<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: changing IP address on security gateway and SIC in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116322#M16411</link>
    <description>&lt;P&gt;SIC does indeed operate with certificates and cares not about the IP addresses involved, BUT there is an implied rule on the firewall that allows only the known IP address of the SMS to talk to the known IP addresses of the firewall for management traffic such as SIC and policy installs.&amp;nbsp; If you change any elements of this you may run afoul of this implied rule, and be forced to perform a &lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; on the firewall for SIC to start working after an IP change.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To avoid this, create an temporary explicit rule at the top of your rulebase ahead of time and install it to the gateway *prior* to the WAN IP change:&lt;/P&gt;
&lt;P&gt;Src: SMS (and/or SMS NAT address)&lt;/P&gt;
&lt;P&gt;Dst: Any&lt;/P&gt;
&lt;P&gt;Service: Any&lt;/P&gt;
&lt;P&gt;Action: Accept&lt;/P&gt;
&lt;P&gt;Once the WAN IP change is made and you successfully install policy to the gateway under the new config, the implied rule will be updated (assuming you correctly changed the firewall's WAN address on the firewall/cluster object) and this temporary explicit rule can be removed.&lt;/P&gt;</description>
    <pubDate>Mon, 19 Apr 2021 14:49:03 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-04-19T14:49:03Z</dc:date>
    <item>
      <title>changing IP address on security gateway and SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116306#M16402</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to set up CHeckpoint GW as VPN edge for remote location and I am wondering if I set up community vpn between gateway and SMS and on the day of shipping the Gateway I will change IP address of WAN GW interface do I have to reestablish SIC or everything will be working out of the box ?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 09:37:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116306#M16402</guid>
      <dc:creator>marcinw</dc:creator>
      <dc:date>2021-04-19T09:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: changing IP address on security gateway and SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116308#M16403</link>
      <description>&lt;P&gt;SIC operates on certificates, so you should be fine.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 10:33:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116308#M16403</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2021-04-19T10:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: changing IP address on security gateway and SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116315#M16405</link>
      <description>&lt;P&gt;While this is true, the mention of VPNs concerns me a little. Traffic between the management server and the firewall cannot go over a VPN. The firewall needs to talk to the management server to bring a VPN up, and if the VPN needs to be up to talk to the management, it won't be able to.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 13:42:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116315#M16405</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-19T13:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: changing IP address on security gateway and SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116317#M16406</link>
      <description>&lt;P&gt;You will have to change the GW IP in Dashboard, of course...&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 13:47:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116317#M16406</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-04-19T13:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: changing IP address on security gateway and SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116318#M16407</link>
      <description>&lt;P&gt;With VPN you have traffic between two GWs, not the SMS - so if VPN Domain is defined correctly, it will work.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 13:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116318#M16407</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-04-19T13:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: changing IP address on security gateway and SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116321#M16410</link>
      <description>&lt;P&gt;Except the firewall has to fetch the CRL from the management. If that fails, the VPN won't come up. Thus, the remote firewall must be able to talk to the management server without the VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 14:25:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116321#M16410</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-19T14:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: changing IP address on security gateway and SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116322#M16411</link>
      <description>&lt;P&gt;SIC does indeed operate with certificates and cares not about the IP addresses involved, BUT there is an implied rule on the firewall that allows only the known IP address of the SMS to talk to the known IP addresses of the firewall for management traffic such as SIC and policy installs.&amp;nbsp; If you change any elements of this you may run afoul of this implied rule, and be forced to perform a &lt;STRONG&gt;fw unloadlocal&lt;/STRONG&gt; on the firewall for SIC to start working after an IP change.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To avoid this, create an temporary explicit rule at the top of your rulebase ahead of time and install it to the gateway *prior* to the WAN IP change:&lt;/P&gt;
&lt;P&gt;Src: SMS (and/or SMS NAT address)&lt;/P&gt;
&lt;P&gt;Dst: Any&lt;/P&gt;
&lt;P&gt;Service: Any&lt;/P&gt;
&lt;P&gt;Action: Accept&lt;/P&gt;
&lt;P&gt;Once the WAN IP change is made and you successfully install policy to the gateway under the new config, the implied rule will be updated (assuming you correctly changed the firewall's WAN address on the firewall/cluster object) and this temporary explicit rule can be removed.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Apr 2021 14:49:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/116322#M16411</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-04-19T14:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: changing IP address on security gateway and SIC</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/228557#M43958</link>
      <description>&lt;P&gt;I can confirm you're 100% correct here, this is exactly what happens, because it happened to me&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 08:37:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/changing-IP-address-on-security-gateway-and-SIC/m-p/228557#M43958</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2024-10-01T08:37:03Z</dc:date>
    </item>
  </channel>
</rss>

