBUG</file_level>
    		<screen_level>NORMAL</screen_level>
    		<sys_log_level>NEVER</sys_log_level>
    		<colors>true</colors>
    	</logging>
    </properties>
    ```

  <!-- -->

  * **Supported XML elements:**

    The root XML element is "**`properties`**".

    Enter the string to filter this table:

    |-----------------------------------|-----------------|--------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
    | Section                           | Sub-Section     | XML element                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
    | <installation>                    |                 | <reboot_delay>                 | Specifies the delay (in seconds) before rebooting the appliance after completing the installation process. The default delay is: 10 To suppress the reboot completely, define the value -1 (**not recommended**).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | <machine_configuration>           |                 | <perform>                      | Specifies the whether to perform the unattended installation or not: * `true` - perform the unattended installation * `false` - (default) do not perform the unattended installation (other elements in the `<machine_configuration>` sub-section will be ignored)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
    | <machine_configuration>           |                 | <hostname>                     | Specifies the appliance's HostName to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
    | <machine_configuration>           |                 | <password_hash>                | Specifies the appliance's admin password to configure during the unattended installation. * The hash value of the password string (e.g., 72ae...c3d8) Run one of the following commands in the Expert mode to get the hash value of the admin password from the configured system (must use the same Gaia OS version): * `dbget passwd:admin:passwd` * `grep admin /etc/shadow | cut -d: -f2`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
    | <machine_configuration>           |                 | <maintenance_hash>             | The maintenance_hash is password for the GRUB boot loader. Starting in R81.20, it is mandatory. This password must be generated on a server that already has R81.20 or higher installed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
    | <machine_configuration>           | <network>       |                                | This sub-section specifies the network interface configurations that will apply during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
    | <machine_configuration>           | <network>       | <ipv4addr>                     | Specifies the appliance's IPv4 address (X.X.X.X) to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | <machine_configuration>           | <network>       | <masklength>                   | Specifies the appliance's IPv4 address subnet mask length (1-32) to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | <machine_configuration>           | <network>       | <interface>                    | Specifies the appliance's main management interface to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
    | <machine_configuration>           | <network>       | <default_gw>                   | Specifies the appliance's default gateway (IPv4) to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | <machine_configuration>           | <network>       | <ipv6addr>                     | Specifies the appliance's IPv6 address (X:X:X:X:X:X:X:X) to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
    | <machine_configuration>           | <network>       | <ipv6mask>                     | Specifies the appliance's IPv6 address subnet mask length (1-128) to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
    | <machine_configuration>           | <network>       | <ipv6default_gw>               | Specifies the appliance's default gateway (IPv6) to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | <role_configuration>              |                 |                                | This sub-section specifies the role-based configurations that will apply during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
    | <role_configuration>              | <gateway>       |                                | This sub-section specifies the Security Gateway configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
    | <role_configuration>              |                 | <activation_key>               | Specifies the appliance's SIC one-time key to configure during the unattended installation. The SIC key must be provided in the Base64 encoding.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
    | <role_configuration>              |                 | <cluster>                      | Flag that specifies whether to enable cluster membership on the Security Gateway or not.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
    | <role_configuration>              | <management>    |                                | This sub-section specifies the Security Management Server configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
    | <role_configuration>              |                 | <credentials>                  | This sub-section specifies the credentials for the Security Management administrator.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
    | <role_configuration>              |                 | <credentials> <use_gaia_admin> | Constant flag that specifies whether to use the Gaia credentials as the Security Management administrator or define a new administrator: * `true` - (default) use the Gaia credentials * `false` - define a new administrator                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
