<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall replacement - consequences for VPN clients and how to handle it in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21923#M13639</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can see two things:&lt;/P&gt;&lt;P&gt;&amp;nbsp;- if you have no reason to delete the corresponding object in the Dahsboard (and I think you should not delete it): the certificate initialized at the creation step of this object in the dashboard will be kept and applied for the new physical hardware (just after the first policy installation).&lt;/P&gt;&lt;P&gt;&amp;nbsp;- you will not have to change anything on the trac.config file deployed on users' PC because you maintain the @IP or the hostname and you'll inherit of the 'old' certificate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 May 2018 13:15:28 GMT</pubDate>
    <dc:creator>XavierBens</dc:creator>
    <dc:date>2018-05-09T13:15:28Z</dc:date>
    <item>
      <title>Firewall replacement - consequences for VPN clients and how to handle it</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21920#M13636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Firewall replacement - consequences for VPN clients and how to handle it&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're going to replace our todays firewall and as I've understood you cannot create the new VPN client (Mobile VPN) until the new firewall object has been created and is up and running. We've done this on another location with mixed experience. Users were not prompted for new certificate not even after site has been deleted/re-created in the VPN client. The only solution we found for that site was to uninstall/re-install the VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we're going to replace the firewalls on a bigger site with hundreds of VPN clients connected. I would not like to re-install those clients as users are often on business trips and do not have local admin rights.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how to proceed with this the least painful way?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2018 07:19:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21920#M13636</guid>
      <dc:creator>andre_paulsen</dc:creator>
      <dc:date>2018-05-08T07:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall replacement - consequences for VPN clients and how to handle it</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21921#M13637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andre,&lt;/P&gt;&lt;P&gt;What do you mean exactly by "VPN Mobile"? RemoteAccess VPN client (also known as VPN Standalone client)? And what is the version?&lt;/P&gt;&lt;P&gt;And when you say firewall replacement: do you mean that you just change the hardware of an actual firewall without changing @IP addresses nor active blades?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2018 16:59:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21921#M13637</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2018-05-08T16:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall replacement - consequences for VPN clients and how to handle it</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21922#M13638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, and thanks for your reply. Sorry for being unclear about that, but yes it's the Remote Access VPN client where we choose ''Mobile VPN'' out of the three options (Endpoint Security, Mobile VPN, Secure Remote). We have different kinds of versions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, we are going to replace an Open Server with an Appliance where we keep the same external IP-address and all active blade.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I've understood the VPN client cannot be prepeared ahead of the firewall change and when the new firewall is up and running I'm afraid that we need to uninstall/re-install the VPN-client for our users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 07:56:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21922#M13638</guid>
      <dc:creator>andre_paulsen</dc:creator>
      <dc:date>2018-05-09T07:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall replacement - consequences for VPN clients and how to handle it</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21923#M13639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can see two things:&lt;/P&gt;&lt;P&gt;&amp;nbsp;- if you have no reason to delete the corresponding object in the Dahsboard (and I think you should not delete it): the certificate initialized at the creation step of this object in the dashboard will be kept and applied for the new physical hardware (just after the first policy installation).&lt;/P&gt;&lt;P&gt;&amp;nbsp;- you will not have to change anything on the trac.config file deployed on users' PC because you maintain the @IP or the hostname and you'll inherit of the 'old' certificate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 13:15:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21923#M13639</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2018-05-09T13:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall replacement - consequences for VPN clients and how to handle it</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21924#M13640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With replace, I mean replace one Open server with two appliances in cluster. This means that the object must be re-created. Sorry to be unclear about this to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply so far!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2018 14:31:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21924#M13640</guid>
      <dc:creator>andre_paulsen</dc:creator>
      <dc:date>2018-05-10T14:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall replacement - consequences for VPN clients and how to handle it</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21925#M13641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, so: yes off course you will have to delete the old object and create a cluster object including each of needed appliances. By that: you'll have to redo SIC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And, a new certificate will be generated and pushed at the first policy installation on each gateways' cluster.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But you can create on your own and then import it&lt;/STRONG&gt;. By that, you will be able to find its fingerprint and updating the trac.config of your clients before you're cutover.&lt;/P&gt;&lt;P&gt;You'll find it the IPSec VPN section of the cluster object, such as:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/65464_pastedImage_7.png" /&gt;&lt;/P&gt;&lt;P&gt;and you'll have to place it in the &lt;STRONG&gt;internal_ca_fingerprint&lt;/STRONG&gt; field of the trac.config file:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/65465_pastedImage_8.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2018 15:20:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21925#M13641</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2018-05-10T15:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall replacement - consequences for VPN clients and how to handle it</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21926#M13642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, Xavier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My main consern regarding this solution is editing the trac.config and if this is officially supported by checkpoint? Also what other lines in the trac.config must be added or inherited from the old trac.config. In addition we most likely have dozens of different versions of the VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand your solution would be to push the updated trac.config file to our clients with the help of GPO or similar?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 07:35:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21926#M13642</guid>
      <dc:creator>andre_paulsen</dc:creator>
      <dc:date>2018-05-14T07:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall replacement - consequences for VPN clients and how to handle it</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21927#M13643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In general, yes, you can edit trac.config.&lt;/P&gt;&lt;P&gt;There are several SKs that discuss doing exactly that.&lt;/P&gt;&lt;P&gt;That's not to say EVERY change to trac.config is supported of course &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2018 17:02:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Firewall-replacement-consequences-for-VPN-clients-and-how-to/m-p/21927#M13643</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-14T17:02:10Z</dc:date>
    </item>
  </channel>
</rss>

