<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving Gaia portal IP to a new interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85192#M81322</link>
    <description>&lt;P&gt;Oh, I forgot to mention that while modifying interfaces on standby node I put it in down state to avoid cluster flapping by using "clusterXL_admin down" command. Once finished with modifying interfaces and I want to do&amp;nbsp;clusterXL_admin up, it won't jointhe cluster as number of required interfaces is not equal. My guess is that at such condition connections won't be synchronized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 May 2020 09:06:53 GMT</pubDate>
    <dc:creator>abihsot__</dc:creator>
    <dc:date>2020-05-14T09:06:53Z</dc:date>
    <item>
      <title>Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77079#M81313</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;clusterxl, two nodes, R80.20.&lt;/P&gt;&lt;P&gt;I want to move gaia portal IP to a new physical interface.&lt;/P&gt;&lt;P&gt;My idea was to use temporary another IP of different interface as gaia portal while manipulating interfaces.&lt;/P&gt;&lt;P&gt;I though it should work, but gaia portal doesn't load although it seems to listen on any IP:&lt;/P&gt;&lt;P&gt;tcp 0 0 0.0.0.0:8443 0.0.0.0:* LISTEN&lt;/P&gt;&lt;P&gt;In smartconsole in cluster object there is a section "platform portal", however it has only one setting - main url. So I can't modify it per node separately, right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 08:08:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77079#M81313</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-03-04T08:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77084#M81314</link>
      <description>&lt;P&gt;When you change IP addresses on a cluster node, you also need to change the interface name in the cluster configuration in SmartConsole. Let's assume you moved the IP from interface eth1 to eth3&lt;/P&gt;
&lt;P&gt;Double click the cluster object, go to the tab Network Management, find the interface with the IP you assigned for the Gaia portal.&lt;/P&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_3" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_4" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_5" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_6" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_7" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorMaarten_Sjouw_8" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Interface.JPG" style="width: 295px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4666iED27102AD66616FD/image-dimensions/295x320?v=v2" width="295" height="320" role="button" title="Interface.JPG" alt="Interface.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;With interface names you change the name from eth1 to eth3 and push policy.&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 08:44:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77084#M81314</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-04T08:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77085#M81315</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;but before modifying cluster object with new interface name&amp;nbsp;&lt;SPAN&gt;eth1 to eth3, in Gaia portal the IP should have been transferred&amp;nbsp;already to eth3, right? Are you saying once modified in cluster object it will transfer IP in Gaia automatically? That would be awesome because so far I did like this: go to gaia, move IP to the new interface, modify cluster object with new interface and push the policy. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am stuck only on interface which has Gaia portal on it, and I cannot modify it because it complains "you are going to modify interface which you are connected to".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 08:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77085#M81315</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-03-04T08:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77088#M81316</link>
      <description>&lt;P&gt;Ok, so you need the full step by step guide...&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;ssh to member 1 of the cluster&lt;/LI&gt;
&lt;LI&gt;ssh from member 1 to member 2 on the sync network (if not allowed by policy set it to be allowed)&lt;/LI&gt;
&lt;LI&gt;on member 2 issue the following commands from clish (the hostname&amp;gt; prompt)
&lt;UL&gt;
&lt;LI&gt;to remove the ip form the old interface:
&lt;UL&gt;
&lt;LI&gt;delete intyerface eth1 ipv4-address&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Top add IP 1.2.3.4/25 to the eth3 interface:
&lt;UL&gt;
&lt;LI&gt;set interface eth3 ipv4-address 1.2.3.4 mask-length 25&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;update SmartConsole for member 2&lt;/LI&gt;
&lt;LI&gt;push policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;ssh into member 2 on the 1.2.3.4 IP&lt;/LI&gt;
&lt;LI&gt;ssh from member 2 to member 1 on the sync network&lt;/LI&gt;
&lt;LI&gt;on member 12 issue the following commands from clish (the hostname&amp;gt; prompt)
&lt;UL&gt;
&lt;LI&gt;to remove the ip form the old interface:
&lt;UL&gt;
&lt;LI&gt;delete intyerface eth1 ipv4-address&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Top add IP 1.2.3.5/25 to the eth3 interface:
&lt;UL&gt;
&lt;LI&gt;set interface eth3 ipv4-address 1.2.3.5 mask-length 25&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;update SmartConsole for member 1&lt;/LI&gt;
&lt;LI&gt;push policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;You have now completed the change of the interfaces .&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 09:09:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77088#M81316</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-04T09:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77094#M81317</link>
