<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterXL management changes in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183045#M33579</link>
    <description>&lt;P&gt;For this type of activity (Change the management IP of each GW, of ClusterXL), there is no need to "break" the ClusterXL during the "Maintenance Window", right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your time, and sorry for the "silly" doubts. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2023 12:42:20 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-06-02T12:42:20Z</dc:date>
    <item>
      <title>ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/182996#M33565</link>
      <description>&lt;P&gt;Hello, team.&lt;/P&gt;
&lt;P&gt;I currently have a couple of ClusterXLs, hooked up to an SMS. &lt;BR /&gt;All in version R81.10&lt;/P&gt;
&lt;P&gt;I understand that the IPs that appear in the SmartConsole, are the management IPs, is that correct?&lt;/P&gt;
&lt;P&gt;By decision and "reordering" of the client, the "management" IPs will be changed to those of the gateways.&lt;/P&gt;
&lt;P&gt;What seems strange to me, is that for so long, they have been working with a VIRTUAL IP for each Cluster, which is a PUBLIC IP, and for the gateways as such, they have been working with private IPs.&lt;BR /&gt;I don't understand why.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CL.png" style="width: 864px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21232i65BDFFBAAB9314EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="CL.png" alt="CL.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;To be able to do the process of changing the IPs of each cluster, it must be considered a "service interruption"?&lt;BR /&gt;Is it recommended to have a working window?&lt;/P&gt;
&lt;P&gt;What is the order to change the IPs in the gateways?&lt;BR /&gt;Should the passive one be started first, then the active one? &lt;BR /&gt;At the end change it in the same SmartConsole?&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 22:16:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/182996#M33565</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-01T22:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/182999#M33566</link>
      <description>&lt;P&gt;The "management" IP is the IP that's listed in the General tab of the relevant gateway object (also called the Main IP).&lt;BR /&gt;A Cluster IP can be on a different subnet from the gateway's configured interfaces, which is a useful feature:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk32073" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk32073&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Generally, changing IP addresses of a gateway or cluster should be done in a maintenance window.&lt;BR /&gt;Make the OS level changes first, then make the changes in SmartConsole.&lt;BR /&gt;Similar to:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk62024" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk62024&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 22:30:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/182999#M33566</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-01T22:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183010#M33569</link>
      <description>&lt;P&gt;You got perfect answer from&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, thats exactly how you would do the order, as per 2nd sk he provided.&lt;/P&gt;
&lt;P&gt;Good luck bro!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 01:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183010#M33569</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T01:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183037#M33576</link>
      <description>&lt;P&gt;Sorry,&lt;/P&gt;
&lt;P&gt;By "start on each operating system", they mean start on each ClusterXL gateway, correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the order matter?&lt;/P&gt;
&lt;P&gt;Or is it better to start by changing the management IPs, always by the passive member, and then the active one?&lt;/P&gt;
&lt;P&gt;Or is it indifferent?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 12:11:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183037#M33576</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-02T12:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183039#M33577</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Im fairly sure what it implies is to do changes on OS level first (meaning Gaia clish or web UI) and then app level (ie smart console object topology). I always do everything first on standby, then master and that works well.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 12:23:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183039#M33577</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T12:23:12Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183045#M33579</link>
      <description>&lt;P&gt;For this type of activity (Change the management IP of each GW, of ClusterXL), there is no need to "break" the ClusterXL during the "Maintenance Window", right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your time, and sorry for the "silly" doubts. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 12:42:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183045#M33579</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-02T12:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183046#M33580</link>
      <description>&lt;P&gt;No, you dont need to break the cluster, but to be 100% safe, maybe better to do off hours.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 12:43:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183046#M33580</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T12:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183047#M33581</link>
      <description>&lt;P&gt;Never be sorry about asking any questions mate...regardless of some people thinking question may sound silly or stupid, if answer will save you headache down the road, then everyone wins.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 12:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183047#M33581</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T12:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183060#M33587</link>
      <description>&lt;P&gt;It is better to always keep the criterion of doing it in a "working window", but knowing that it is not necessary to break the ClusterXL.&lt;BR /&gt;Just as a "precautionary" measure, right?&lt;/P&gt;
&lt;P&gt;Thanks, bro.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:50:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183060#M33587</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-02T13:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL management changes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183061#M33588</link>
      <description>&lt;P&gt;Thats my mentality as well, correct.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:50:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-management-changes/m-p/183061#M33588</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-02T13:50:54Z</dc:date>
    </item>
  </channel>
</rss>