    | <role_configuration>              |                 | <credentials> <admin_name>     | Specifies the username for the Security Management administrator. Relevant only if "`use_gaia_admin`" set to "`false`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
    | <role_configuration>              |                 | <credentials> <admin_password> | Specifies the password for the Security Management administrator. Password must be provided in the Base64 encoding. Relevant only if "`use_gaia_admin`" is set to "`false`".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
    | <send_data_to_usercenter>         |                 |                                | Consent flag that specifies whether the appliance is allowed to send various statistics data to Check Point Cloud (refer to [sk111080](https://support.checkpoint.com/results/sk/sk111080)): * `true` - (default) send various statistics data to Check Point Cloud * `false` - do not send various statistics data to Check Point Cloud                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
    | <enable_download_from_checkpoint> |                 |                                | Consent flag that specifies whether the appliance is allowed to download various data (updates, latest packages, contracts, etc.) from Check Point Cloud (refer to [sk111080](https://support.checkpoint.com/results/sk/sk111080)): * `true` - (default) download various data from Check Point Cloud * `false` - do not download various data from Check Point Cloud                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
    | <user_updates>                    |                 | <entry_point>                  | Specifies the main executable user shell script to call during the unattended installation, which will perform the desired operations. The default script name is: `install_content.sh` Example: The "`user_updates`" directory contains: * The main user shell script "`install_content.sh`" with the following commands: `#!/bin/bash` `Log_File="/var/log/user_main_script.log"` `echo "Configuring Mgmt interface..." >> $Log_File` `clish -i -s -f "clish_commands.txt" >> $Log_File` `echo "Installing private RPMs..." >> $Log_File` `rpm -ihv some_private_RPM.rpm >> $Log_File` `exit 0` * The file with relevant Gaia Clish commands "`clish_commands.txt`": `lock database override` `set interface Mgmt auto-negotiation off` `set interface Mgmt state on` `set interface Mgmt link-speed 100M/full` `set interface Mgmt ipv4-address 192.168.1.1 subnet-mask 255.255.255.0` * User RPM package "*some_private_RPM.rpm*" |
    | <logging>                         | <file_level>    |                                | Specifies the desired priority to filter the log entries saved in the main log file "`/var/log/blink/logs_<DATE>/Main_log.elg`" (order below is from highest to lowest priority): 1. `DEBUG` (default) 2. `NORMAL` 3. `ERROR` 4. `ALWAYS` 5. `NONE` For example, if "`file_level`" is set to "`ERROR`", then messages marked as "Debug" and "Normal" will not be written to the log file - only messages marked as "Errors" and "Always" will be written to the log file. If "`file_level`" is set to "`NONE`", then no messages will be written to the log file.                                                                                                                                                                                                                                                                                                                                                                     |
    | <logging>                         | <screen_level>  |                                | Specifies the desired priority to filter the log entries displayed on the screen (order below is from highest to lowest priority): 1. `DEBUG` 2. `NORMAL` (default) 3. `ERROR` 4. `ALWAYS` 5. `NONE` For example, if "`screen_level`" is set to "`ERROR`", then messages marked as "Debug" and "Normal" will not be displayed on the screen - only messages marked as "Errors" and "Always" will be displayed on the screen. If "`screen_level`" is set to "`NONE`", then no messages will be displayed on the screen.                                                                                                                                                                                                                                                                                                                                                                                                                |
    | <logging>                         | <sys_log_level> |                                | Specifies the desired priority to filter the log entries sent to Syslog server (order below is from highest to lowest priority): 1. `DEBUG` 2. `NORMAL` 3. `ERROR` 4. `ALWAYS` 5. `NONE` (default) For example, if "`sys_log_level`" is set to "`ERROR`", then messages marked as "Debug" and "Normal" will not be sent to Syslog server - only messages marked as "Errors" and "Always" will be sent to Syslog server. If "`sys_log_level`" is set to "`NONE`", then no messages be sent to Syslog server.                                                                                                                                                                                                                                                                                                                                                                                                                           |
    | <logging>                         | <colors>        |                                | Specifies whether to use colors on the screen or not (refer to "<screen_level>"): * `true` - (default) use colors on the screen * `false` - do not use colors on the screen                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |

