<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic IP on WAN interface. Managed on its local static… in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119399#M16882</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone add some clarity over the proposed options and best practice over this scenario please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 interfaces - WAN and LAN.&lt;/P&gt;&lt;P&gt;WAN is DHCP. LAN is Static.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The gateway is managed via its LAN address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT is ticked to hide all internal networks behind this gateway.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When that WAN IP changes, how does the topology in smart dashboard update? Also, what would happen to the NAT? Would it fail?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note - I have NOT ticked DAIP gateway as the Main IP of the gateway object is the LAN address which is indeed static.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 26 May 2021 07:06:48 GMT</pubDate>
    <dc:creator>JackPrendergast</dc:creator>
    <dc:date>2021-05-26T07:06:48Z</dc:date>
    <item>
      <title>Dynamic IP on WAN interface. Managed on its local static…</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119399#M16882</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone add some clarity over the proposed options and best practice over this scenario please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 interfaces - WAN and LAN.&lt;/P&gt;&lt;P&gt;WAN is DHCP. LAN is Static.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The gateway is managed via its LAN address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT is ticked to hide all internal networks behind this gateway.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When that WAN IP changes, how does the topology in smart dashboard update? Also, what would happen to the NAT? Would it fail?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note - I have NOT ticked DAIP gateway as the Main IP of the gateway object is the LAN address which is indeed static.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 07:06:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119399#M16882</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2021-05-26T07:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic IP on WAN interface. Managed on its local static…</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119402#M16883</link>
      <description>&lt;P&gt;How did you define the topology ? I would assume that your LAN IP is the external IP as all internal IPS are NATed behind it, and the WAN IP an internal interface. As you can not tick DAIP for your WAN IF, the IP change would never propagate anywhere, i think. So what in fact does happen in your scenario ?&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 07:14:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119402#M16883</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-05-26T07:14:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic IP on WAN interface. Managed on its local static…</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119428#M16885</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Topology is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Modem - CP - LAN Router - Users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP has eth1 attached to Modem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;eth1 has obtain ip automatically, with custom dhcp options configured in dhclient and recieves public IP from ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DHCP for the LAN is done on the CP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local traffic via the LAN router routes to the CP and CP hides local traffic behind the public IP assigned to eth1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;eth2 attached to LAN router is static. Fixed 192.168.0.0/24 address&lt;/P&gt;&lt;P&gt;eth1, attached to ISP modem is dynamic (ISP wont give fixed IP)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gateway is managed locally via eth2. DAIP is NOT enabled as gateway is managed on LAN via static IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, the question is, when the public IP attached to eth1 changes, how do these changes apply to the rest of the process?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can the topology in SC update automatically? Otherwise, traffic will stop and fail. Traffic will try be hide nat behind the old public IP as topology hasnt updated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There must be a way for this?&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 10:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119428#M16885</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2021-05-26T10:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic IP on WAN interface. Managed on its local static…</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119433#M16886</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-05-26 at 11.17.21.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11825i15ACF762A30A4ECA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-05-26 at 11.17.21.png" alt="Screenshot 2021-05-26 at 11.17.21.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-05-26 at 11.17.13.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11826iBE2C2C2E7173E564/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2021-05-26 at 11.17.13.png" alt="Screenshot 2021-05-26 at 11.17.13.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 10:18:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119433#M16886</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2021-05-26T10:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic IP on WAN interface. Managed on its local static…</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119472#M16890</link>
      <description>&lt;P&gt;Marking the gateway as DAIP is really only necessary if you manage the gateway via the interface that is dynamic.&lt;BR /&gt;Marking the gateway DAIP imposes some significant limitations:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167473" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167473&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Without checking that box, if WAN address actually changes, it would require a policy install (with config changes) to restore all functionality, most likely.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 14:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-IP-on-WAN-interface-Managed-on-its-local-static/m-p/119472#M16890</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-26T14:59:03Z</dc:date>
    </item>
  </channel>
</rss>

