<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Five Habits That Improved My Check Point Deployments in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/280311#M46619</link>
    <description>&lt;P&gt;Its often that these kind of implementation documentation is saved in some sort of project.&lt;BR /&gt;Then when you need it 1-2 years later, its nowhere to be found as the engineers installed it has moved on.&lt;BR /&gt;&lt;BR /&gt;When doing planning, documentation etc&lt;BR /&gt;Do that in a system that is used within production for your documenation.&lt;BR /&gt;We for example uses Netbox for all the physical stuff and the things that is "non standard" to have it easily accessible in day to day operation when its time for the next upgrade / tshoot.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Ofc its good if your standard is then well documented, but i still find it more useful that you make sure to document things that was changed from default settings, IE: &lt;SPAN&gt;00-OS-XX.rules&amp;nbsp; / user.def or similar files.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jul 2026 13:20:55 GMT</pubDate>
    <dc:creator>Magnus-Holmberg</dc:creator>
    <dc:date>2026-07-28T13:20:55Z</dc:date>
    <item>
      <title>Five Habits That Improved My Check Point Deployments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279760#M46582</link>
      <description>&lt;P class="PDq2pG_selectionAnchorContainer lia-align-justify" data-end="883" data-start="659"&gt;Over the past few years, I've had the opportunity to work full-time with Check Point deployment projects, participating in hundreds of firewall implementations ranging from small environments to large enterprise deployments.&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="1076" data-start="885"&gt;Every project has taught me something new. Some lessons came from successful implementations, while others came from unexpected situations that forced me to improve my planning and execution.&lt;/P&gt;
&lt;P class="lia-align-justify" data-end="1169" data-start="1078"&gt;I'd like to share the workflow that has helped me consistently deliver successful projects.&lt;/P&gt;
&lt;H2 data-end="1233" data-start="1176" data-section-id="a9pa61"&gt;&lt;STRONG&gt;1. Understand the Project Before Touching the Firewall&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P data-end="1313" data-start="1235"&gt;When a new project arrives, the first thing we usually hear is something like:&lt;/P&gt;
&lt;UL data-end="1426" data-start="1315"&gt;
&lt;LI data-end="1353" data-start="1315" data-section-id="14h8yuw"&gt;"We'll deploy two Quantum gateways."&lt;/LI&gt;
&lt;LI&gt;"We'll deploy 30 Quantum gateways."&lt;/LI&gt;
&lt;LI&gt;"We'll deploy SD-WAN"&lt;/LI&gt;
&lt;LI data-end="1385" data-start="1354" data-section-id="1nirwiw"&gt;"It's a Maestro environment."&lt;/LI&gt;
&lt;LI data-end="1426" data-start="1386" data-section-id="16z9axl"&gt;"We're migrating from another vendor."&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1458" data-start="1428"&gt;But that's only the beginning.&lt;/P&gt;
&lt;P data-end="1535" data-start="1460"&gt;Before writing a single command, I try to fully understand the environment:&lt;/P&gt;
&lt;UL data-end="1724" data-start="1537"&gt;
&lt;LI data-end="1556" data-start="1537" data-section-id="1gic2o4"&gt;Physical topology&lt;/LI&gt;
&lt;LI data-end="1575" data-start="1557" data-section-id="rzywxe"&gt;Logical topology&lt;/LI&gt;
&lt;LI data-end="1594" data-start="1576" data-section-id="1s38d9j"&gt;Existing routing&lt;/LI&gt;
&lt;LI data-end="1612" data-start="1595" data-section-id="1yjhzw5"&gt;WAN connections&lt;/LI&gt;
&lt;LI data-end="1626" data-start="1613" data-section-id="1197npr"&gt;VLAN design&lt;/LI&gt;
&lt;LI data-end="1659" data-start="1627" data-section-id="57fl9e"&gt;High Availability architecture&lt;/LI&gt;
&lt;LI data-end="1674" data-start="1660" data-section-id="1gn1589"&gt;VPN topology&lt;/LI&gt;
&lt;LI data-end="1698" data-start="1675" data-section-id="1i6ukwo"&gt;External integrations&lt;/LI&gt;
&lt;LI data-end="1724" data-start="1699" data-section-id="14h2oz2"&gt;Management architecture&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1776" data-start="1726"&gt;The firewall is only one piece of the environment.&lt;/P&gt;
&lt;P data-end="1852" data-start="1778"&gt;Understanding how everything connects together makes planning much easier.&lt;/P&gt;
&lt;P data-end="1852" data-start="1778"&gt;&lt;STRONG&gt;&lt;U style="color: #000000; font-family: inherit; background-color: #ffffff;"&gt;Tip: Never leave the planning phase with unanswered questions. Every unanswered question has the potential to become a production issue during implementation.&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-end="2202" data-start="2020"&gt;&lt;STRONG data-end="2058" data-start="2020"&gt;One thing that still surprises me:&lt;/STRONG&gt; many environments still don't have an updated network topology diagram. Good documentation is one of the best investments any IT team can make.&lt;/P&gt;