    {#Filter_answers_xmlTable}

  <!-- -->

  * **Management Server example file (XML v1.1):**

    ```
    <properties xmlVersion="1.1">

    	<installation>
    		<reboot_delay>10</reboot_delay>
    	</installation>

    	<machine_configuration>
    		<perform>false</perform>
    		<hostname>MyGW123</hostname>
    		<password_hash>$1$Es1wXWZ8$vVK0iT0nXRiGdYZ9zb6ah/</password_hash>
    		<maintenance_hash>grub.pbkdf2.sha512.10000.220BD6CF50DDABECBC0E66ADC5C7DD64FE8B337ADA2A34665BBF1</maintenance_hash>
    		<network>
    			<ipv4addr>192.168.1.22</ipv4addr>
    			<masklength>24</masklength>
    			<interface>Mgmt</interface>
    			<default_gw>192.168.1.254</default_gw>
    		</network>
    		<role_configuration>
    			<gateway>
    				<!-- activation_key must be in base64 encoding -->
    				<activation_key>SIC_BASED64_FIELD</activation_key>
    				<cluster>false</cluster>
    			</gateway>
    			<management>
    				<credentials>
    					<use_gaia_admin>false</use_gaia_admin>
    					<!--  Relevant only if use_gaia_admin is false -->
    					<admin_name>myadmin</admin_name>
    					<!--  admin_password must be in base64 encoding -->
    					<admin_password>YWRtaW5wYXNzMTIz</admin_password>
    				</credentials>
    			</management>
    		</role_configuration>
    		<send_data_to_usercenter>true</send_data_to_usercenter>
    		<enable_download_from_checkpoint>true</enable_download_from_checkpoint>
    	</machine_configuration>
    	<user_updates>
    		<entry_point>install_content.sh</entry_point>
    	</user_updates>

    	<!--
    	logging - Used in order to filter the logs saved to files, displayed on the screen or sent to the syslog.
    	Supported logging levels: DEBUG, NORMAL, ERROR, ALWAYS, NEVER
    	Colors - Should be set to true for displaying log messages in color on the screen.
    	-->
    	<logging>
    		<file_level>DEBUG</file_level>
    		<screen_level>NORMAL</screen_level>
    		<sys_log_level>NEVER</sys_log_level>
    		<colors>true</colors>
    	</logging>
    </properties>

    ```

  {#answers.xml version 1.1}
{#answers.xml version 1.1}
* **The *answers.xml* - file for old Blink Security Gateway images (XML v1.0)**

  Show / Hide this Section   

  * **Default File (XML v1.0):**

    ```
    <?xml version="1.0" encoding="UTF-8"?>

    <properties xmlVersion="1.0">
    	<installation>
    		<reboot_delay>10</reboot_delay>
    	</installation>
    	<machine_configuration>
    		<perform>false</perform>
    		<hostname>GWOBJECT_NAME_FIELD</hostname>
    		<password>
    			<value>PASSWORD_FIELD</value>
    			<is_hash>true</is_hash>
    		</password>
    		<network>
    			<ipv4addr>IPV4_FIELD</ipv4addr>
    			<masklength>IPV4_MASKLENGTH_FIELD</masklength>
    			<interface>IPV4_INTERFACE_FIELD</interface>
    			<default_gw>DEFAULTGW_FIELD</default_gw>
    		</network>
    		<activation_key>SIC_FIELD</activation_key>
    		<cluster>false</cluster>
    		<send_data_to_usercenter>true</send_data_to_usercenter>
    		<enable_download_from_checkpoint>true</enable_download_from_checkpoint>
    	... ...
    	</machine_configuration>

    	<user_updates>
    		<entry_point>install_content.sh</entry_point>
    	</user_updates>

    	<!--
    	logging - Used in order to filter the logs saved to files, displayed on the screen or sent to the syslog.
    	Supported logging levels: DEBUG, NORMAL, ERROR, ALWAYS, NEVER
    	Colors - Should be set to true for displaying log messages in color on the screen.
    	-->
    	<logging>
    		<file_level>DEBUG</file_level>
    		<screen_level>NORMAL</screen_level>
    		<sys_log_level>NEVER</sys_log_level>
    		<colors>true</colors>
    	</logging>
    </properties>

    ```

  <!-- -->

  * **Supported XML elements:**

    The root XML element is "**`properties`**".

    Enter the string to filter this table:

