<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic quick question about bootp in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48676#M3605</link>
    <description>&lt;P&gt;hi chaps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;quick question:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when you do bootp, you change your "relay-to" IP address and ...&lt;/P&gt;
&lt;P&gt;do you really have to push FW policy even though you've made already "save config" with immediate effect on Gaia?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this little bit odd but it turnes out that Install Policy (via SC) is really not needed at all.&lt;/P&gt;
&lt;P&gt;Just wanted to make sure you've had similar things on your side in a past. Some people claim that whatever you chage via clish/shell or gaia you need to "push" from SC - I strongly disagreed to that knowing that routing require that "push" but dhcp-relay not necessarily.&lt;/P&gt;
&lt;P&gt;what do you think?&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 15:10:46 GMT</pubDate>
    <dc:creator>Jerry</dc:creator>
    <dc:date>2019-03-26T15:10:46Z</dc:date>
    <item>
      <title>quick question about bootp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48676#M3605</link>
      <description>&lt;P&gt;hi chaps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;quick question:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when you do bootp, you change your "relay-to" IP address and ...&lt;/P&gt;
&lt;P&gt;do you really have to push FW policy even though you've made already "save config" with immediate effect on Gaia?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found this little bit odd but it turnes out that Install Policy (via SC) is really not needed at all.&lt;/P&gt;
&lt;P&gt;Just wanted to make sure you've had similar things on your side in a past. Some people claim that whatever you chage via clish/shell or gaia you need to "push" from SC - I strongly disagreed to that knowing that routing require that "push" but dhcp-relay not necessarily.&lt;/P&gt;
&lt;P&gt;what do you think?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 15:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48676#M3605</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-03-26T15:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: quick question about bootp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48716#M3606</link>
      <description>Certainly for a new bootp/dhcp relay configuration, a policy install makes sense. Changing the "relay to" IP, not 100% sure on that.</description>
      <pubDate>Tue, 26 Mar 2019 18:04:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48716#M3606</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-26T18:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: quick question about bootp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48745#M3607</link>
      <description>When you setup your policy properly, in DHCP relay youhave a rule allowing the gateway to send the DHCP requests to the DHCP server, so when that server IP changes, the rule changes as well.&lt;BR /&gt;So as long as you don have a rule that will allow the traffic anyway, you should indeed push policy with the updated DHCP server.</description>
      <pubDate>Tue, 26 Mar 2019 19:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48745#M3607</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-03-26T19:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: quick question about bootp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48750#M3608</link>
      <description>&lt;P&gt;In case everything is already allowed within rulebase&amp;nbsp;(new relay-to IP), there is no need to install policy. Tested. Confirmed.&lt;/P&gt;
&lt;P&gt;The best is to have all DHCP servers in 1 group.&lt;/P&gt;
&lt;P&gt;In case some new DHCP server is needed, just add the new host (or network) to this particular group and push the policy.&lt;BR /&gt;Another case is &lt;STRONG&gt;new VLAN&lt;/STRONG&gt; and DHCP on top of this new VLAN. In case you are creating new VLAN together with bootp, policy push is still needed (to fetch Primary Address).&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 20:24:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quick-question-about-bootp/m-p/48750#M3608</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2019-03-26T20:24:32Z</dc:date>
    </item>
  </channel>
</rss>

