<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interface cleanup before migrating to new appliances in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237724#M46169</link>
    <description>&lt;P&gt;K, read it, that makes sense to me, yeah. Just make sure the IP addresses are NOT referenced anywhere else before removing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jan 2025 17:54:22 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-01-06T17:54:22Z</dc:date>
    <item>
      <title>Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237688#M46160</link>
      <description>&lt;P&gt;Good morning and Happy New Year!&lt;/P&gt;
&lt;P&gt;We are currently running a (2) node R81.20 cluster - (active / standby) on a pair of 5100 appliances.&lt;/P&gt;
&lt;P&gt;We are going to migrate our exact configuration / rule sets to a new pair of 9100s following the below post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/69251#M5294" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/69251#M5294&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before I do the migration, I'd like to cleanup the interfaces on my existing 5100s so I can build out the new appliances with the updated/correct interfaces.&lt;/P&gt;
&lt;P&gt;For instance, my &lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;eth1&lt;/STRONG&gt; &lt;/FONT&gt;and &lt;STRONG&gt;eth2&lt;/STRONG&gt; had been used for my two external ISP connections.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We configured a third ISP to replace the ISP on eth2.&amp;nbsp; Due to port constraints, we configured this third ISP interface on the interface labeled as "Mgmt".&lt;/P&gt;
&lt;P&gt;Our actual interface that we use for management is &lt;STRONG&gt;eth4&lt;/STRONG&gt; - one of our internal LAN interfaces.&lt;/P&gt;
&lt;P&gt;We re-configured &lt;STRONG&gt;ISP Redundancy&lt;/STRONG&gt; to use interfaces &lt;STRONG&gt;eth1&lt;/STRONG&gt; (Primary) and &lt;STRONG&gt;Mgmt&lt;/STRONG&gt; (Backup).&amp;nbsp; (This works as it should).&lt;/P&gt;
&lt;P&gt;We have since turned off the service for the old ISP that was on &lt;STRONG&gt;eth2&lt;/STRONG&gt;, but the "cable" is still connected to the &lt;STRONG&gt;eth2&lt;/STRONG&gt; port.&amp;nbsp; The "Link Status" is "Down" on both cluster nodes.&lt;/P&gt;
&lt;DIV id="tinyMceEditorJoe_Kanaszka_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;STRONG&gt;See below screenshot of one of my 5100 cluster nodes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-01-06 085929.jpg" style="width: 942px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29098i2B3D3A5EDAAAB280/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-01-06 085929.jpg" alt="Screenshot 2025-01-06 085929.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before I build out the new 9100s, I'd like to delete the "Old ISP" from the &lt;STRONG&gt;eth2&lt;/STRONG&gt; interface and move my new&amp;nbsp; Backup ISP interface currently on &lt;STRONG&gt;Mgmt&lt;/STRONG&gt;&amp;nbsp;to &lt;STRONG&gt;eth2.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Then when I configure my new 9100s, I can start with the "cleaned up" interfaces configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How best to go about this?&lt;/P&gt;
&lt;P&gt;I'm guessing step 1 is reconfigure the interfaces on the "Standby" node first.&amp;nbsp; Make all the changes in the Gaia portal.&lt;/P&gt;
&lt;P&gt;After this step I'm not sure how best to proceed...&lt;/P&gt;
&lt;P&gt;Thanks guys!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you both Andy and Akos for your assistance!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 19:33:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237688#M46160</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2025-01-06T19:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237694#M46161</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;I would definitely remove backup interfaces first, save, then master, save, update topology in smart console (interfaces WITHOUT topology that is).&lt;/P&gt;
&lt;P&gt;Take backups first!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 15:06:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237694#M46161</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-06T15:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237695#M46162</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;First I suggest you to do it in smaller eg. in a LAB environment. Thats gives you confidence.&lt;/P&gt;
&lt;P&gt;If I understood correct (from a little pieces of info)&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Q: Before I build out the new 9100s, I'd like to delete the "Old ISP" from the&amp;nbsp;&lt;STRONG&gt;eth2&lt;/STRONG&gt;&amp;nbsp;interface and move my new&amp;nbsp; Backup ISP interface currently on&amp;nbsp;&lt;STRONG&gt;Mgmt&lt;/STRONG&gt;&amp;nbsp;to&amp;nbsp;&lt;STRONG&gt;eth2.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Here is the exact steps how to add or remove Interface from a Cluster.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk57100" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk57100&lt;/A&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;put the standby member to down&lt;/LI&gt;
