<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Discovering changes in topology table in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27774#M5664</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On existing production gateway or cluster,&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;the difference between "Get Interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;Without&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Topology" and "Get Interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;With&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Topology" is typically 2 to 4 hours of troubleshooting &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Seriously though, when you already have manually defined topology and antispoofing settings, the "With Topology" may wreck a havoc on your infrastructure. See this thread for example:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/11111"&gt;Cluster Sync lost after Get Interfaces with topology&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;It may also create a duplicate network objects.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Jan 2019 16:45:39 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2019-01-27T16:45:39Z</dc:date>
    <item>
      <title>Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27770#M5660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Checkmates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the difference between "Get Interface &lt;STRONG&gt;Without&lt;/STRONG&gt; Topology" and "Get Interface &lt;STRONG&gt;With&lt;/STRONG&gt; Topology"&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;What will firs and what will second option do ?&lt;/P&gt;&lt;P&gt;When to use "Get Interface &lt;STRONG&gt;With&lt;/STRONG&gt; Topology" and when&amp;nbsp;&lt;SPAN&gt;"Get Interface&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Without&lt;/STRONG&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Topology" in discovering topology changes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have R80.20&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2019 10:08:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27770#M5660</guid>
      <dc:creator>s_milidrag</dc:creator>
      <dc:date>2019-01-27T10:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27771#M5661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Slobodan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The get Interfaces with topology option will interrogate the gateway to retrieve the interfaces, it will also calculate the topology and also set the interfaces (this network only etc) for the purposes of anti-spoofing based on the routing table .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using only the "Get Interfaces without topology" will get all interfaces without changing your existing topology.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From experience I only use the "with" option when configuring a new gateway. As performing a topology get on an existing gateway/cluster may change your desired topology if you have set some specific spoofing groups up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally I like to control the topology and will more than likely make changes to the topology even when using the "with topology:" option.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2019 11:15:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27771#M5661</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-01-27T11:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27772#M5662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Mark,&lt;/P&gt;&lt;P&gt;I've noticed in a case I have changes in routing (add static routes) and run&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;"Get Interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold;"&gt;Without&lt;/STRONG&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Topology", gateway will not update topology table, so I need to run&amp;nbsp;&lt;SPAN&gt;"Get Interface&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;With&lt;/STRONG&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Topology"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2019 12:05:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27772#M5662</guid>
      <dc:creator>s_milidrag</dc:creator>
      <dc:date>2019-01-27T12:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27773#M5663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Happy to help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, if you are using the "Determine Topology based on route table" setting under the gateway/cluster that is correct otherwise then topology needs to be defined manually .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2019 12:10:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27773#M5663</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-01-27T12:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27774#M5664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On existing production gateway or cluster,&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;the difference between "Get Interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;Without&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Topology" and "Get Interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;With&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Topology" is typically 2 to 4 hours of troubleshooting &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Seriously though, when you already have manually defined topology and antispoofing settings, the "With Topology" may wreck a havoc on your infrastructure. See this thread for example:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/11111"&gt;Cluster Sync lost after Get Interfaces with topology&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;It may also create a duplicate network objects.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2019 16:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27774#M5664</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-01-27T16:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27775#M5665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I totally agree.&lt;/P&gt;&lt;P&gt;The safest way is to choose "without topology" for existing devices. If there are some legacy configurations, if some part of the network is not documented, if there are many people managing firewalls, if there are just many vlans, better to just add manually the new network to the group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, adding to duplicate objects, you can have some naming convention that this automatic retreival will not care about, of course.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Jan 2019 22:13:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27775#M5665</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2019-01-27T22:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27776#M5666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Slobodan, even though this might look fancy and is easy when you add routes, however, did you see how these networks are created in the objects database? Irrelevant if the network already exists or not a new network object is created in a semi-hidden state. What I mean by that is that you cannot add that network to a access rule or a group as it just does not show up in the listing. So later on when that network is removed from your environment, your stuck with a hidden object for a non existing network.&lt;/P&gt;&lt;P&gt;In a network with many changes this is not something you want&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifically in Cluster environments I would not use the With topology option, as mentioned by&amp;nbsp; &lt;A href="https://community.checkpoint.com/migrated-users/47844"&gt;Vladimir Yakovlev&lt;/A&gt;&amp;nbsp;below.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2019 18:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/27776#M5666</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-01-28T18:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/79942#M16200</link>
      <description>&lt;P&gt;Hi Vladimir,&lt;/P&gt;&lt;P&gt;So what happens if you don't use neither of the options, but just create manually and then policy push?&lt;BR /&gt;When testing this, it seems like the topology information where specific groups were defined before adding new VLAN interface are now disappeared and I am seeing anti-spoofing blocks on entirely different interfaces than the new ones I added..&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;KC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 10:11:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/79942#M16200</guid>
