<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are the implications of setting an interface as &amp;quot;management interface&amp;quot; ? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128347#M18692</link>
    <description>&lt;P&gt;Always kind of wondered how the gateway decided whether to use the SMS's NAT address or real address for sending logs, thanks for this.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Aug 2021 11:43:17 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-08-30T11:43:17Z</dc:date>
    <item>
      <title>What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/119420#M16884</link>
      <description>&lt;P&gt;Hey Guys,&lt;BR /&gt;&lt;BR /&gt;what are the exact implications of setting an interface as "management interface" ?&amp;nbsp; For example, are the number of queues for the management interface somehow limited?&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 09:24:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/119420#M16884</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-05-26T09:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/119501#M16896</link>
      <description>&lt;P&gt;There are a couple of aspects to what the management interface definition actually does, let's cover the Multi-Queue side first.&lt;/P&gt;
&lt;P&gt;In regards to Multi-Queue and the management interface, it was impossible to enable Multi-Queue on the defined management interface in the Gaia 3.10 FCS (First Customer Ship) edition of R80.30 and the FCS of R80.40 (which uses Gaia 3.10).&amp;nbsp; The explanation I got from R&amp;amp;D is that they wanted to ensure management access to the box even if some kind of Multi-Queue failure occurred, as MQ is enabled by default on all interfaces that support it under Gaia 3.10 except the management interface.&lt;/P&gt;
&lt;P&gt;This restriction was lifted in Gaia 3.10 R80.30 Jumbo HFA Take 219+ and R80.40 Jumbo HFA Take 78+.&amp;nbsp; In R81+ FCS MQ is enabled by default on all interfaces that support it.&amp;nbsp; I'm not exactly sure what happens to the MQ status of the management interface if you started with an older Jumbo HFA or FCS and cross the boundary into where MQ is supported on the management interface, I believe it does get automatically enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be warned however that it is not a good idea to manually mess around with MQ's state on the various interfaces under Gaia 3.10 as you can end up with various issues such as&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168498&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk168498: High rate of input discards after reboot when Multi-Queue is configured&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167200&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk167200: &lt;STRONG&gt;Multi-queue&lt;/STRONG&gt; state is "off" when changing the &lt;STRONG&gt;management&lt;/STRONG&gt; &lt;STRONG&gt;interface.&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The other aspect to the management interface definition independent of Multi-Queue is what the definition means to the Gaia OS:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;The defined management interface will have it's IP mapped to the firewall's hostname in the /etc/hosts file generated at Gaia boot.&amp;nbsp; Elements of the Gaia OS (not Check Point Product code) that need to determine what the main IP is they should use for various purposes will look here.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Trying to change the IP address of the management interface in the Gaia web interface will throw a warning cautioning that completing this change may cut off your administrative access.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That's about it as far as I know, if I missed any other impacts I'd love to hear about it.&amp;nbsp; The management interface definition does not impact or restrict your ability to "manage" the Gaia OS with SSH or HTTPS on any interface, as long as the firewall policy and the Gaia "Authorized Hosts" definitions (clish command &lt;STRONG&gt;add allowed-hosts&lt;/STRONG&gt;) permit it.&amp;nbsp; As far as which interface to choose as the management interface, I did provide some guidance on this in my Gaia 3.10 Immersion video course; here are the relevant pages:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gaia 3.10 Immersion Video Course Page 64" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11846i18DF5E599F64F50A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Gaia310_Mgmt1.png" alt="Gaia 3.10 Immersion Video Course Page 64" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Gaia 3.10 Immersion Video Course Page 64&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gaia 3.10 Immersion Video Course Page 65" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11847i4236841C7A208007/image-size/large?v=v2&amp;amp;px=999" role="button" title="Gaia310_Mgmt2.png" alt="Gaia 3.10 Immersion Video Course Page 65" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Gaia 3.10 Immersion Video Course Page 65&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 18:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/119501#M16896</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-26T18:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128345#M18691</link>
      <description>&lt;P&gt;This setting might also impact if the gateway tries to connect to the SMS via NAT IP or not, see &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk171665&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk171665&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Quote: "The Security Gateway sends logs to the Security Management NATed IP because the Management's server private IP is found on the "Management" interface of the NAT-enforcing Gateway, and only hosts with IP's from the network behind the "Management" interface are allowed to connect to the Management server private IP.&lt;/P&gt;
&lt;P&gt;Since the Gateway IP is not in range of the "Management" interface, the Gateway connects to the Management server via the NATed IP."&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 11:32:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128345#M18691</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-08-30T11:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128347#M18692</link>
      <description>&lt;P&gt;Always kind of wondered how the gateway decided whether to use the SMS's NAT address or real address for sending logs, thanks for this.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 11:43:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128347#M18692</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-30T11:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128357#M18694</link>
      <description>&lt;P&gt;I am having trouble visualizing this. From what I am reading, it seems that:&lt;/P&gt;
&lt;P&gt;1. both management interfaces, the one of SMS and the one of the gateway&amp;nbsp; are on the same network.&lt;/P&gt;
&lt;P&gt;2. SMS object defined with public IP in its NAT properties.&lt;/P&gt;
&lt;P&gt;3. the last sentence: "Since the Gateway IP is not in range of the "Management" interface, the Gateway connects to the Management server via the NATed IP." does not make sense to me, because of the preceding statement "Management's server private IP is found on the "Management" interface of the NAT-enforcing Gateway".&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 13:16:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128357#M18694</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-08-30T13:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128433#M18713</link>
      <description>&lt;P&gt;Hopefully someone from Checkpoint can clarify, I'm not sure if this info is still relevant myself.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 09:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128433#M18713</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-08-31T09:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128466#M18715</link>
      <description>&lt;P&gt;I also would like for someone from Check Point to clarify.&lt;/P&gt;
&lt;P&gt;The only scenario where that description may be applicable, (stretching our imagination), is if there is an L3 routing hop between SMS and the Management interface of the gateway performing NAT for SMS.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 13:52:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128466#M18715</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-08-31T13:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128495#M18721</link>
      <description>&lt;P&gt;I'm pretty sure the IP that will be used here is the main IP of the management object in SmartConsole.&lt;BR /&gt;Which...may or may not be the interface marked as management.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 00:46:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128495#M18721</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-01T00:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: What are the implications of setting an interface as "management interface" ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128497#M18722</link>
      <description>&lt;P&gt;Fair point, but even in this case, I do not see why the logs would be forwarded to a different interface, unless there is a routing issue.&lt;/P&gt;
&lt;P&gt;I've used some fancy routing setup on virtual SMS long time ago, advertising its local loop address (used as its main IP as well as management interface) through different virtual interfaces via OSPF, but did not see any issues described in sk171665.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 02:05:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-are-the-implications-of-setting-an-interface-as-quot/m-p/128497#M18722</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-09-01T02:05:04Z</dc:date>
    </item>
  </channel>
</rss>

