<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change of Firewall Public IP and Endpoint Security VPN  in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31173#M13997</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try the mentioned SK but it did not work.&lt;/P&gt;&lt;P&gt;You could create a package in SCCM where you have to stop the Checkpoint Endpoint Connect Services and then change the trac.config.&lt;/P&gt;&lt;P&gt;This is nearly the same as upgrading to a new version or kill and recreate the Site with trac.exe.&lt;/P&gt;&lt;P&gt;It would be realy great if the Clients would also update their policy in the secure Network as they did with SecureClient.&lt;/P&gt;&lt;P&gt;The biggest problem are users, which didn't connect to the Site for months and do not have the actual policy.&lt;/P&gt;&lt;P&gt;If you try to do a trac.exe update it says you are in the internal network and do not need a connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Sep 2018 05:44:45 GMT</pubDate>
    <dc:creator>Jan_Kleinhans</dc:creator>
    <dc:date>2018-09-21T05:44:45Z</dc:date>
    <item>
      <title>Change of Firewall Public IP and Endpoint Security VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31167#M13991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have to change our WAN IP.&lt;/P&gt;&lt;P&gt;How do we configure the distributed Endpoint Security VPN-Clients?&lt;/P&gt;&lt;P&gt;I have tried to use the options:&lt;/P&gt;&lt;P&gt;enable_gw_resolving = true&lt;/P&gt;&lt;P&gt;automatic_mep_topology="false"&lt;/P&gt;&lt;P&gt;mep_mode="dns_based"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and changed the dns entry for our site but it always connects to the old IP and do not try to establish a link to the new ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another try where it seems to work is,&lt;/P&gt;&lt;P&gt;enable_gw_resolving = true&lt;/P&gt;&lt;P&gt;automatic_mep_topology="false"&lt;/P&gt;&lt;P&gt;mep_mode="primary_backup"&lt;/P&gt;&lt;P&gt;ips_of_gws_in_mep="ip_old&amp;amp;#ip_new&amp;amp;#"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to work (tried routing the old ip to blackhole and see connections to the new ip). But how do I get the configuration to clients not connecting frequently.&lt;/P&gt;&lt;P&gt;Is the only way to publish a new client with a new configuration?&lt;/P&gt;&lt;P&gt;The problem is, that we have 2 different authentication methods configured. If we deploy a new client with a new configuration, the users have to manualy change the authentication method.&lt;/P&gt;&lt;P&gt;I tried to run "trac.exe update" from inside the network. But it only says that the ressources are already available an does not update its configuration from trac_default.ttm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anybody that migrated to another ip with Endpoint Security Clients a tip?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2018 07:28:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31167#M13991</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2018-02-21T07:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Change of Firewall Public IP and Endpoint Security VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31168#M13992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume your users can delete/re-add the site?&lt;/P&gt;&lt;P&gt;That requires users doing something manually, of course, but it's an option.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2018 23:07:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31168#M13992</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-22T23:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Change of Firewall Public IP and Endpoint Security VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31169#M13993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you change the entry in the DNS server on the network you are connecting from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In NSLOOKUP do you see the new IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Adi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 08:45:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31169#M13993</guid>
      <dc:creator>Adi_Babai</dc:creator>
      <dc:date>2018-02-26T08:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Change of Firewall Public IP and Endpoint Security VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31170#M13994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I changed the DNS Entry on the local DNS Server on a remote network.&lt;/P&gt;&lt;P&gt;I could do a nslookup with the new ip address.&lt;/P&gt;&lt;P&gt;But I did not see a connection try to the new ip address in a tcpdump on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are now deploying a new configuration with primary and secondary MEP.&lt;/P&gt;&lt;P&gt;I hope that this will work when we change the IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 09:10:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31170#M13994</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2018-02-26T09:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Change of Firewall Public IP and Endpoint Security VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31171#M13995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We did it by deinstalling and installing the Client with SCCM and added the site by trac.exe. It does work but it is not a realy good way.&lt;/P&gt;&lt;P&gt;When you create the Site, there is no downloading of the Sites policy until the user connects the first time.&lt;/P&gt;&lt;P&gt;So Location Awareness does not work and the users always get the SDL Popup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the past, the old SecureClient fetched the policy when creating the site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 14:29:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31171#M13995</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2018-03-22T14:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Change of Firewall Public IP and Endpoint Security VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31172#M13996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I researched migration options for RA VPN and stumbled over this thread. &lt;/P&gt;&lt;P&gt;Jan, regarding the problem that you faced with the DNS change not making a difference to the IP the clients connected to, I think this SK might resolve the problem:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103440" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103440"&gt;How to force Remote Access VPN Client to resolve DNS name of VPN Site at every connection&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would the only thing required for an IP address migration not just be to push a new trac.config file with SCCM to all clients rather than reinstallation? I understand Jan's problem is now resolved but I wanted to continue the discussion on this matter in case anyone is interested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2018 13:40:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31172#M13996</guid>
      <dc:creator>Albert_Wilkes</dc:creator>
      <dc:date>2018-09-17T13:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Change of Firewall Public IP and Endpoint Security VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31173#M13997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did try the mentioned SK but it did not work.&lt;/P&gt;&lt;P&gt;You could create a package in SCCM where you have to stop the Checkpoint Endpoint Connect Services and then change the trac.config.&lt;/P&gt;&lt;P&gt;This is nearly the same as upgrading to a new version or kill and recreate the Site with trac.exe.&lt;/P&gt;&lt;P&gt;It would be realy great if the Clients would also update their policy in the secure Network as they did with SecureClient.&lt;/P&gt;&lt;P&gt;The biggest problem are users, which didn't connect to the Site for months and do not have the actual policy.&lt;/P&gt;&lt;P&gt;If you try to do a trac.exe update it says you are in the internal network and do not need a connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 05:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Change-of-Firewall-Public-IP-and-Endpoint-Security-VPN/m-p/31173#M13997</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2018-09-21T05:44:45Z</dc:date>
    </item>
  </channel>
</rss>