    |-------------------------|-------------|-----------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
    | Section                 | Sub-Section | XML element                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
    | <installation>          |             | <reboot_delay>                    | Specifies the delay (in seconds) before rebooting the appliance after completing the installation process. The default delay is: 10 To suppress the reboot completely, define the value -1 (**not recommended**).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
    | <machine_configuration> |             | <perform>                         | Specifies the whether to perform the unattended installation or not: * `true` - perform the unattended installation * `false` - (default) do not perform the unattended installation (other elements in the `<machine_configuration>` sub-section will be ignored)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
    | <machine_configuration> |             | <hostname>                        | Specifies the appliance's HostName to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
    | <machine_configuration> | <password>  |                                   | This sub-subsection specifies the appliance's admin password to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
    | <machine_configuration> | <password>  | <value>                           | Specifies the appliance's admin password string: * either plain-text string (e.g., `password123`) * or hash value of the password string (e.g., `72ae...c3d8`) > Run one the following commands in the Expert mode to get the hash value of the admin password from the configured system (must use the same Gaia OS version): > * `dbget passwd:admin:passwd` > * `grep admin /etc/shadow | cut -d: -f2`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
    | <machine_configuration> | <password>  | <is_hash>                         | Specifies how the appliance's admin password string was defined in the "`<value>`" element: * `false` - the defined appliance's admin password string is a plain-text string * `true` - (default) the defined appliance's admin password string is a hash value of the password string                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
    | <machine_configuration> | <network>   |                                   | This sub-section specifies the network interface configurations that will apply during the unattended installation                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
    | <machine_configuration> | <network>   | <ipv4addr>                        | Specifies the appliance's IPv4 address (X.X.X.X) to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
    | <machine_configuration> | <network>   | <masklength>                      | Specifies the appliance's IPv4 address subnet mask length (0-32) to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
    | <machine_configuration> | <network>   | <interface>                       | Specifies the appliance's main management interface to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
    | <machine_configuration> | <network>   | <default_gw>                      | Specifies the appliance's default gateway to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
    | <machine_configuration> |             | <activation_key>                  | Specifies the appliance's SIC one-time key to configure during the unattended installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
    | <machine_configuration> |             | <cluster>                         | Flag that specifies whether to enable cluster membership for the gateway or not.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
    | <machine_configuration> |             | <send_data_to_usercenter>         | Consent flag that specifies whether the appliance is allowed to send various statistics data to Check Point Cloud (refer to [sk111080](https://support.checkpoint.com/results/sk/sk111080)): * `true` - (default) send various statistics data to Check Point Cloud * `false` - do not send various statistics data to Check Point Cloud                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
    | <machine_configuration> |             | <enable_download_from_checkpoint> | Consent flag that specifies whether the appliance is allowed to download various data (updates, latest packages, contracts, etc.) from Check Point Cloud (refer to [sk111080](https://support.checkpoint.com/results/sk/sk111080)): * `true` - (default) download various data from Check Point Cloud * `false` - do not download various data from Check Point Cloud                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
    | <user_updates>          |             | <entry_point>                     | Specifies the main executable user shell script to call during the unattended installation, which will perform the desired operations. The default script name is: `install_content.sh` *Example:* The "`user_updates`" directory contains: 1. The main user shell script `install_content.sh` with the following commands: ` #!/bin/bash` ` Log_File="/var/log/user_main_script.log"` ` echo "Configuring Mgmt interface..." >> $Log_File` ` clish -i -s -f "clish_commands.txt" >> $Log_File` ` echo "Installing private RPMs..." >> $Log_File` ` rpm -ihv some_private_RPM.rpm >> $Log_File` ` exit 0` 2. The file with relevant Gaia Clish commands `clish_commands.txt`: ` lock database override` ` set interface Mgmt auto-negotiation off` ` set interface Mgmt state on` ` set interface Mgmt link-speed 100M/full` ` set interface Mgmt ipv4-address 192.168.1.1 subnet-mask 255.255.255.0 ` 3. User RPM package `some_private_RPM.rpm` |
    | <logging>               |             | <file_level>                      | Specifies the desired priority to filter the log entries saved in the main log file "`/var/log/blink/logs_<DATE>/Main_log.elg`" (order below is from highest to lowest priority): 1. `DEBUG` (default) 2. `NORMAL` 3. `ERROR` 4. `ALWAYS` 5. `NONE` For example, if "`file_level`" is set to "`ERROR`", then messages marked as "Debug" and "Normal" will not be written to the log file - only messages marked as "Errors" and "Always" will be written to the log file. If "`file_level`" is set to "`NONE`", then no messages will be written to the log file.                                                                                                                                                                                                                                                                                                                                                                                 |
    | <logging>               |             | <screen_level>                    | Specifies the desired priority to filter the log entries displayed on the screen (order below is from highest to lowest priority): 1. `DEBUG` 2. `NORMAL` (default) 3. `ERROR` 4. `ALWAYS` 5. `NONE` For example, if "`screen_level`" is set to "`ERROR`", then messages marked as "Debug" and "Normal" will not be displayed on the screen - only messages marked as "Errors" and "Always" will be displayed on the screen. If "`screen_level`" is set to "`NONE`", then no messages will be displayed on the screen.                                                                                                                                                                                                                                                                                                                                                                                                                            |
    | <logging>               |             | <sys_log_level>                   | Specifies the desired priority to filter the log entries sent to Syslog server (order below is from highest to lowest priority): 1. `DEBUG` 2. `NORMAL` 3. `ERROR` 4. `ALWAYS` 5. `NONE` (default) For example, if "`sys_log_level`" is set to "`ERROR`", then messages marked as "Debug" and "Normal" will not be sent to Syslog server - only messages marked as "Errors" and "Always" will be sent to Syslog server. If "`sys_log_level`" is set to "`NONE`", then no messages be sent to Syslog server.                                                                                                                                                                                                                                                                                                                                                                                                                                       |
    | <logging>               |             | <colors>                          | Specifies the whether to use colors on the screen or not (refer to "<screen_level>"): * `true` - (default) use colors on the screen * `false` - do not use colors on the screen                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |

    {#Filter_answers_xmlTable}
  * **Example File (XML v1.0):**

    ```
    <?xml version="1.0" encoding="UTF-8"?>

    <properties xmlVersion="1.0">

    	<installation>
    		<reboot_delay>10</reboot_delay>
    	</installation>

    	<machine_configuration>
    		<perform>true</perform>
    		<hostname>MyGW123</hostname>
    		<password>
    			<value>mypassword</value>
    			<is_hash>false</is_hash>
    		</password>
    		<network>
    			<ipv4addr>192.168.1.22</ipv4addr>
    			<masklength>24</masklength>
    			<interface>Mgmt</interface>
    			<default_gw>192.168.1.254</default_gw>
    		</network>
    		<activation_key>12345</activation_key>
    		<cluster>true</cluster>
    		<send_data_to_usercenter>true</send_data_to_usercenter>
    		<enable_download_from_checkpoint>true</enable_download_from_checkpoint>
    	</machine_configuration>

    	<user_updates>
    		<entry_point>install_content.sh</entry_point>
    	</user_updates>

    	<!--
    	logging - Used in order to filter the logs saved to files, displayed on the screen or sent to the syslog.
    	Supported logging levels: DEBUG, NORMAL, ERROR, ALWAYS, NEVER
    	Colors - Should be set to true for displaying log messages in color on the screen.
    	-->
    	<logging>
    		<file_level>DEBUG</file_level>
    		<screen_level>NORMAL</screen_level>
    		<sys_log_level>NEVER</sys_log_level>
    		<colors>true</colors>
    	</logging>
    </properties>

    ```

  {#answers.xml version 1.0}
{#answers.xml version 1.0}

Downloads {#Downloads}
----------------------

Show / Hide this Section   


### Fast Deployment Image (Blink) Utility {#Toggle_downloads}

Blink Utility - the main utility that extracts the Blink Image and other packages, and installs them. Starting from R80.20, Blink Utility is a part of release.

|---------------------------|---------------------------------------------------------------------------------------------------------------------------------------|
| Description               | Link to download                                                                                                                      |
| Blink Utility version 1.1 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/58510) (TGZ) |

To verify the version of the Blink Utility you have, run the below command in the Expert mode:

`[Expert@Host:0]# blink --version`  
`Blink Utility version: 1.1`

Run "`blink --help`" for help.

