<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding a VLAN Interface into firewall cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-a-VLAN-Interface-into-firewall-cluster/m-p/99321#M10381</link>
    <description>&lt;P&gt;What you described should work totally ok. Wether to do manual spoofing or fetch topology automatically is a personal choice. We use automated option and never really had any problems. No interruptions or failovers during configuration. I just find manual prone to errors if you have high number of interfaces and routes.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Oct 2020 18:30:07 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2020-10-16T18:30:07Z</dc:date>
    <item>
      <title>Adding a VLAN Interface into firewall cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-a-VLAN-Interface-into-firewall-cluster/m-p/99320#M10380</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We're planning to add a VLAN Interface into the firewall cluster (R77.30) and the Smart console version is R80.30&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Have gone through SK57100 which says 'maintenance window' is required and it may cause an outage when fetching the topology.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While the article sk118518 says it can be done without fetching the topology and the plan is:-&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To create a VLAN interface on both the firewalls via Gaia portal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Smart console -&amp;gt; Create a new Interface with 'cluster'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Create the interface with VIP address and click on Modify -&amp;gt; Enter the gateway members interface IP addresses of both the firewalls&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Enable Anti-Spoofing&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Save and install the policy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;With this option, believe anti-spoofing isn't overridden for other interfaces or no topology/routing changes will be made.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this correct way to do or can you please suggest the best way to achieve this without any outage or failover.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 17:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-a-VLAN-Interface-into-firewall-cluster/m-p/99320#M10380</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2020-10-16T17:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a VLAN Interface into firewall cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-a-VLAN-Interface-into-firewall-cluster/m-p/99321#M10381</link>
      <description>&lt;P&gt;What you described should work totally ok. Wether to do manual spoofing or fetch topology automatically is a personal choice. We use automated option and never really had any problems. No interruptions or failovers during configuration. I just find manual prone to errors if you have high number of interfaces and routes.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 18:30:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-a-VLAN-Interface-into-firewall-cluster/m-p/99321#M10381</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-10-16T18:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Adding a VLAN Interface into firewall cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-a-VLAN-Interface-into-firewall-cluster/m-p/99355#M10382</link>
      <description>&lt;P&gt;Hi Kaspars,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;Hope by adding this, new interfaces will be reported when the "cphaprob -a if" issued.&lt;/P&gt;&lt;P&gt;Also, can you please suggest what rollback option should be followed to minimize the outage (if something goes wrong)? Just by reverting the installation history or by reverting the snapshot.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2020 14:33:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-a-VLAN-Interface-into-firewall-cluster/m-p/99355#M10382</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2020-10-17T14:33:24Z</dc:date>
    </item>
  </channel>
</rss>

