<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterXL Interface Deletion Question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140544#M21588</link>
    <description>&lt;P&gt;Sure. Rules are totally separate from the interface config. After all, firewalls can have routers behind them.&lt;/P&gt;
&lt;P&gt;In general, you should remove the interface from the topology table in the firewall object on the management server, push policy,&amp;nbsp;&lt;EM&gt;then&lt;/EM&gt; remove the interface config on the firewalls themselves. That way, the firewall software stops looking for the interface before the interface actually goes away. If you remove the interface on the CLI first, you could get failovers and other weird behavior because the firewall software may still be trying to use it.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Feb 2022 18:17:28 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2022-02-04T18:17:28Z</dc:date>
    <item>
      <title>ClusterXL Interface Deletion Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140538#M21587</link>
      <description>&lt;P&gt;We have a ClusterXL pair of two 7000's. I'm about to start deleting ClusterXL interfaces from the pair. So I'll be removing them from the local gateways and updating SmartCentre. I've never done it before. Can an Interface be deleted from inside SmartCentre if there are still objects with IP addresses that fall inside the subnet of the interface being deleted? Can I delete the interface without having to delete all the objects and rules first in SmartCentre?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 16:30:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140538#M21587</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-04T16:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Interface Deletion Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140544#M21588</link>
      <description>&lt;P&gt;Sure. Rules are totally separate from the interface config. After all, firewalls can have routers behind them.&lt;/P&gt;
&lt;P&gt;In general, you should remove the interface from the topology table in the firewall object on the management server, push policy,&amp;nbsp;&lt;EM&gt;then&lt;/EM&gt; remove the interface config on the firewalls themselves. That way, the firewall software stops looking for the interface before the interface actually goes away. If you remove the interface on the CLI first, you could get failovers and other weird behavior because the firewall software may still be trying to use it.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 18:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140544#M21588</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-02-04T18:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Interface Deletion Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140779#M21621</link>
      <description>&lt;P&gt;Hi Bob, thanks for taking the time to reply. I didn't know this. My basic plan was to proceed like this....&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Brief action plan for&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;I&gt;removing&lt;/I&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;an interface from cluster topology (R80.10 and above)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Remove the Virtual IP address and Change the Interface to 'Private' in SmartConsole and push policy.&lt;/LI&gt;&lt;LI&gt;check &lt;STRONG&gt;chaprob -a if &lt;/STRONG&gt;for the change on both firewall gateway members.&lt;/LI&gt;&lt;LI&gt;Disable clustering on standby gateway.&lt;/LI&gt;&lt;LI&gt;delete the interface from standby gateway.&lt;/LI&gt;&lt;LI&gt;delete the interface from active gateway.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;Delete the interface&amp;nbsp; from SmartConsole and push policy.&lt;/LI&gt;&lt;LI&gt;Restart clustering on standby gateway.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is taken from sk57100. Do you think this will be okay if I proceed like this, or do you think I should remove the VIP and delete the interface entirely and pushing policy before heading over to the actual gateways to remove the interfaces from there?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 14:23:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140779#M21621</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-07T14:23:24Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Interface Deletion Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140788#M21623</link>
      <description>&lt;P&gt;I would delete it entirely from the GUI first, push policy, then delete it on the CLI.&lt;/P&gt;
&lt;P&gt;Setting the interface to Private&amp;nbsp;&lt;EM&gt;should be&lt;/EM&gt; enough, but seems like an extra step and an extra policy push for no good reason.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 16:25:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140788#M21623</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-02-07T16:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL Interface Deletion Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140831#M21631</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Bob, thanks for taking the time to reply once more. Interesting. Makes me wonder why they didn't simplify it to doing it the way you are suggesting. I'm sure there must be a good reason for for the extra step.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 07:14:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-Interface-Deletion-Question/m-p/140831#M21631</guid>
      <dc:creator>Martin_S_1</dc:creator>
      <dc:date>2022-02-08T07:14:30Z</dc:date>
    </item>
  </channel>
</rss>