      <dc:creator>Support_Team_Pi</dc:creator>
      <dc:date>2020-03-27T10:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/184862#M30799</link>
      <description>&lt;P&gt;What is difference between clicking get interfaces without Topology and to add interface manually? As i understand, they sound same to me.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 02:45:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/184862#M30799</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2023-06-27T02:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/184988#M30820</link>
      <description>&lt;P&gt;Get Interfaces (without topology) will automatically define any interfaces that don't exist.&lt;BR /&gt;It will not define the topology settings for new interfaces nor will it disrupt the topology configuration that exists for other interaces.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 19:58:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/184988#M30820</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-27T19:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/185488#M30931</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please confirm that there is downtime if &lt;SPAN&gt;Get Interfaces with topology is used,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Existing interfaces will be not reachable until the process is completed (Get Interfaces with topology )&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 17:21:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/185488#M30931</guid>
      <dc:creator>Tal009988</dc:creator>
      <dc:date>2023-07-03T17:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/185509#M30935</link>
      <description>&lt;P&gt;The issue with Get Interfaces with Topology won't cause an outage.&lt;BR /&gt;It will, however, reset the topology configuration and possibly create extra objects in the process.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 20:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/185509#M30935</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-03T20:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/206205#M34201</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;I got a question please regarding the network defined by routes!&lt;/P&gt;&lt;P&gt;Currently my setup is to add the manual static routes on the firewalls and then do a get interface with topology! By doing this I am getting a lot of hidden duplicated object which I want to avoid that. (sk126872)&lt;/P&gt;&lt;P&gt;We are changing our routing from static to dynamic in the next few month and I was wondering if I use the option&amp;nbsp;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;Network defined by routes&amp;nbsp;&lt;/STRONG&gt;will I still have duplicated object created ? if yes, what is the best approach to avoid this? as I understand using the option specific with a manually created network groups is mainly for static routes right?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I also saw this in the documentation&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;When the &lt;STRONG&gt;Network defined by routes&lt;/STRONG&gt; option is selected along with &lt;STRONG&gt;Perform Anti-Spoofing based on interface topology&lt;/STRONG&gt;, you get &lt;I&gt;Dynamic Anti-Spoofing&lt;/I&gt;. The valid IP addresses range is automatically calculated without the administrator having to do click &lt;STRONG&gt;Get Interfaces&lt;/STRONG&gt; or install a policy&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Regards,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Alissone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Feb 2024 16:38:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/206205#M34201</guid>
      <dc:creator>alissone007</dc:creator>
      <dc:date>2024-02-15T16:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/206331#M34229</link>
      <description>&lt;P&gt;By using the Network Defined By Routes option, you do not have to define the topology (and no duplicate objects are created).&lt;BR /&gt;This feature will work with either dynamic or static routes.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 19:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/206331#M34229</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-16T19:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Discovering changes in topology table</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/206343#M34230</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;This is definitely the best explanation from the smart console help page.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/ZvkmnUK_XluBBIIAw1mF3A2.htm?cshid=ZvkmnUK_XluBBIIAw1mF3A2" target="_blank"&gt;Interface - Topology Settings (checkpoint.com)&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Understanding Topology&lt;/H2&gt;
&lt;P&gt;An interface can be defined as being External (leading to the Internet) or Internal (leading to the LAN).&lt;/P&gt;
&lt;P&gt;The type of network that the interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Leads To&lt;/SPAN&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Internet (External)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;This Network (Internal)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This is the default setting. It is automatically calculated from the topology of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. To update the topology of an internal network after changes to static routes, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Network Management&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Get Interfaces&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;General Properties&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Override&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Override the default setting.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Override&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the default setting:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Internet (External)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- All external/Internet addresses&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;This Network (Internal)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Not Defined&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- All IP addresses behind this interface are considered a part of the internal network that connects to this interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Network defined by the interface IP and Net Mask&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Only the network that directly connects to this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Network defined by routes&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;dynamically calculates the topology behind this interface. If the network changes, there is no need to click "Get Interfaces" and install a policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Specific&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- A specific network object (a network, a host, an address range, or a network group) behind this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Interface leads to DMZ&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The DMZ that directly connects to this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;VPN Tunnel Interfaces&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If the interface is part of a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/ZvkmnUK_XluBBIIAw1mF3A2.htm?cshid=ZvkmnUK_XluBBIIAw1mF3A2#" data-mc-state="closed" data-aria-describedby="bdfc4682-1859-4808-8958-5f3943456148" target="_blank"&gt;VPN Tunnel&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="the_rock_0-1708113494630.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24542i58B70B0E2CE0DF42/image-size/medium?v=v2&amp;amp;px=400" role="button" title="the_rock_0-1708113494630.gif" alt="the_rock_0-1708113494630.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;, then the interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Leads To&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Point to Point&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;network. The interface is one end of the point to point connection. All traffic in the network behind the interface is part of the point to point connection. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Override&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to define a specific network.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2024 19:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Discovering-changes-in-topology-table/m-p/206343#M34230</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-16T19:58:29Z</dc:date>
    </item>
  </channel>
</rss>

