<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing ISP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/135180#M73849</link>
    <description>&lt;P&gt;SIC is based on certificates, so changing IPs won't be an issue.&lt;BR /&gt;If the effective management IP changes for B and C, you'll need to push policy to them as well.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Nov 2021 20:25:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-11-29T20:25:23Z</dc:date>
    <item>
      <title>Changing ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/134855#M73848</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a simple setup with 3 gateways (A, B and C) and 1 management server (M).&amp;nbsp; M is behind A.&amp;nbsp; SIC is established and all VPN tunnels have been up and working for years.&amp;nbsp; M has a static NAT.&amp;nbsp; I'm getting ready to change the ISP of A.&amp;nbsp; Here are the steps I would take to do this.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Login to Gaia on A and&amp;nbsp;update the network interface and the default gateway&lt;/LI&gt;&lt;LI&gt;Login to SmartConsole and edit the gateway object to update A's IP address,&amp;nbsp;IPSec VPN, VPN Clients, etc.&lt;/LI&gt;&lt;LI&gt;Update M's NAT&lt;/LI&gt;&lt;LI&gt;Push policy&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;My thought is when I push the policy it would install on A but not the others because the trust will break because the B and C have no idea about the ISP change.&amp;nbsp; Would I need to reset SIC on B and C or is there a way to avoid resetting?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Fred&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 00:38:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/134855#M73848</guid>
      <dc:creator>Fred_Katsumi</dc:creator>
      <dc:date>2021-11-25T00:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Changing ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/135180#M73849</link>
      <description>&lt;P&gt;SIC is based on certificates, so changing IPs won't be an issue.&lt;BR /&gt;If the effective management IP changes for B and C, you'll need to push policy to them as well.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 20:25:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/135180#M73849</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-29T20:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Changing ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/135206#M73850</link>
      <description>&lt;P&gt;You should add a temp rule before you change IPs to ensure the gateways B anc C will accept traffic from the new M NAT IP. They would have an implied rule to accept traffic from the current NAT IP but would likely not accept a policy install from the new NAT IP.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 03:47:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/135206#M73850</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2021-11-30T03:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Changing ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/135431#M73851</link>
      <description>&lt;P&gt;Thank you for the pointers.&amp;nbsp; I was able to complete this.&amp;nbsp; As emmap suggested I created a dummy host with the new M NAT IP and created a rule to allow traffic.&amp;nbsp; Installed the policy on all gateways.&amp;nbsp; Then I made all the IP address changes to the gateway A and management M as I outlined above.&amp;nbsp; With the temp rule in place, SIC never broke and I was able to push policy using the new ISP connection.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 17:20:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Changing-ISP/m-p/135431#M73851</guid>
      <dc:creator>Fred_Katsumi</dc:creator>
      <dc:date>2021-12-02T17:20:54Z</dc:date>
    </item>
  </channel>
</rss>

