<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dependencies in FW Configuration in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283028#M106956</link>
    <description>&lt;P&gt;Hey Lesley&lt;BR /&gt;&lt;STRONG&gt;Just for the record&lt;/STRONG&gt;:&lt;BR /&gt;This logic applies in the same way in &lt;STRONG&gt;VS environments&lt;/STRONG&gt;, doesn’t it?&lt;BR /&gt;Let’s imagine I have four VS's on my VSX, and on one of them I’m using BGP whilst on another I’m using OSPF, and I make changes to the configuration via the CLI…&lt;BR /&gt;&lt;STRONG&gt;Is it enough just to run ‘save config’ on the configuration I’ve made, right?&lt;/STRONG&gt;&lt;BR /&gt;There’s no need to send policies for installation&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2026 17:19:04 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2026-09-29T17:19:04Z</dc:date>
    <item>
      <title>Dependencies in FW Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283010#M106943</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;Whenever a change is made at the routing level (dynamic or static) on a firewall managed by an SMS or a CMA from an MDS… or, for example, when modifying NTP/SNMP settings…&lt;BR /&gt;&lt;STRONG&gt;Is it ‘mandatory’ to implement policies?&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Or is the change simply made on the firewall and the implementation ignored?&lt;/STRONG&gt;&lt;BR /&gt;Thank you for your clarification.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 14:59:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283010#M106943</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2026-09-29T14:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Dependencies in FW Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283013#M106946</link>
      <description>&lt;P&gt;For static routing changes in VSX yes.&lt;/P&gt;
&lt;P&gt;Other changes typically only require policy to be pushed if the policy needs to be updated to take the settings change into account to allow the traffic to pass including things like anti-spoofing etc.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 15:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283013#M106946</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-09-29T15:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dependencies in FW Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283014#M106947</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;In a ‘traditional environment’ without VSX, if you need to work with BGP,&lt;BR /&gt;I plan to carry out the configuration via my firewall’s CLI, but once I’ve finished doing that, do I need to install policies from the MDS?&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 16:06:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283014#M106947</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2026-09-29T16:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: Dependencies in FW Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283016#M106948</link>
      <description>&lt;P&gt;If you change BGP routing via local GAIA clish no policy push is needed from MGMT.&lt;/P&gt;
&lt;P&gt;If you change the NTP servers in GAIA no push is needed.&lt;/P&gt;
&lt;P&gt;BUT if there is a rule that the firewall uses to reach the NTP server it needs to be changed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Source: Firewall , destination: NTP server old port 123&lt;/P&gt;
&lt;P&gt;A policy push is to change this rule policy. It does not tell the firewall to change the GAIA config or something. All changes in GAIA config are active after you do save config, no push needed&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 16:21:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283016#M106948</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-09-29T16:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Dependencies in FW Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283028#M106956</link>
      <description>&lt;P&gt;Hey Lesley&lt;BR /&gt;&lt;STRONG&gt;Just for the record&lt;/STRONG&gt;:&lt;BR /&gt;This logic applies in the same way in &lt;STRONG&gt;VS environments&lt;/STRONG&gt;, doesn’t it?&lt;BR /&gt;Let’s imagine I have four VS's on my VSX, and on one of them I’m using BGP whilst on another I’m using OSPF, and I make changes to the configuration via the CLI…&lt;BR /&gt;&lt;STRONG&gt;Is it enough just to run ‘save config’ on the configuration I’ve made, right?&lt;/STRONG&gt;&lt;BR /&gt;There’s no need to send policies for installation&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 17:19:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283028#M106956</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2026-09-29T17:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dependencies in FW Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283029#M106957</link>
      <description>&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_vss variable"&gt;Virtual Systems&lt;/SPAN&gt; support:&lt;/P&gt;
&lt;P&gt;OSPF&lt;/P&gt;
&lt;P&gt;RIP&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;BGP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;PIM&lt;/P&gt;
&lt;P&gt;Static routes, you change via Smart Console. But if you want to change SNMP / NTP or other gaia config it is local gaia CLISH and no push needed. Indeed save config&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 17:29:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283029#M106957</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-09-29T17:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Dependencies in FW Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283030#M106958</link>
      <description>&lt;P&gt;Generally, yes. With VSX, some things must be done through the CLI (dynamic routing, bonding), while others must be done through SmartConsole (static routes, interface IP/mask changes, VLANs). Certain interface changes need a policy push simply because antispoofing is part of the policy.&lt;/P&gt;
&lt;P&gt;Routing changes (whether static or dynamic) never need a policy push to take effect. They may send traffic through different paths, which could cause it to no longer match existing rules (for example, if you change the route to a destination, it might be in a different zone), and it can take a policy push to fix that, but that's technically not part of the routing change.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2026 17:30:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283030#M106958</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-09-29T17:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Dependencies in FW Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283042#M106963</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk39960" target="_blank"&gt;sk39960 - How to allow Dynamic Routing protocols traffic (OSPF, BGP, PIM, RIP, IGRP) through Check Point Security Gateway&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2026 00:21:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Dependencies-in-FW-Configuration/m-p/283042#M106963</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-09-30T00:21:18Z</dc:date>
    </item>
  </channel>
</rss>

