<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deploying new VLANs in production in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183562#M33695</link>
    <description>&lt;P&gt;Thank you for your response.&lt;/P&gt;
&lt;P&gt;For this type of configuration that I have exposed.&lt;/P&gt;
&lt;P&gt;Do you think it is necessary, to break the ClusterXL????&lt;/P&gt;
&lt;P&gt;In your experience, is it feasible to leave the interface as it is now configured, with one IP, and add the new segment as a VLAN?&lt;BR /&gt;Or is it better to "leave the interface blank" and configure the 2 segments as distinct VLANs? ????&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2023 22:02:28 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-06-07T22:02:28Z</dc:date>
    <item>
      <title>Deploying new VLANs in production</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183550#M33693</link>
      <description>&lt;P&gt;Hello, world.&lt;/P&gt;
&lt;P&gt;A query, I currently have a ClusterXL which has configured in its interface Eth2 of each Firewall:&lt;/P&gt;
&lt;P&gt;FW 01 -&amp;gt; 10.20.20.1&lt;BR /&gt;FW 02 -&amp;gt; 10.20.20.2&lt;BR /&gt;VIP -&amp;gt; 10.20.20.254&lt;/P&gt;
&lt;P&gt;What we need, is to put a new segment in that same interface, (10.100.100.0/22)&lt;/P&gt;
&lt;P&gt;In this scenario, it is ideal to leave configured the segment that currently already has the interface, and add the new segment as a VLAN?&lt;/P&gt;
&lt;P&gt;Or is it necessary to leave the interface blank by default and configure the 2 segments as different VLANs?&lt;/P&gt;
&lt;P&gt;What is the best practice in your experience?&lt;/P&gt;
&lt;P&gt;This type of configuration, it is advisable to always start it in the passive member, and then in the active, and all this, in a working window, right ????&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 19:54:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183550#M33693</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-07T19:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying new VLANs in production</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183559#M33694</link>
      <description>&lt;P&gt;In general, changes of this nature should be done on the passive member first, OS level changes first, then update the configuration in SmartConsole.&lt;BR /&gt;And yes, this will definitely need to be done in a maintenance window.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 21:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183559#M33694</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-07T21:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying new VLANs in production</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183562#M33695</link>
      <description>&lt;P&gt;Thank you for your response.&lt;/P&gt;
&lt;P&gt;For this type of configuration that I have exposed.&lt;/P&gt;
&lt;P&gt;Do you think it is necessary, to break the ClusterXL????&lt;/P&gt;
&lt;P&gt;In your experience, is it feasible to leave the interface as it is now configured, with one IP, and add the new segment as a VLAN?&lt;BR /&gt;Or is it better to "leave the interface blank" and configure the 2 segments as distinct VLANs? ????&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 22:02:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183562#M33695</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-07T22:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying new VLANs in production</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183563#M33696</link>
      <description>&lt;P&gt;Note that ClusterXL requires the interface configuration to be the same on both cluster members.&lt;BR /&gt;Generally interfaces with VLANs should only have VLANs configured on it (i.e. no IP on the physical interface).&lt;BR /&gt;That implies "leave the interface blank" as you put it.&lt;BR /&gt;Not sure if that's a hard requirement or just best practice.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 22:10:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Deploying-new-VLANs-in-production/m-p/183563#M33696</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-07T22:10:02Z</dc:date>
    </item>
  </channel>
</rss>

