<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change External Interface from 1G to 10G in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137502#M20835</link>
    <description>&lt;P&gt;Related to this, you may want to consider changing the external interface to a bond. Even if you don't add more than one interface, bonds abstract your logical interfaces (with the IP addresses) away from the physical hardware underpinning them. They make this kind of move much easier.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Dec 2021 09:41:22 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2021-12-31T09:41:22Z</dc:date>
    <item>
      <title>Change External Interface from 1G to 10G</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137496#M20832</link>
      <description>&lt;P&gt;Hello Mates,&lt;/P&gt;&lt;P&gt;I have a challenging question to all of you and hope you can help with advise on the Proper plan.&lt;/P&gt;&lt;P&gt;My case is that, I have three gateways cluster, which I need to change their external interface from one physical interface to another, currently on 1 G, I need to move it to 10G. All the IP addresses on the Interfaces on all three gateways should be the same just I have to move the IPs on another physical interface. The issue is that my Management Server part of the MDS environment is located in another location and the only connectivity to the MDS ( other location) is via VPN from the location which I am making the pre-configuration. As this is external interface ( Public IPs/peer for the that site)once I attempt to shutdown and remove IPs from current external interface this will disconnect all the VPNs as the VIP of that external interface is peer for each VPN tunnel, so I will kick down my connection to the MDS/ CMA ( Management).&lt;/P&gt;&lt;P&gt;So my question is, is there easy way on the Gateway level that I can simply change the IP via command line/ interface file, without the need to " get interfaces with topology" on the Management. If not what is the best plan that you can suggest.&lt;/P&gt;&lt;P&gt;The eventual plan which comes to my mind is:&lt;/P&gt;&lt;P&gt;1. Configure new Interface with the same IPs as other with state down. ( if Gaia allow this as same IPs with same Netmask, will not be allowed to configure as far as I know)&lt;/P&gt;&lt;P&gt;2. Shutdown the old interfaces * this way I will lose the VIP on the external and my VPN connection will be down...&lt;/P&gt;&lt;P&gt;3. Set new Interfaces UP, but without Management Server( CMA/MDS) I will not be possible to point via Smart Console which is the VIP IP ( same OLD IP- re-used)&amp;nbsp; so to push policy and finish the pre-configuration....&lt;/P&gt;&lt;P&gt;This is all that comes to my mind, but looks like I am not on the right way, so I am looking for your kind advise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please share you suggestion and better approach for that case?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 06:56:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137496#M20832</guid>
      <dc:creator>Darina2019</dc:creator>
      <dc:date>2021-12-31T06:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Change External Interface from 1G to 10G</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137499#M20834</link>
      <description>&lt;P&gt;You need out of band access to your MGMT servers to complete the operation. There is no any way around it here.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 08:35:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137499#M20834</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-31T08:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Change External Interface from 1G to 10G</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137502#M20835</link>
      <description>&lt;P&gt;Related to this, you may want to consider changing the external interface to a bond. Even if you don't add more than one interface, bonds abstract your logical interfaces (with the IP addresses) away from the physical hardware underpinning them. They make this kind of move much easier.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 09:41:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137502#M20835</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-12-31T09:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: Change External Interface from 1G to 10G</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137518#M20843</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt; Thats a good idea but the thing is hes trying do change from 1G to 10G port and not sure if you can bond those interfaces with different physical duplexing and i assumed on 10G hes going to be using SFP instead of ethernet. So i would go as &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp; said confirm and out of band connection in order to work with the MGMT. &lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 15:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137518#M20843</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-31T15:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Change External Interface from 1G to 10G</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137522#M20844</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;is absolutely right...I dont see any other way myself either.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 17:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137522#M20844</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-31T17:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Change External Interface from 1G to 10G</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137523#M20845</link>
      <description>&lt;P&gt;You can. I've done it before to deal with this exact scenario.&lt;/P&gt;
&lt;P&gt;The firewall application cares very deeply about the names of the interfaces you give it. This is why you have to update the topology table when you move an IP from a 1g to a 10g interface. Same thing if you move it from a 1g interface to a bond.&lt;/P&gt;
&lt;P&gt;However, once the firewall application knows about, e.g., bond0, it doesn't care which physical interfaces make up bond0, or even how the bond is set up. I recommend using bonds for everything possible for this reason.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 18:09:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137523#M20845</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-12-31T18:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Change External Interface from 1G to 10G</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137525#M20846</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;is correct as well. In some cases, you are right, might not be optimal, but it works for sure. I had done it on Fortinet and CP before and never had an issue. You can mix 1 G and 10 G interfaces in a bond and works real well.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 18:17:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137525#M20846</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-31T18:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Change External Interface from 1G to 10G</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137527#M20847</link>
      <description>&lt;P&gt;If you have an Open Server, there is an easy way.&lt;BR /&gt;&lt;BR /&gt;Replace the PCI BUS IDs between 10 GBit and 1 GBit interface in the file "/etc/udev/rules.d/00-OS-XX.rules".&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="udef_change.jpg" style="width: 327px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14737i8172CC3916A9AF35/image-size/large?v=v2&amp;amp;px=999" role="button" title="udef_change.jpg" alt="udef_change.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;For example, if eth0 is a 1G interface and eth3 is a 10G interface, you only need to change the interface PCI bus ID.&lt;BR /&gt;&lt;BR /&gt;After that you just have to reboot the gateway.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;If it is an appliance, this hack will not work.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Dec 2021 19:46:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-External-Interface-from-1G-to-10G/m-p/137527#M20847</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-12-31T19:46:31Z</dc:date>
    </item>
  </channel>
</rss>