### Fast Deployment Image (Blink) Images - the Gaia OS images

***Security Management Fast Deployment Image GA Images***

|--------------------------------------------------------------------------------------------------------------------------------------|-------------|-----------------------------------------------------------------------------------------------------------------------------------------------|
| Version                                                                                                                              | Date        | Download Link                                                                                                                                 |
| **[R82](https://support.checkpoint.com/results/sk/sk181127) (GA Take 777)**                                                          | 21 Oct 2024 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/135034) (TGZ)        |
| **[R81.20](https://support.checkpoint.com/results/sk/sk173903) (GA Take 631)**                                                       | 21 Nov 2022 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/124409) (TGZ)        |
| **[R81.10](https://support.checkpoint.com/results/sk/sk170416) (GA Take 335)**                                                       | 06 Jul 2021 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/115162) (TGZ)        |
| **[R81](https://support.checkpoint.com/results/sk/sk166715) (GA Take 392)[](https://support.checkpoint.com/results/sk/sk122485)**    | 22 Oct 2020 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/109196) (TGZ)        |
| **[R80.40](https://support.checkpoint.com/results/sk/sk160736) (GA Take 294)[](https://support.checkpoint.com/results/sk/sk122485)** | 28 Jan 2020 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/102394) (TGZ)        |
| **[R80.30](https://support.checkpoint.com/results/sk/sk144293) (GA Take 200)[](https://support.checkpoint.com/results/sk/sk122485)** | 06 Jun 2019 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/91363) (TGZ)         |
| **[R80.20](https://support.checkpoint.com/results/sk/sk122485) (GA Take 117)[](https://support.checkpoint.com/results/sk/sk111841)** | 15 Oct 2019 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/78206) (TGZ)         |
| **[R80.10](https://support.checkpoint.com/results/sk/sk111841) (GA Take 479) (except Smart-1 525/5150)**                             | 05 Apr 2020 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/72129) (TGZ)         |
| **[R80.10](https://support.checkpoint.com/results/sk/sk111841) for Smart-1 525/5150 appliance**                                      | 17 Sep 2018 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink Image updates")](https://support.checkpoint.com/results/download/72133) (TGZ) |

* To check if a custom Blink image that includes specific ad-hoc hotfixes can be created, you can [contact Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html).
* To download the latest Blink Image for Security Management including Jumbo Hotfix, refer to
  * [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R80.30](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.30/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R80.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.20/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R80.10](https://support.checkpoint.com/results/sk/sk116380)

***Security Gateway Fast Deployment Image GA Images***

|--------------------------------------------------------------------------------------------------------------------------------------|-------------|-----------------------------------------------------------------------------------------------------------------------------------------------|
| Version                                                                                                                              | Date        | Download Link                                                                                                                                 |
| **[R82](https://support.checkpoint.com/results/sk/sk181127) (GA Take 777)**                                                          | 21 Oct 2024 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/135033) (TGZ)        |
| **[R81.20](https://support.checkpoint.com/results/sk/sk173903) (GA Take 631)**                                                       | 21 Nov 2022 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/124408) (TGZ)        |
| **[R81.10](https://support.checkpoint.com/results/sk/sk170416) (GA Take 335)**                                                       | 06 Jul 2021 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/115161) (TGZ)        |
| **[R81](https://support.checkpoint.com/results/sk/sk166715) (GA Take 392)[](https://support.checkpoint.com/results/sk/sk122485)**    | 22 Oct 2020 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/109195) (TGZ)        |
| **[R80.40](https://support.checkpoint.com/results/sk/sk160736) (GA Take 294)[](https://support.checkpoint.com/results/sk/sk122485)** | 28 Jan 2019 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/102168) (TGZ)        |
| **[R80.30](https://support.checkpoint.com/results/sk/sk144293) (GA Take 200)[](https://support.checkpoint.com/results/sk/sk122485)** | 06 Jun 2019 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/91362) (TGZ)         |
| **[R80.20](https://support.checkpoint.com/results/sk/sk122485) (GA Take 117)[](https://support.checkpoint.com/results/sk/sk111841)** | 23 Sep 2019 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink image")](https://support.checkpoint.com/results/download/78205) (TGZ)         |
| **[R80.10](https://support.checkpoint.com/results/sk/sk111841) (GA Take 479)**                                                       | 05 Apr 2020 | [![](https://sc1.checkpoint.com/sc/images/download-m.png "Blink Image updates")](https://support.checkpoint.com/results/download/60684) (TGZ) |

* To check if a custom Blink image that includes specific ad-hoc hotfixes can be created, you can [contact Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html).
* To download the latest Blink Image for Security Gateway including Jumbo Hotfix, refer to
  * [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R80.30](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.30/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R80.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.20/Default.htm) \> Downloads
  * [Jumbo Hotfix Accumulator for R80.10](https://support.checkpoint.com/results/sk/sk116380)