&lt;HR data-end="2207" data-start="2204" /&gt;
&lt;H2 data-end="2257" data-start="2209" data-section-id="g0y76c"&gt;&lt;STRONG&gt;2. Spend More Time Planning Than Implementing&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P data-end="2381" data-start="2259"&gt;After understanding the environment, I start writing the Method of Procedure (MOP), or what we call the Executive Project.&lt;/P&gt;
&lt;P data-end="2422" data-start="2383"&gt;This is where I invest most of my time.&lt;/P&gt;
&lt;P data-end="2521" data-start="2424"&gt;A well-written implementation plan dramatically increases the chances of a successful deployment.&lt;/P&gt;
&lt;P data-end="2582" data-start="2523"&gt;My planning includes much more than firewall configuration.&lt;/P&gt;
&lt;P data-end="2607" data-start="2584"&gt;I verify items such as:&lt;/P&gt;
&lt;UL data-end="2819" data-start="2609"&gt;
&lt;LI data-end="2626" data-start="2609" data-section-id="1mbvmqy"&gt;Hardware models&lt;/LI&gt;
&lt;LI data-end="2639" data-start="2627" data-section-id="1oj22ke"&gt;Interfaces&lt;/LI&gt;
&lt;LI data-end="2654" data-start="2640" data-section-id="18kbe9b"&gt;Transceivers&lt;/LI&gt;
&lt;LI data-end="2667" data-start="2655" data-section-id="1g35yfq"&gt;Rack rails&lt;/LI&gt;
&lt;LI data-end="2688" data-start="2668" data-section-id="1668zsr"&gt;Power requirements&lt;/LI&gt;
&lt;LI data-end="2698" data-start="2689" data-section-id="77xdj8"&gt;Cabling&lt;/LI&gt;
&lt;LI data-end="2714" data-start="2699" data-section-id="za27qf"&gt;IP addressing&lt;/LI&gt;
&lt;LI data-end="2734" data-start="2715" data-section-id="1c3i6m0"&gt;Security policies&lt;/LI&gt;
&lt;LI data-end="2740" data-start="2735" data-section-id="1o4cr7"&gt;NAT&lt;/LI&gt;
&lt;LI data-end="2760" data-start="2741" data-section-id="acpgi8"&gt;VPN configuration&lt;/LI&gt;
&lt;LI data-end="2797" data-start="2761" data-section-id="1fih46f"&gt;Virtual machines (when applicable)&lt;/LI&gt;
&lt;LI data-end="2819" data-start="2798" data-section-id="1mj6tog"&gt;Rollback procedures&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="2840" data-start="2821"&gt;I also create both:&lt;/P&gt;
&lt;UL data-end="2899" data-start="2842"&gt;
&lt;LI data-end="2860" data-start="2842" data-section-id="xyq6d4"&gt;Current topology&lt;/LI&gt;
&lt;LI data-end="2899" data-start="2861" data-section-id="rhw0o2"&gt;Future topology after implementation&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-align-justify" data-end="3098" data-start="2901"&gt;Physical topology diagrams are just as important as logical ones. During implementation they help distinguish firewall issues from switching or cabling problems, making troubleshooting much faster.&lt;/P&gt;
&lt;HR data-end="3103" data-start="3100" /&gt;
&lt;H2 data-end="3146" data-start="3105" data-section-id="1u0xgx2"&gt;&lt;STRONG&gt;3. Study Before the Maintenance Window&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P data-end="3235" data-start="3148"&gt;Even after years of experience, I still review the implementation before every project.&lt;/P&gt;
&lt;P data-end="3247" data-start="3237"&gt;I revisit:&lt;/P&gt;
&lt;UL data-end="3369" data-start="3249"&gt;
&lt;LI data-end="3259" data-start="3249" data-section-id="1fr68l8"&gt;Commands&lt;/LI&gt;
&lt;LI data-end="3276" data-start="3260" data-section-id="xx0cao"&gt;Best practices&lt;/LI&gt;
&lt;LI data-end="3292" data-start="3277" data-section-id="1au0k3e"&gt;Documentation&lt;/LI&gt;
&lt;LI data-end="3317" data-start="3293" data-section-id="1uays03"&gt;Configuration examples&lt;/LI&gt;
&lt;LI data-end="3337" data-start="3318" data-section-id="1myxvk"&gt;Known limitations&lt;/LI&gt;
&lt;LI data-end="3353" data-start="3338" data-section-id="1ydjbnq"&gt;Upgrade paths&lt;/LI&gt;
&lt;LI data-end="3369" data-start="3354" data-section-id="w7nupu"&gt;Release notes&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="3453" data-start="3371"&gt;If there is something I might need during implementation, I prepare it beforehand.&lt;/P&gt;
&lt;P data-end="3474" data-start="3455"&gt;The goal is simple:&lt;/P&gt;
&lt;P data-end="3547" data-start="3476"&gt;Don't waste valuable maintenance window time searching for information.&lt;/P&gt;
&lt;HR data-end="3552" data-start="3549" /&gt;
&lt;H2 data-end="3603" data-start="3554" data-section-id="1ml49un"&gt;&lt;STRONG&gt;4. Always Keep Documentation Available Offline&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P data-end="3638" data-start="3605"&gt;This lesson came from experience.&lt;/P&gt;
