<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Get interface in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246573#M41199</link>
    <description>&lt;P&gt;Excellent advice Lesley.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2025 18:41:11 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-15T18:41:11Z</dc:date>
    <item>
      <title>Get interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246503#M41184</link>
      <description>&lt;P&gt;what is the difference between get interface with topology and without?&lt;BR /&gt;which one is better to use? and why?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 12:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246503#M41184</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-04-15T12:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Get interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246559#M41192</link>
      <description>&lt;P&gt;Get Interfaces is generally safer as it only adds detected interfaces to the gateway object without setting or changing any configuration related to them.&lt;BR /&gt;Get Interfaces With Topology will actually set the anti-spoofing configuration based on what it can see in the device's routing table.&lt;BR /&gt;Problem is: duplicate and sometimes hidden objects are created as part of this process.&lt;BR /&gt;Which is why using Get Interfaces With Topology is generally not considered best practice to use outside of an initial configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 16:53:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246559#M41192</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-15T16:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Get interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246561#M41193</link>
      <description>&lt;P&gt;Phoneboy explained it exactly how it is. For your reference, I would strongly recommend to use without topology. Below are settings its referring to.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/SmartConsole_OLH/EN/Topics-OLH/ZvkmnUK_XluBBIIAw1mF3A2.htm?cshid=ZvkmnUK_XluBBIIAw1mF3A2" target="_blank"&gt;Interface - Topology Settings&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Understanding Topology&lt;/H2&gt;
&lt;P&gt;An interface can be defined as being External (leading to the Internet) or Internal (leading to the LAN).&lt;/P&gt;
&lt;P&gt;The type of network that the interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Leads To&lt;/SPAN&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Internet (External)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;This Network (Internal)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This is the default setting. It is automatically calculated from the topology of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. To update the topology of an internal network after changes to static routes, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Network Management&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Get Interfaces&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;General Properties&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Override&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Override the default setting.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Override&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the default setting:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Internet (External)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- All external/Internet addresses&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;This Network (Internal)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Not Defined&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- All IP addresses behind this interface are considered a part of the internal network that connects to this interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Network defined by the interface IP and Net Mask&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Only the network that directly connects to this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Network defined by routes&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;dynamically calculates the topology behind this interface. If the network changes, there is no need to click "Get Interfaces" and install a policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Specific&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- A specific network object (a network, a host, an address range, or a network group) behind this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Interface leads to DMZ&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The DMZ that directly connects to this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;VPN Tunnel Interfaces&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If the interface is part of a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R82/SmartConsole_OLH/EN/Topics-OLH/ZvkmnUK_XluBBIIAw1mF3A2.htm?cshid=ZvkmnUK_XluBBIIAw1mF3A2#" data-mc-state="closed" data-aria-describedby="f301d7d9-3fee-477c-b724-ec13699a5689" target="_blank"&gt;VPN Tunnel&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;, then the interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Leads To&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Point to Point&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;network. The interface is one end of the point to point connection. All traffic in the network behind the interface is part of the point to point connection. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Override&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to define a specific network.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 16:56:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246561#M41193</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-15T16:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Get interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246571#M41198</link>
      <description>&lt;P&gt;What posted before by phoneboy and the_rock is good advice.&lt;/P&gt;
&lt;P&gt;Only extra tip I can add, screenshot toplogy before fetch and compare it after. Then you are sure the right changes are performed.&lt;/P&gt;
&lt;P&gt;Fetching with toplogy I have never done (yet) before&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 18:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246571#M41198</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-15T18:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Get interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246573#M41199</link>
      <description>&lt;P&gt;Excellent advice Lesley.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 18:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246573#M41199</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-15T18:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Get interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/257036#M43280</link>
      <description>&lt;P&gt;My general advice is to only use "Get Interfaces With Topology" on a new gateway that is not yet in production.&amp;nbsp; &amp;nbsp;For a production gateway, one should only use "Get Interfaces Without Topology" and then manually set topology for any newly fetched interfaces.&amp;nbsp;&amp;nbsp;"Get Interfaces With Topology" should be avoided on a production gateway as it can disrupt the topology settings of preexisting interfaces, resulting in massive anti-spoofing drops.&lt;/P&gt;
&lt;P&gt;This behavior has been fully documented here at last: &lt;A href="https://support.checkpoint.com/results/sk/sk183590" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk183590: "Get interfaces with topology" and "Get interfaces without topology" actions in SmartConsole&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 14:11:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/257036#M43280</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-09-10T14:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: Get interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/257038#M43282</link>
      <description>&lt;P&gt;100% agree...thats what I always suggest to people as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 10 Sep 2025 14:45:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/257038#M43282</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-10T14:45:10Z</dc:date>
    </item>
  </channel>
</rss>

