<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About external interfaces in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/173189#M28892</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73441"&gt;@fjulianom&lt;/a&gt;&amp;nbsp;It's safe to do "get interfaces" in production. It won't take effect until you accept, publish and push the policy. Just make sure you don't publish anything and discard it. Usually, the only interface marked as "External" is the one linked to your default route. The logic is quite basic. I tend to switch most interfaces to "defined by routes".&lt;/P&gt;
&lt;P&gt;External in this regard is in the context of the firewall. Is the traffic behind or in front of the firewall? On a firewall connected to the Internet, the external interface would normally be the one the firewall itself uses for outbound traffic. Even if you have DMZ networks with public IP addresses, you usually mark them as "Internal" and add the option "Interface Leads to DMZ". This ensures that Threat Prevention Policies will treat your DMZ subnets like they are external adding additional protection by default.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Mar 2023 13:02:18 GMT</pubDate>
    <dc:creator>RamGuy239</dc:creator>
    <dc:date>2023-03-01T13:02:18Z</dc:date>
    <item>
      <title>About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/172634#M28793</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read this article&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R80.30/SmartConsole_OLH/EN/ZvkmnUK_XluBBIIAw1mF3A2" target="_blank" rel="noopener"&gt;Interface - Topology Settings&lt;/A&gt;&amp;nbsp;but still I can't understand how an external interface is defined. When a new firewall is set up, or if I do a "Get interfaces with topology", the external interfaces are those which are gateways for static routes? For example, if I have this in GAIA:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gaia.PNG" style="width: 769px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19768i51260E206FFD5605/image-size/large?v=v2&amp;amp;px=999" role="button" title="gaia.PNG" alt="gaia.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Gateways for 10.129.254.10 and 10.129.255.10 are interfaces eth10 and eth11, respectively. Does this mean eth10 and eth11 will be external, and the rest of interfaces will be internal?&lt;/P&gt;&lt;P&gt;What exactly does it mean "...calculated from the topology of the gateway"?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Internet (External)&lt;/STRONG&gt;&amp;nbsp;or&amp;nbsp;&lt;STRONG&gt;This Network (Internal)&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;-&amp;nbsp;&lt;/STRONG&gt;This is the default setting. It is automatically calculated from the topology of the gateway.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Julián&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 11:12:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/172634#M28793</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2023-02-24T11:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/172667#M28797</link>
      <description>&lt;P&gt;When you do Get Interfaces with Topology, whichever interface has the default route is set to External. Antispoofing groups are built for all the other interfaces containing network objects for the networks which route out that interface.&lt;/P&gt;
&lt;P&gt;In most situations, you should only use External and Internal &amp;gt; Network Defined by Routes. Manually managing your antispoofing topology is a great way to shoot yourself in the foot over and over forever.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 15:55:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/172667#M28797</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-02-24T15:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/172670#M28798</link>
      <description>&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ok, but in my case only one interface has the default route (eth11), the other one (eth10) has static routes, and both of them appear as Internet (External):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="624330CC-402C-4E42-B4C6-71540BFB185B.png" style="width: 502px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19776iC814B19A5F4302CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="624330CC-402C-4E42-B4C6-71540BFB185B.png" alt="624330CC-402C-4E42-B4C6-71540BFB185B.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Shouldn’t eth10 appear as Internal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Julian&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 17:07:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/172670#M28798</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2023-02-24T17:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/172683#M28802</link>
      <description>&lt;P&gt;Hey Julian,&lt;/P&gt;
&lt;P&gt;2 questions:&lt;/P&gt;
&lt;P&gt;1) What happens if you click "get interfaces without topology"?&lt;/P&gt;
&lt;P&gt;2) What IP is defined for internal interface?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 19:30:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/172683#M28802</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-24T19:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/173112#M28877</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't understand your questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I can't do a "get interfaces...", the firewall is in production.&lt;/P&gt;&lt;P&gt;2. What internal interface do you refer to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Julián&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 07:41:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/173112#M28877</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2023-03-01T07:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/173189#M28892</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73441"&gt;@fjulianom&lt;/a&gt;&amp;nbsp;It's safe to do "get interfaces" in production. It won't take effect until you accept, publish and push the policy. Just make sure you don't publish anything and discard it. Usually, the only interface marked as "External" is the one linked to your default route. The logic is quite basic. I tend to switch most interfaces to "defined by routes".&lt;/P&gt;
&lt;P&gt;External in this regard is in the context of the firewall. Is the traffic behind or in front of the firewall? On a firewall connected to the Internet, the external interface would normally be the one the firewall itself uses for outbound traffic. Even if you have DMZ networks with public IP addresses, you usually mark them as "Internal" and add the option "Interface Leads to DMZ". This ensures that Threat Prevention Policies will treat your DMZ subnets like they are external adding additional protection by default.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 13:02:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/173189#M28892</guid>
      <dc:creator>RamGuy239</dc:creator>
      <dc:date>2023-03-01T13:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/173986#M29055</link>
      <description>&lt;P&gt;Hi RamGuy239,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't forget this topic. I wanted to do a "get interfaces" but I had this error because for some reason I have some interfaces locked:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.PNG" style="width: 448px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19985i424D87D715D76A71/image-size/large?v=v2&amp;amp;px=999" role="button" title="error.PNG" alt="error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So I open a TAC case to solve this. Anyway, I have been investigating my firewall configuration and I think I have two external interfaces because I have&lt;SPAN&gt;&amp;nbsp;the default route via eth11, eth10 has static routes, but in the PBR section eth10 is used as default route, this makes more sense.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Julián&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 07:22:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/173986#M29055</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2023-03-08T07:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/174061#M29070</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Hi RamGuy239,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I solved the problem. I was able to do "Get interfaces" and after doing it, both interfaces appeared as external. As said before,&amp;nbsp;I think these two interfaces are external because I have&amp;nbsp;the default route via eth11, eth10 has static routes, but in the PBR section eth10 is used as default route.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Julián&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 15:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/174061#M29070</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2023-03-08T15:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: About external interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/174064#M29072</link>
      <description>&lt;P&gt;I saw your answer to my post just now, apologies. Well, this can be topic for discussion, but I will throw in my 2 cents. Personally, I always suggest to do get interfaces without topology, specially in production. Plus I believe its good idea to use option "network defined by routes", because thats CP recommended way to begin with. Please refer to below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R80.30/SmartConsole_OLH/EN/ZvkmnUK_XluBBIIAw1mF3A2" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R80.30/SmartConsole_OLH/EN/ZvkmnUK_XluBBIIAw1mF3A2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 08 Mar 2023 15:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-external-interfaces/m-p/174064#M29072</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-08T15:52:22Z</dc:date>
    </item>
  </channel>
</rss>