&lt;LI&gt;You need to remove the ClusterIP-s first -&amp;gt; to achieve this delete the IF in the SmartConsole -&amp;gt; then policy install. Only after this change anything on GAIA portal.&lt;/LI&gt;
&lt;LI&gt;If you do this, the old &lt;STRONG style="font-family: inherit; background-color: #ffffff;"&gt;ISP stopped working immediately, &lt;/STRONG&gt;&lt;SPAN&gt;but eth2 will released.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;This would be the goal?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 15:33:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237695#M46162</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-06T15:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237696#M46163</link>
      <description>&lt;P&gt;Good reference sk!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 15:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237696#M46163</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-06T15:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237722#M46167</link>
      <description>&lt;P&gt;Good afternoon Akos and thank you!&lt;/P&gt;
&lt;P&gt;What I would like to do is this:&lt;/P&gt;
&lt;P&gt;Remove old physical IP and cluster IP from eth2 from both nodes.&amp;nbsp; This interface is currently not being used.&lt;/P&gt;
&lt;P&gt;Move my backup ISP connection curently on "Mgmt" to eth2 on both nodes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After I'm done I should have both of my external ISP connections on eth1 and eth2 on both nodes.&amp;nbsp; The current Mgmt will not be used for "Management".&lt;/P&gt;
&lt;P&gt;eth4 will continue to be my local LAN &amp;amp; Management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this make sense?&amp;nbsp; So I'm deleting two interfaces: Mgmt &amp;amp; eth2, and then re-configuring eth2 with the same IP that was on Mgmt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 17:51:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237722#M46167</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2025-01-06T17:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237723#M46168</link>
      <description>&lt;P&gt;Thanks Andy!&amp;nbsp; Please see my response to Akos.&lt;/P&gt;
&lt;P&gt;I may not have explained myself well the first post.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 17:52:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237723#M46168</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2025-01-06T17:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237724#M46169</link>
      <description>&lt;P&gt;K, read it, that makes sense to me, yeah. Just make sure the IP addresses are NOT referenced anywhere else before removing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 17:54:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237724#M46169</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-06T17:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237737#M46172</link>
      <description>&lt;P&gt;Forgot to add, maybe do snapshots too if you can.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 19:03:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237737#M46172</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-06T19:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237738#M46173</link>
      <description>&lt;P&gt;Hi K,&lt;/P&gt;
&lt;P&gt;If you want to remove the Virtual IP of a Cluster IF,&amp;nbsp; the only way is to delete te if in the SmartConsole, then push policy. Don't forget it, trust me, I know. I can't highlight it enough &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Put the standby member to DOWN state to avoid of unwanted cluster flapping. (with #clusterXL_admin down)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And The holy triumvirate: snapshot, system backup, save configurtaion.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 19:05:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237738#M46173</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-06T19:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237740#M46174</link>
      <description>&lt;P&gt;Yes, super important!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 19:07:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237740#M46174</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-06T19:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Interface cleanup before migrating to new appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237913#M46191</link>
      <description>&lt;P&gt;Hey Joe,&lt;/P&gt;
&lt;P&gt;Forgot to mention something kind of important, though you may not have to do any of this, but better confirm. Whenever I deal with things like this, I always verify afterwards in guidbedit that whatever is supposed to be removed is gone there as well.&lt;/P&gt;
&lt;P&gt;Just a suggestion.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 23:27:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interface-cleanup-before-migrating-to-new-appliances/m-p/237913#M46191</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-07T23:27:29Z</dc:date>
    </item>
  </channel>
</rss>