      <description>&lt;P&gt;Now I got it! Totally forgot about ssh between the cluster nodes using other interfaces. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 09:18:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/77094#M81317</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-03-04T09:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85171#M81318</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I ran into another issue while using this procedure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The procedure works fine if the interface is not part of "required interfaces" here:&lt;/P&gt;&lt;P&gt;#cphaprob -a if&lt;/P&gt;&lt;P&gt;CCP mode: Automatic&lt;BR /&gt;Required interfaces: 8&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;eth5 UP non sync(non secured), unicast&lt;BR /&gt;eth3 UP non sync(non secured), unicast&lt;BR /&gt;eth4 UP non sync(non secured), unicast&lt;BR /&gt;Sync UP sync(secured), unicast&lt;BR /&gt;Mgmt Non-Monitored non sync(non secured)&lt;BR /&gt;bond1 UP non sync(non secured), unicast, bond Load Sharing (bond1.1)&lt;BR /&gt;bond1 UP non sync(non secured), unicast, bond Load Sharing (bond1.2)&lt;BR /&gt;bond2 UP non sync(non secured), unicast, bond Load Sharing (bond2.3)&lt;BR /&gt;bond2 UP non sync(non secured), unicast, bond Load Sharing (bond2.4)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I try to migrate IP from bond1.1 to bond2.1 on standby node, the interface dissapears from this table and "required interfaces" becomes 7, and cluster do not want to failover because of lower number of interfaces available. Meanwhile new interface appears with correct bond in "Virtual cluster interfaces" table below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found in checkpoint documentation that interfaces for this table are selected by the gateway atomatically and I cannot intervene here. It all went well with interfaces which were not in this table and now I am stuck here. Only two vlans left and I can't move them.&lt;/P&gt;&lt;P&gt;Any ideas hot to proceed?&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 07:55:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85171#M81318</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-05-14T07:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85184#M81319</link>
      <description>You can still flip over by running cphastop on the active member.</description>
      <pubDate>Thu, 14 May 2020 08:27:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85184#M81319</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-05-14T08:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85190#M81320</link>
      <description>But that would be disruptive to sync'ed connections? I want to have as minimal impact as possible.</description>
      <pubDate>Thu, 14 May 2020 08:47:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85190#M81320</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-05-14T08:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85191#M81321</link>
      <description>the sync is still working and with the cphastop you will just disable the primary member so the other one can take over and should not be disruptive.&lt;BR /&gt;It would be better though to do it at the end of the business day to prevent disruptions as much as possible.</description>
      <pubDate>Thu, 14 May 2020 08:58:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85191#M81321</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-05-14T08:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85192#M81322</link>
      <description>&lt;P&gt;Oh, I forgot to mention that while modifying interfaces on standby node I put it in down state to avoid cluster flapping by using "clusterXL_admin down" command. Once finished with modifying interfaces and I want to do&amp;nbsp;clusterXL_admin up, it won't jointhe cluster as number of required interfaces is not equal. My guess is that at such condition connections won't be synchronized.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 09:06:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85192#M81322</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-05-14T09:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85249#M81323</link>
      <description>Then I'm afraid you will have to make the move when you have a window to do so.</description>
      <pubDate>Thu, 14 May 2020 13:38:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85249#M81323</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-05-14T13:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85253#M81324</link>
      <description>&lt;P&gt;I just need a way to temporary remove bond1.x interfaces from that list. Somehow two vlans bond2.x (migrated ones) appeared in there...&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 13:41:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/85253#M81324</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-05-14T13:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Gaia portal IP to a new interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/89054#M81325</link>
      <description>&lt;P&gt;ok, so migration is completed. In the end I was able to manipulate which interfaces were monitored in ClusterXL by using&amp;nbsp;&lt;SPAN&gt;sk92826, which helped to remove interfaces from "required list"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 14:57:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Moving-Gaia-portal-IP-to-a-new-interface/m-p/89054#M81325</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2020-06-18T14:57:08Z</dc:date>
    </item>
  </channel>
</rss>

