<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint connectivity between management &amp;amp; gateway over vpn in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241736#M46933</link>
    <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Thanks for your reply , so senerio is simple that we have management in different location and gateway in other location they are working 81.10 version and we have to add the gateway with management checkpoint through ipsec.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Feb 2025 04:24:51 GMT</pubDate>
    <dc:creator>AnkitBhandari</dc:creator>
    <dc:date>2025-02-20T04:24:51Z</dc:date>
    <item>
      <title>Checkpoint connectivity between management &amp; gateway over vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241641#M46906</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;I am facing a issue that we got a project&amp;nbsp;to replace the existing check point firewall and place the new check point but check point management is on Delhi and check point getaway is on Pune. Exiting was ipsec connectivity between gateway and management so how will I replace the Exiting firewall without or without snapshot backup?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 10:29:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241641#M46906</guid>
      <dc:creator>AnkitBhandari</dc:creator>
      <dc:date>2025-02-19T10:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint connectivity between management &amp; gateway over vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241704#M46917</link>
      <description>&lt;P&gt;More details about the existing environment are needed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Appliances and Software versions used currently (version/JHF levels)&lt;/LI&gt;
&lt;LI&gt;Appliances you are adding/replacing&lt;/LI&gt;
&lt;LI&gt;A simple network diagram showing all components&lt;/LI&gt;
&lt;LI&gt;Confirming someone didn’t disable the various implied rules to force management traffic through VPN (easy enough to see with a tcpdump on the external interface when, say, pushing policy or when the remote gateway sends logs).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2025 16:14:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241704#M46917</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-19T16:14:40Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint connectivity between management &amp; gateway over vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241735#M46932</link>
      <description>&lt;P&gt;In case like that, I would get show configuration fdrom existing gateway and copy "bits and pieces" to new fw clish config, as long as you make sure relevant interfaces match. Unless its same hardware, backup/restore method would not sadly work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Otherwise, you could technically try below method, though it was written for a cluster, but I did use it for single appliances as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/157228#M27268" target="_blank"&gt;Solved: Re: Replace/Upgrade Cluster - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 04:12:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241735#M46932</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-20T04:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint connectivity between management &amp; gateway over vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241736#M46933</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Thanks for your reply , so senerio is simple that we have management in different location and gateway in other location they are working 81.10 version and we have to add the gateway with management checkpoint through ipsec.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 04:24:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241736#M46933</guid>
      <dc:creator>AnkitBhandari</dc:creator>
      <dc:date>2025-02-20T04:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint connectivity between management &amp; gateway over vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241770#M46950</link>
      <description>&lt;P&gt;Putting management traffic (which is already encrypted, FYI) through a VPN is not recommended as it requires editing implied rules and&amp;nbsp;you can end up in a situation where it is impossible to manage your remote gateway if the VPN is down.&lt;BR /&gt;The official procedure for doing this is in an internal SK (sk115215) that requires consultation with TAC.&lt;/P&gt;
&lt;P&gt;See also these public threads on CheckMates:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Exclude-CPM-traffic-from-implied-rules/m-p/3934#M452" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Exclude-CPM-traffic-from-implied-rules/m-p/3934#M452&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Exclude-CPM-Traffic-from-Implied-Rules/m-p/9187#M1452" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Exclude-CPM-Traffic-from-Implied-Rules/m-p/9187#M1452&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 20 Feb 2025 12:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241770#M46950</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-20T12:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint connectivity between management &amp; gateway over vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241772#M46951</link>
      <description>&lt;P&gt;I definitely misunderstood your question. Yes, what Phoneboy said is 100% correct.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 12:52:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-connectivity-between-management-amp-gateway-over-vpn/m-p/241772#M46951</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-20T12:52:29Z</dc:date>
    </item>
  </channel>
</rss>

