<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change Management IP addresses in Cluster in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99364#M19352</link>
    <description>&lt;P&gt;That sounds very good.&lt;/P&gt;
&lt;P&gt;If you have another gateway between your gateway you should modify the rules for communication between CMA and gateway. Read more here: &lt;A href="https://community.checkpoint.com/docs/DOC-2740-r80x-ports-used-for-communication-by-various-check-point-modules" target="_blank" rel="noopener"&gt;R80.x - Ports Used for Communication by Various Check Point Modules&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I would do the following before you changes the IP:&lt;/P&gt;
&lt;P&gt;Gateway -&amp;gt; Snapshot&lt;BR /&gt;MDS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; mds_backup or Snapshot&lt;/P&gt;
&lt;P&gt;Then you can rollback everything if necessary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 17 Oct 2020 17:17:41 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2020-10-17T17:17:41Z</dc:date>
    <item>
      <title>Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99310#M19344</link>
      <description>&lt;P&gt;Hi mates,&lt;/P&gt;&lt;P&gt;I have a question for you, just before the week-end &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;A cluster was configured and sent the our Data Center using temporary non-routed management IP addresses, I don't know why...&lt;/P&gt;&lt;P&gt;So I'd like to change them with the good IP addresses before put them in production but I'm not sure of the good way to do it. I've looked on the documentation and here, but i'm still confused. I thought of the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;using the console access, change the ip address on the Mgmt Interfaces of each gateway&lt;/LI&gt;&lt;LI&gt;add the necessary static route for the communication with the CMA&lt;/LI&gt;&lt;LI&gt;on the smartConsole, edit the object of the gateways and change the IP addresses&lt;/LI&gt;&lt;LI&gt;Change the IP address of the cluster objet&lt;/LI&gt;&lt;LI&gt;Get interface without topology&amp;nbsp; and push the policy&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Am I missing something, or maybe completely wrong on the procedure ? Worst case scenario I can fresh install the gateways as they are not in production, but I’d rather just change the ip addresses.&lt;/P&gt;&lt;P&gt;Thanks for your help, and have a good week-end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: the procedure above did the trick, I was able to change the IP addresses of the gateways. Just one thing, as the policy was already pushed on the gateway with the old ip addresses, the communication between the CMA and the gateway wasn't working with the new IPs, they were droped. A &lt;EM&gt;fw unloadlocal&lt;/EM&gt; was necessary to be able to push the new topology and the policy again.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 10:21:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99310#M19344</guid>
      <dc:creator>Josh28</dc:creator>
      <dc:date>2020-10-28T10:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99325#M19347</link>
      <description>&lt;P&gt;That seems like the right procedure to me.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 20:11:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99325#M19347</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-16T20:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99364#M19352</link>
      <description>&lt;P&gt;That sounds very good.&lt;/P&gt;
&lt;P&gt;If you have another gateway between your gateway you should modify the rules for communication between CMA and gateway. Read more here: &lt;A href="https://community.checkpoint.com/docs/DOC-2740-r80x-ports-used-for-communication-by-various-check-point-modules" target="_blank" rel="noopener"&gt;R80.x - Ports Used for Communication by Various Check Point Modules&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I would do the following before you changes the IP:&lt;/P&gt;
&lt;P&gt;Gateway -&amp;gt; Snapshot&lt;BR /&gt;MDS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; mds_backup or Snapshot&lt;/P&gt;
&lt;P&gt;Then you can rollback everything if necessary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Oct 2020 17:17:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99364#M19352</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-10-17T17:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99590#M19394</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thanks for your feedback. Just to let you know that it did the trick, I was able to change the management IP addresses thank you.&lt;/P&gt;&lt;P&gt;But I'm facing some strange issue now. I was going to upgrade both gateway (in R80.20, I know it should be at least 30 but it's not my decision. And a long story).&lt;/P&gt;&lt;P&gt;Anyway, it went well for the first gateway using a blink upgrade as I did for a few clusters lately. But for the second I get this message:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;installer verify 1&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Info: Initiating verify of blink_image_1.1_Check_Point_R80.20_T117_JHF_T173_SecurityGateway.tgz...&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Interactive mode is enabled. Press CTRL + C to exit (this will not stop the operation)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Result: Verifier results Package: blink_image_1.1_Check_Point_R80.20_T117_JHF_T173_SecurityGateway.tgz Clean Install: Installation is allowed. Upgrade: The following results are not compatible with the package:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;- Machine's configuration is 'StandAlone'&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;This image is valid only for Security Gateway upgrade&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;And I can't use it to upgrade... I guess my former coworker installed it in standalone mode. Do you know if this is something I can change&amp;nbsp; easily or should I just fresh install everything ?&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 12:37:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99590#M19394</guid>
      <dc:creator>Josh28</dc:creator>
      <dc:date>2020-10-20T12:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99600#M19395</link>
      <description>&lt;P&gt;I would suggest to stay on the safe side with a fresh install !&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 14:04:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99600#M19395</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-20T14:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99618#M19397</link>
      <description>&lt;P&gt;Yep, but that's what I'd like to avoid ‌&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;‌&lt;/P&gt;&lt;P&gt;What I can't understand, it's how the gateway can be in standalone mode, and in the same time managed by a management server, because I was able to add it on a CMA, configure ClusterXL, do the sic and push the policy etc... ‌&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;‌&lt;/P&gt;&lt;P&gt;Can I check somewhere the deployment type actually configured on the GWs ?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 16:28:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/99618#M19397</guid>
      <dc:creator>Josh28</dc:creator>
      <dc:date>2020-10-20T16:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/131338#M23828</link>
      <description>&lt;P&gt;Did you have to re-establish SIC between management and each gateway? I asked Checkpoint how to change the management IPs in a pair of gateways in a cluster. Their advice was to delete the cluster, change the gateways one by one, and recreate the cluster. Seems excessive to me. I'd have expected to be able to just change the IPs on the gateways and on management (via SmartConsole), then re-establish SIC, then push policy.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Oct 2021 05:44:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/131338#M23828</guid>
      <dc:creator>jimm</dc:creator>
      <dc:date>2021-10-08T05:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/131353#M23832</link>
      <description>&lt;P&gt;This is possible using CLI, and you also can change it. But the command is not supported except when advised by TAC to use it !&lt;/P&gt;
&lt;LI-SPOILER&gt;
&lt;P&gt;My GW gives me:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;# cpprod_util FwIsFirewallModule&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;# cpprod_util FwIsStandAlone &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;0&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;# cpprod_util FwIsFirewallMgmt&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;0&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;You could try the set command:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;# cpprod_util FwSetStandAlone 0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI-SPOILER&gt;</description>
      <pubDate>Fri, 08 Oct 2021 09:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/131353#M23832</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-08T09:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Change Management IP addresses in Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/133754#M24065</link>
      <description>&lt;P&gt;i have a similar scenario - i have Management on one particular interface (internal) and i want to change the management to another existing Internal interface. All is routable.&lt;/P&gt;&lt;P&gt;i assume all i need to do is change the Management IP on the cluster nodes.&lt;/P&gt;&lt;P&gt;i wasn't sure if i needed to re-establish SIC on each cluster node - some forums have suggested you do and others have said no.&lt;/P&gt;&lt;P&gt;i was hoping to avoid having to do an fw unloadlocal and wiping the policy as that would trigger an outage to all services using that firewall.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2021 17:00:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-Management-IP-addresses-in-Cluster/m-p/133754#M24065</guid>
      <dc:creator>JMB77</dc:creator>
      <dc:date>2021-11-10T17:00:36Z</dc:date>
    </item>
  </channel>
</rss>

