<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Get interfaces or manually add an interface - is there any difference? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244089#M62901</link>
    <description>&lt;P&gt;With over 100 interfaces (VLAN's) it is still a lot of changes to push. And the time increases on some sort of exponential scale with the number of interfaces involved.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Mar 2025 15:44:04 GMT</pubDate>
    <dc:creator>Hugo_vd_Kooij</dc:creator>
    <dc:date>2025-03-18T15:44:04Z</dc:date>
    <item>
      <title>Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/243646#M62894</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I'd like to understand if there is any functional difference between adding interfaces in Network Topology manually against using 'Get Interfaces' feature.&lt;/P&gt;&lt;P&gt;We used to add all interfaces manually. It worked, no issues.&lt;/P&gt;&lt;P&gt;Recently I tried to create a GRE tunnel on a cluster (R81.20). I followed&amp;nbsp;sk169794. The only difference was that I added GRE interfaces manually instead of using 'Get Interfaces with Topology'.&lt;/P&gt;&lt;P&gt;GRE tunnel was up and running however all GRE packets sent by a cluster member were sent with the active cluster member physical interface IP as a source, not VIP.&lt;/P&gt;&lt;P&gt;I've been told that running 'Get Interfaces with Topology' and installing policy should solve the issue.&amp;nbsp;I ran 'Get Interfaces with Topology' however that created about a hundred configuration changes and I'm not happy to publish them.&lt;/P&gt;&lt;P&gt;I always believed that 'Get Interfaces' is a helpful shortcut used to make all interface name/ip/spoofing group/etc creation easier. Is there anything else that happens behind the scene?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Pawel&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 13:13:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/243646#M62894</guid>
      <dc:creator>Pawel_</dc:creator>
      <dc:date>2025-03-12T13:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/243996#M62895</link>
      <description>&lt;P&gt;I fail to see how Get Interfaces with Topology would resolve this issue.&lt;BR /&gt;I assume Cluster NAT isn't happening on GRE traffic.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 19:35:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/243996#M62895</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-17T19:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244027#M62896</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11697"&gt;@Pawel_&lt;/a&gt;;&lt;BR /&gt;&lt;BR /&gt;Here is a comparison between adding interfaces manually in Network Topology and using the 'Get Interfaces' feature in SmartConsole:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Manual Configuration:&lt;/STRONG&gt; &lt;BR /&gt;Recommended for environments where precision and customization are critical, especially for special interfaces like loopback interfaces.&lt;BR /&gt;Allows for the inclusion of special interfaces like loopback interfaces, which are not retrieved by the 'Get Interfaces' feature.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Get Interfaces Feature:&lt;/STRONG&gt; &lt;BR /&gt;Suitable for environments where efficiency and consistency are prioritized, and the number of interfaces is manageable.&lt;BR /&gt;Automatically retrieves and configures multiple interfaces quickly, saving time. There is a higher chance of configuration errors due to manual input.&lt;BR /&gt;Does not retrieve interfaces without assigned IP addresses (e.g., 0.0.0.0 or 127.0.0.1) or loopback interfaces.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 07:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244027#M62896</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2025-03-18T07:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244038#M62897</link>
      <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;That's exactly what I thought and I wasn't happy to follow the support recommendation and mess up my current config.&lt;/P&gt;&lt;P&gt;I had also created a manual NAT for GRE traffic however it did not work, neither.&lt;/P&gt;&lt;P&gt;Finally I decided to give up and moved GRE to other vendor devices.&lt;/P&gt;&lt;P&gt;Thank you again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 08:52:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244038#M62897</guid>
      <dc:creator>Pawel_</dc:creator>
      <dc:date>2025-03-18T08:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244039#M62898</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Got it, so 'Get Interfaces' is just an automatic way that helps to avoid configuration errors. If the interfaces are manually configured correctly 'Get Interfaces' should not bring any additional value.&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 08:56:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244039#M62898</guid>
      <dc:creator>Pawel_</dc:creator>
      <dc:date>2025-03-18T08:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244066#M62899</link>
      <description>&lt;P&gt;Correct.&amp;nbsp; One other note that I mention in my classes is to NEVER do a "Get interfaces with topology" on an existing gateway that is in production, since as you saw doing so may attempt to reconfigure the topology of dozens or hundreds of interfaces and get you into anti-spoofing trouble.&amp;nbsp; Use "Get interfaces without topology" on production gateways instead then manually verify the topology settings for any new interfaces.&amp;nbsp; "Get interfaces with topology" is fine for a new gateway you are deploying that is not in production yet, but you'll still need to manually verify the topology settings of all interfaces.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 13:04:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244066#M62899</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-18T13:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244069#M62900</link>
      <description>&lt;P&gt;There are specific cases. For instance, VTI implementation asks you to perform a "Get interfaces without topology" as you can't create them manually, which is always a great feeling to have when clicking on this option on a production environment.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 13:21:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244069#M62900</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-03-18T13:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244089#M62901</link>
      <description>&lt;P&gt;With over 100 interfaces (VLAN's) it is still a lot of changes to push. And the time increases on some sort of exponential scale with the number of interfaces involved.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 15:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244089#M62901</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2025-03-18T15:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Get interfaces or manually add an interface - is there any difference?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244093#M62902</link>
      <description>&lt;P&gt;Get interfaces without topology would simply "fetch" whats on the OS level.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 16:52:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Get-interfaces-or-manually-add-an-interface-is-there-any/m-p/244093#M62902</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-18T16:52:39Z</dc:date>
    </item>
  </channel>
</rss>