&lt;P data-end="3691" data-start="3640"&gt;Not every data center has reliable Internet access.&lt;/P&gt;
&lt;P data-end="3748" data-start="3693"&gt;Some environments have no external connectivity at all.&lt;/P&gt;
&lt;P data-end="3830" data-start="3750"&gt;Before traveling to a customer site, I download everything that might be useful:&lt;/P&gt;
&lt;UL data-end="3938" data-start="3832"&gt;
&lt;LI data-end="3855" data-start="3832" data-section-id="71b1in"&gt;Administration Guides&lt;/LI&gt;
&lt;LI data-end="3877" data-start="3856" data-section-id="elypml"&gt;Installation Guides&lt;/LI&gt;
&lt;LI data-end="3891" data-start="3878" data-section-id="1myas7b"&gt;SK articles&lt;/LI&gt;
&lt;LI data-end="3907" data-start="3892" data-section-id="wy8sbm"&gt;Release Notes&lt;/LI&gt;
&lt;LI data-end="3913" data-start="3908" data-section-id="1o4c4a"&gt;MOP&lt;/LI&gt;
&lt;LI data-end="3938" data-start="3914" data-section-id="fyugv2"&gt;Customer documentation&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="4004" data-start="3940"&gt;Having everything available offline has saved me multiple times.&lt;/P&gt;
&lt;H2 data-end="4056" data-start="4011" data-section-id="1mrdxdi"&gt;&lt;STRONG&gt;5. Execution Is Where Preparation Pays Off&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P data-end="4094" data-start="4058"&gt;Implementation day can be stressful.&lt;/P&gt;
&lt;P data-end="4230" data-start="4096"&gt;Many projects involve critical infrastructure, maintenance windows, and environments where downtime has a significant business impact.&lt;/P&gt;
&lt;P data-end="4266" data-start="4232"&gt;It's normal to feel some pressure.&lt;/P&gt;
&lt;P data-end="4323" data-start="4268"&gt;That's exactly why I dedicate so much time to planning.&lt;/P&gt;
&lt;P data-end="4411" data-start="4325"&gt;When the maintenance window begins, I don't want to be thinking about what to do next.&lt;/P&gt;
&lt;P data-end="4492" data-start="4413"&gt;I want to execute a plan that has already been carefully designed and reviewed.&lt;/P&gt;
&lt;P data-end="4551" data-start="4494"&gt;Good preparation reduces stress and increases confidence.&lt;/P&gt;
&lt;HR data-end="5034" data-start="5031" /&gt;
&lt;H2 data-end="5053" data-start="5036" data-section-id="114wazr"&gt;&lt;STRONG&gt;Final Thoughts&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P data-end="5108" data-start="5055"&gt;Every engineer develops their own workflow over time.&lt;/P&gt;
&lt;P data-end="5265" data-start="5110"&gt;The process above isn't the only correct approach, but it's the one that has consistently worked for me across hundreds of Check Point deployment projects.&lt;/P&gt;
&lt;P data-end="5403" data-start="5267"&gt;Technical knowledge is essential, but successful implementations also depend on planning, documentation, communication, and preparation.&lt;/P&gt;
&lt;P data-end="5444" data-start="5405"&gt;I'm curious to hear from the community.&lt;/P&gt;
&lt;P data-end="5524" data-start="5446"&gt;&lt;STRONG data-end="5524" data-start="5446"&gt;What practices have helped you deliver successful Check Point deployments?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 02:09:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279760#M46582</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-07-16T02:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Five Habits That Improved My Check Point Deployments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279762#M46583</link>
      <description>&lt;P&gt;I agree with you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/93117"&gt;@israelfds95&lt;/a&gt;&amp;nbsp;, what you wrote is probably the best way to work, unfortunately, for my experience, most of the time&amp;nbsp; this approach is far from the reality, where the customer considers the installation of a firewall comparable to installing a PC.&lt;/P&gt;
&lt;P&gt;I like to prepare and planning every job before before pressing the keys on the keyboard, and I thing that all the five steps are the right way to work.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 06:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279762#M46583</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-07-16T06:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Five Habits That Improved My Check Point Deployments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279764#M46584</link>
      <description>&lt;P&gt;So true&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/93117"&gt;@israelfds95&lt;/a&gt;&amp;nbsp;, the return on investment in planning and scoping is huge.&lt;/P&gt;
&lt;P&gt;It save time and money and allows wins for customer, partners and check points.&lt;/P&gt;
&lt;P&gt;Environments today are more complex, so even more important.&lt;/P&gt;
