<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DHCP rant in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23762#M1830</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Files you modify outside of Gaia/WebUI may not be preserved on an upgrade.&lt;/P&gt;&lt;P&gt;What things were you adding to your dhcpd.conf?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 19 Jan 2018 23:32:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-01-19T23:32:23Z</dc:date>
    <item>
      <title>DHCP rant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23760#M1828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I upgraded some 5xxx appliances from R77.30 to R80.10 using CPUSE. I didn't read the upgrade instructions, like I did in the old days with IPSO. Partially because Check Point makes it very easy to upgrade with CPUSE, partially because I did not expect the thing to happen, that happened to my DHCP configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You see - as soon as you need any DHCP Option other than DNS, Router or Domain, you're forced to manually craft your own little dhcpd.conf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During the automated upgrade, this dhcpd.conf is overwritten and the original state is lost, ignoring the fact, that you have set this file to immutable (chattr +i) before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're in 2018. Free and open source firewalls such as pfSense have a GUI which allows the creation of custom DHCP options for more than 10 years now. But Check Point? Buy some crazy snake oil threat prevention thingy! New and shiny! Software Blades! Woooop! But a simple thing, such as custom DHCP options? Rocket science.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the rant. I had to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And no worries: I had a backup of the dhcpd.conf.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jan 2018 07:35:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23760#M1828</guid>
      <dc:creator>Viktor_Steinman</dc:creator>
      <dc:date>2018-01-18T07:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP rant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23761#M1829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hahaha, you made me laugh but point is valid 100%! &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/grin.png" /&gt;&amp;nbsp;Can't agree more&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jan 2018 08:12:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23761#M1829</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-01-18T08:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP rant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23762#M1830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Files you modify outside of Gaia/WebUI may not be preserved on an upgrade.&lt;/P&gt;&lt;P&gt;What things were you adding to your dhcpd.conf?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jan 2018 23:32:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23762#M1830</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-19T23:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP rant</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23763#M1831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Files that are set to +i (immutable) should not be overwritten or at least automatically backed up by an upgrade process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Options we use include 186 (WYSE WDM Server), 043, 066 120, 160 (all needed for Skype for Business with Hardware phones by Polycom).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jan 2018 08:32:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DHCP-rant/m-p/23763#M1831</guid>
      <dc:creator>Viktor_Steinman</dc:creator>
      <dc:date>2018-01-20T08:32:26Z</dc:date>
    </item>
  </channel>
</rss>

