<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Expand the office mode segment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171469#M31086</link>
    <description>&lt;P&gt;I will tell you what I did with couple of customers and never a problem. Dont bother changing default object for OM (though you can), just create new one, call it say "office-mode-network" and enable NAT (just default hide behind gateway option), give it say 172.16.10.0 and subnet 255.255.254.0 (thats /23, I do know that as bad as I am with subnetting LOL), make sure its configured in all the right places, push policy and vola, thats it : - )&lt;/P&gt;</description>
    <pubDate>Tue, 14 Feb 2023 17:45:36 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-02-14T17:45:36Z</dc:date>
    <item>
      <title>Expand the office mode segment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171466#M31083</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently have a 24 bit office mode segment, but I need to extend it, I just have to change the skin on the object and install right?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Or do I need to create a new segment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best practice for this change?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 17:40:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171466#M31083</guid>
      <dc:creator>Itzel_Gtz26</dc:creator>
      <dc:date>2023-02-14T17:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Expand the office mode segment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171468#M31085</link>
      <description>&lt;P&gt;Correct, just change the subnet mask in the same object and install policy.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 17:43:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171468#M31085</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2023-02-14T17:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Expand the office mode segment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171469#M31086</link>
      <description>&lt;P&gt;I will tell you what I did with couple of customers and never a problem. Dont bother changing default object for OM (though you can), just create new one, call it say "office-mode-network" and enable NAT (just default hide behind gateway option), give it say 172.16.10.0 and subnet 255.255.254.0 (thats /23, I do know that as bad as I am with subnetting LOL), make sure its configured in all the right places, push policy and vola, thats it : - )&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 17:45:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171469#M31086</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-14T17:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Expand the office mode segment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171484#M31088</link>
      <description>&lt;P&gt;So both configurations should work?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 18:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171484#M31088</guid>
      <dc:creator>Itzel_Gtz26</dc:creator>
      <dc:date>2023-02-14T18:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Expand the office mode segment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171485#M31089</link>
      <description>&lt;P&gt;Yup! What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;gave you and what I mentioned, both methods work 100%.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 18:54:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171485#M31089</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-14T18:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Expand the office mode segment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171487#M31090</link>
      <description>&lt;P&gt;Thank you both very much.&lt;/P&gt;&lt;P&gt;An additional question, when I make the change will my users who are connected be disconnected? or will it be transparent to them?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 19:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171487#M31090</guid>
      <dc:creator>Itzel_Gtz26</dc:creator>
      <dc:date>2023-02-14T19:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Expand the office mode segment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171489#M31091</link>
      <description>&lt;P&gt;EXCELLENT question. Answer is no, they will not be disconnected...so here, let me give you simple example, because I did this few times with customers and there were no issues. Say you have default OM subnet 172.16.10.0/24 and for argument sake, you decide to use 10.10.10.0/24 instead. If you change it and push policy, users will NOT be disconnected and they will keep having same OM mode (172.16.10.xx), but once they reconnect next time, they will get new OM mode subnet IP from 10.10.10.0/24 subnet. Just ensure new subnet is included in same places as existing one (config, rules, etc...).&lt;/P&gt;
&lt;P&gt;And no, they will NOT have to delete/re-create the site either, which is always a good thing, as most users hate doing that (well, at least from my experience : - )&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 19:12:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Expand-the-office-mode-segment/m-p/171489#M31091</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-14T19:12:20Z</dc:date>
    </item>
  </channel>
</rss>