&lt;P&gt;BR, Amit&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 07:58:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279764#M46584</guid>
      <dc:creator>Amit_Navon</dc:creator>
      <dc:date>2026-07-16T07:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Five Habits That Improved My Check Point Deployments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279805#M46588</link>
      <description>&lt;P&gt;Excellent post! &lt;BR /&gt;&lt;BR /&gt;One point I'd add is the importance of &lt;STRONG data-end="192" data-start="125"&gt;validating the architecture before validating the configuration&lt;/STRONG&gt;. In many deployment issues, the firewall isn't the root cause routing, asymmetric traffic, VLAN design, MTU, or external dependencies are. A well-defined MOP, rollback plan, and pre-validation checklist significantly reduce implementation risk and make troubleshooting much more efficient. Planning is often the biggest differentiator between a successful deployment and a long maintenance window.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 14:26:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279805#M46588</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-07-16T14:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Five Habits That Improved My Check Point Deployments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279928#M46599</link>
      <description>&lt;P&gt;100% echo: &amp;nbsp;"keep documentation offline"! &amp;nbsp;I have, and regularly update, my own repository of the Check Point documentation package AND the updated guides in that package. &amp;nbsp;This has been very beneficial. &amp;nbsp;I wish the writers would regularly update the complete package, perhaps quarterly. &amp;nbsp;It would be a significant quality improvement so we didn't have to go hunting for every admin guide.&lt;/P&gt;
&lt;P&gt;I also keep offline copies of numerous ATRGs and SK articles that I find relevant and subject to repeat visits. Same reasons as mentioned.&lt;/P&gt;
&lt;P&gt;I also 100% echo, and would extend: "no unanswered questions". &amp;nbsp;Ask EVERY question you can imagine, even for the smallest details (what type of ethernet cables, or fiber cables, are you using? Do your switches have auto-negotiation disabled? Do you need NEMA-5-15P cables, or C13? or now C19? How do you expect to handle authentication? Is TLS needed, and what ciphers?). &amp;nbsp;Try to imagine the stupidest scenario and most silly situation; someone has that configuration! &amp;nbsp; I tell my daughter: "if you can imagine it, someone somewhere has already done it". &amp;nbsp;Be very creative! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Indeed, have diagrams and documentation. &amp;nbsp;Your own creations will also go back into the customer's own documentation. &amp;nbsp;Multiple diagrams are advised: &amp;nbsp;Layer 1, Layer 2, and Layer 3. &amp;nbsp;These are not the same thing. &amp;nbsp;If you have the ability, also a Layer 7 diagram to show the expected application or process sequences, not just a wall of text describing it.&lt;/P&gt;
&lt;P&gt;Engineers follow a spec they were given; Architects go around kicking every rock and pebble looking for trouble. &amp;nbsp;Be an architect; if you're irritating everyone, then you're doing it the right way!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 16:46:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/279928#M46599</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2026-07-20T16:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Five Habits That Improved My Check Point Deployments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/280311#M46619</link>
      <description>&lt;P&gt;Its often that these kind of implementation documentation is saved in some sort of project.&lt;BR /&gt;Then when you need it 1-2 years later, its nowhere to be found as the engineers installed it has moved on.&lt;BR /&gt;&lt;BR /&gt;When doing planning, documentation etc&lt;BR /&gt;Do that in a system that is used within production for your documenation.&lt;BR /&gt;We for example uses Netbox for all the physical stuff and the things that is "non standard" to have it easily accessible in day to day operation when its time for the next upgrade / tshoot.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Ofc its good if your standard is then well documented, but i still find it more useful that you make sure to document things that was changed from default settings, IE: &lt;SPAN&gt;00-OS-XX.rules&amp;nbsp; / user.def or similar files.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 13:20:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Five-Habits-That-Improved-My-Check-Point-Deployments/m-p/280311#M46619</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2026-07-28T13:20:55Z</dc:date>
    </item>
  </channel>
</rss>

