<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Will changing an External defined interface to Network defined by routes cause a blip on a cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Will-changing-an-External-defined-interface-to-Network-defined/m-p/51655#M3894</link>
    <description>&lt;P&gt;Our gateways are on R80.10&lt;/P&gt;&lt;P&gt;We currently have two interfaces configured as Topology - External. We want to change one of them to be Topology - Network defined by Routes.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="External facing nic.PNG" style="width: 492px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/942iE2A0FBA60F7CDE1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="External facing nic.PNG" alt="External facing nic.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="External facing nic x2.PNG" style="width: 560px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/943i6BA87B5D9D99FB14/image-size/large?v=v2&amp;amp;px=999" role="button" title="External facing nic x2.PNG" alt="External facing nic x2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There doesn't appear to be this option on R80.10 although the help does takes you to this page:-&lt;/P&gt;&lt;DIV class="pageContent"&gt;Understanding Topology&lt;P class="tpbodytext"&gt;An interface can be defined as being External (leading to the Internet) or Internal (leading to the LAN).&lt;/P&gt;&lt;P class="tpbodytext"&gt;The type of network that the interface &lt;STRONG&gt;Leads To&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Internet (External)&lt;/STRONG&gt; or &lt;STRONG&gt;This Network (Internal) &lt;/STRONG&gt;&lt;STRONG&gt;- &lt;/STRONG&gt;This is the default setting. It is automatically calculated from the topology of the gateway. To update the topology of an internal network after changes to static routes, click &lt;STRONG&gt;Network Management &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Get Interfaces&lt;/STRONG&gt; in the &lt;STRONG&gt;General Properties &lt;/STRONG&gt;window of the gateway.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Override &lt;/STRONG&gt;- Override the default setting.&lt;/LI&gt;&lt;/UL&gt;&lt;P class="tpbodytext"&gt;If you &lt;STRONG&gt;Override&lt;/STRONG&gt; the default setting:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Internet (External) &lt;/STRONG&gt;- All external/Internet addresses&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;This Network (Internal) &lt;/STRONG&gt;-&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Not Defined&lt;/STRONG&gt; - All IP addresses behind this interface are considered a part of the internal network that connects to this interface&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Network defined by the interface IP and Net Mask&lt;/STRONG&gt; - Only the network that directly connects to this internal interface&lt;/LI&gt;&lt;LI&gt;&lt;U&gt;&lt;STRONG&gt;&lt;EM&gt;Network defined by routes - The gateway dynamically calculates the topology behind this interface. If the network changes, there is no need to click "Get Interfaces" and install a policy.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Specific &lt;/STRONG&gt;- A specific network object (a network, a host, an address range, or a network group) behind this internal interface&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Interface leads to DMZ&lt;/STRONG&gt; - The DMZ that directly connects to this internal interface&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One that will remain as External leads to our External facing firewall,&amp;nbsp; the other which we want to change leads to our internal network.&lt;/P&gt;&lt;P&gt;We also have Anti-Spoofing set on this interface .&lt;/P&gt;&lt;P&gt;Firstly is this option available in R80.10 and if not what option is recommended to point back to our internal network.&lt;/P&gt;&lt;P&gt;Secondly will changing this cause us any outage?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2019 10:02:50 GMT</pubDate>
    <dc:creator>Beverley_Cudd</dc:creator>
    <dc:date>2019-04-24T10:02:50Z</dc:date>
    <item>
      <title>Will changing an External defined interface to Network defined by routes cause a blip on a cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Will-changing-an-External-defined-interface-to-Network-defined/m-p/51655#M3894</link>
      <description>&lt;P&gt;Our gateways are on R80.10&lt;/P&gt;&lt;P&gt;We currently have two interfaces configured as Topology - External. We want to change one of them to be Topology - Network defined by Routes.&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="External facing nic.PNG" style="width: 492px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/942iE2A0FBA60F7CDE1D/image-size/large?v=v2&amp;amp;px=999" role="button" title="External facing nic.PNG" alt="External facing nic.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="External facing nic x2.PNG" style="width: 560px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/943i6BA87B5D9D99FB14/image-size/large?v=v2&amp;amp;px=999" role="button" title="External facing nic x2.PNG" alt="External facing nic x2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There doesn't appear to be this option on R80.10 although the help does takes you to this page:-&lt;/P&gt;&lt;DIV class="pageContent"&gt;Understanding Topology&lt;P class="tpbodytext"&gt;An interface can be defined as being External (leading to the Internet) or Internal (leading to the LAN).&lt;/P&gt;&lt;P class="tpbodytext"&gt;The type of network that the interface &lt;STRONG&gt;Leads To&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Internet (External)&lt;/STRONG&gt; or &lt;STRONG&gt;This Network (Internal) &lt;/STRONG&gt;&lt;STRONG&gt;- &lt;/STRONG&gt;This is the default setting. It is automatically calculated from the topology of the gateway. To update the topology of an internal network after changes to static routes, click &lt;STRONG&gt;Network Management &lt;/STRONG&gt;&amp;gt; &lt;STRONG&gt;Get Interfaces&lt;/STRONG&gt; in the &lt;STRONG&gt;General Properties &lt;/STRONG&gt;window of the gateway.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Override &lt;/STRONG&gt;- Override the default setting.&lt;/LI&gt;&lt;/UL&gt;&lt;P class="tpbodytext"&gt;If you &lt;STRONG&gt;Override&lt;/STRONG&gt; the default setting:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Internet (External) &lt;/STRONG&gt;- All external/Internet addresses&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;This Network (Internal) &lt;/STRONG&gt;-&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Not Defined&lt;/STRONG&gt; - All IP addresses behind this interface are considered a part of the internal network that connects to this interface&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Network defined by the interface IP and Net Mask&lt;/STRONG&gt; - Only the network that directly connects to this internal interface&lt;/LI&gt;&lt;LI&gt;&lt;U&gt;&lt;STRONG&gt;&lt;EM&gt;Network defined by routes - The gateway dynamically calculates the topology behind this interface. If the network changes, there is no need to click "Get Interfaces" and install a policy.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Specific &lt;/STRONG&gt;- A specific network object (a network, a host, an address range, or a network group) behind this internal interface&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Interface leads to DMZ&lt;/STRONG&gt; - The DMZ that directly connects to this internal interface&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One that will remain as External leads to our External facing firewall,&amp;nbsp; the other which we want to change leads to our internal network.&lt;/P&gt;&lt;P&gt;We also have Anti-Spoofing set on this interface .&lt;/P&gt;&lt;P&gt;Firstly is this option available in R80.10 and if not what option is recommended to point back to our internal network.&lt;/P&gt;&lt;P&gt;Secondly will changing this cause us any outage?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 10:02:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Will-changing-an-External-defined-interface-to-Network-defined/m-p/51655#M3894</guid>
      <dc:creator>Beverley_Cudd</dc:creator>
      <dc:date>2019-04-24T10:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Will changing an External defined interface to Network defined by routes cause a blip on a clust</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Will-changing-an-External-defined-interface-to-Network-defined/m-p/51883#M3908</link>
      <description>This option is only available on R80.20 gateways and above.&lt;BR /&gt;If the anti-spoofing configuration is not set correctly, it can cause an outage.&lt;BR /&gt;Make certain all the correct network(s) are defined on all the relevant interfaces.</description>
      <pubDate>Thu, 25 Apr 2019 22:51:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Will-changing-an-External-defined-interface-to-Network-defined/m-p/51883#M3908</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-25T22:51:22Z</dc:date>
    </item>
  </channel>
</rss>