Limitations {#Limitations}
--------------------------

|------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID         | Symptoms                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| -          | Standalone installations are not supported.                                                                                                                                                                                                                                                                                                                                                                                                                          |
| -          | Default value for "Management GUI Clients" property is set to "*Any*".                                                                                                                                                                                                                                                                                                                                                                                               |
| DP-2884    | Using Blink images to downgrade the Gaia OS from kernel 3.10 to 2.6.18 is prohibited. * Use the "*revert to snapshot*" option to return to the previous version.                                                                                                                                                                                                                                                                                                     |
| DP-1644    | Reimage: Blink reimage is blocked from running on VSX Gateways.                                                                                                                                                                                                                                                                                                                                                                                                      |
| PMTR-41564 | You can install Blink images on VSX Gateways only if Blink images are R80.40 and higher.                                                                                                                                                                                                                                                                                                                                                                             |
| -          | No automatic Cleanup in case of un-normal progress interruption (power problem, early reboot, etc...). In case interruption, perform the following (in the Expert mode): 1. Unmount the blink new partitions with this command: `umount /mnt/fcd/proc /mnt/fcd/sys /mnt/fcd/dev /mnt/fcd/var/log /mnt/fcd/tmp /mnt/fcd /mnt/BlinkPlugAndPlay_usb` 2. Remove the blink new partition with this command: `lvremove /dev/vg_splat/lv_fcd_new` 3. Run the process again. |
| -          | Blink does not support Secondary Security Management Servers in the Management High Availability configuration. Note: This limitation does not apply to Multi-Domain Security Management Servers.                                                                                                                                                                                                                                                                    |

Revision History {#Revision History}
------------------------------------

Show / Hide revision history  


|--------------|---------------------------------------------------------------------------------------------|
| Date         | Description                                                                                 |
| 07 Sep 2025  | Improved formatting                                                                         |
| 01 Jul 2025  | Resolved limitation "Bond Configuration is not preserved during Blink installation"         |
| 21 Oct 2024  | Added support for R82                                                                       |
| 31 Oct 2023  | Updated the answers.xml version 1.1 default file                                            |
| 14 Aug 2023  | Updated Limitation section                                                                  |
| 17 Jan 2023  | Updated Limitation section                                                                  |
| 15 Jan 2023  | Revised article. Added Basic Usage and Advanced Usage sections                              |
| 05 Nov 2020  | Updated the Supported deployments section                                                   |
| 22 Oct 2020  | Added support for R81                                                                       |
| 05 Apr 2020  | Added Security Gateway and Management images for R80.10 (GA Take 479)                       |
| 28 Jan 2020  | Added support for R80.40                                                                    |
| 19 Dec 2019  | Added PMTR-47403 to the list of Limitations                                                 |
| 11 Dec 2019  | Added support for Upgrade of R80.30 Security Gateways                                       |
| 13 Nov 2019  | Added Security Gateway and Management images for R80.20 with R80.20 Jumbo Hotfix Take 118   |
| 02 Oct 2019  | Added Security Gateway and Management images for R80.20 with R80.20 Jumbo Hotfix Take 103   |
| 23 Sep 2010  | R80.20 Security Gateway image was updated to Take 117                                       |
| 06 June 2019 | Added support for R80.30                                                                    |
| 26 May 2019  | Added "Blink image installation" section                                                    |
| 27 Mar 2019  | List of Known Limitations was updated                                                       |
| 18 Dec 2018  | Added R80.20 Security Gateway and Security Management images                                |
| 14 Oct 2018  | Security Gateway Images have been replaced                                                  |
| 17 Sep 2018  | Added Blink Security Management Images and new `answers.xml` file instructions              |
| 18 Jul 2018  | Added the "Deploying Check Point NG Firewalls just got easier with the Blink utility" video |
| 14 May 2018  | Added Blink Image for R80.10 Jumbo Hotfix Take 103 and R77.30 Jumbo Hotfix Take 302         |
| 07 May 2018  | Updated the "*How to use the Blink mechanism*" section                                      |
| 19 Mar 2018  | Added Blink Image for R80.10 Jumbo Hotfix Take 70                                           |
| 24 Jan 2018  | All images were updated to support appliances with a software RAID                          |
| 21 Jan 2018  | Added Blink Image for R80.10 (GA Take 462)                                                  |
| 31 Dec 2017  | First release of this article                                                               |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
