<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Change gateway IP address (Centrally managed) in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255621#M13138</link>
    <description>&lt;P&gt;I'm looking to change my WAN IP address on an SMB Gateway (although I think the process is the same on normal Gateway also)&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done this before but some time ago. If I recall, this was the processed I followed.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Push a firewall policy to the gateway with Source: SMS -&amp;gt; Dst: New IP range that will be configured on the firewall&lt;/LI&gt;&lt;LI&gt;Log on locally to the Gateway, and change the IP address, and default route.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Log on to SMS and change the Gateway IP, and IP address in topology&lt;/LI&gt;&lt;LI&gt;Push the policy&lt;/LI&gt;&lt;LI&gt;Delete the temporary firewall policy&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Have I missed anything out here?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did this once without doing step one and I think I locked myself out of the firewall. Hypothetically in this instance you would need to do an "fw unloadlocal" , then push the policy again right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 21 Aug 2025 08:34:24 GMT</pubDate>
    <dc:creator>velo</dc:creator>
    <dc:date>2025-08-21T08:34:24Z</dc:date>
    <item>
      <title>Change gateway IP address (Centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255621#M13138</link>
      <description>&lt;P&gt;I'm looking to change my WAN IP address on an SMB Gateway (although I think the process is the same on normal Gateway also)&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have done this before but some time ago. If I recall, this was the processed I followed.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Push a firewall policy to the gateway with Source: SMS -&amp;gt; Dst: New IP range that will be configured on the firewall&lt;/LI&gt;&lt;LI&gt;Log on locally to the Gateway, and change the IP address, and default route.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Log on to SMS and change the Gateway IP, and IP address in topology&lt;/LI&gt;&lt;LI&gt;Push the policy&lt;/LI&gt;&lt;LI&gt;Delete the temporary firewall policy&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Have I missed anything out here?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did this once without doing step one and I think I locked myself out of the firewall. Hypothetically in this instance you would need to do an "fw unloadlocal" , then push the policy again right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 08:34:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255621#M13138</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2025-08-21T08:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Change gateway IP address (Centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255669#M13140</link>
      <description>&lt;P&gt;You've got this more or less correct, and yes fw unloadlocal might be necessary.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 16:48:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255669#M13140</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-21T16:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Change gateway IP address (Centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255720#M13142</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 08:52:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255720#M13142</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2025-08-22T08:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Change gateway IP address (Centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255738#M13144</link>
      <description>&lt;P&gt;For what is worth, since AI seems to be part of every day life these days, here you go : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;*******************************&lt;/P&gt;
&lt;H3 data-start="295" data-end="354"&gt;Typical steps to change WAN IP on a Check Point Gateway&lt;/H3&gt;
&lt;OL data-start="356" data-end="1452"&gt;
&lt;LI data-start="356" data-end="655"&gt;
&lt;P data-start="359" data-end="400"&gt;&lt;STRONG data-start="359" data-end="398"&gt;Pre-change policy rule (good call!)&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="404" data-end="655"&gt;
&lt;LI data-start="404" data-end="553"&gt;
&lt;P data-start="406" data-end="553"&gt;Add a temporary rule allowing management traffic (SmartConsole / SIC / SSH, etc.) from your SMS (Security Management Server) to the &lt;EM data-start="538" data-end="543"&gt;new&lt;/EM&gt; WAN IP.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="557" data-end="576"&gt;
&lt;P data-start="559" data-end="576"&gt;Install policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="580" data-end="655"&gt;
&lt;P data-start="582" data-end="655"&gt;This makes sure once the gateway is re-addressed, you can still reach it.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="657" data-end="951"&gt;
&lt;P data-start="660" data-end="701"&gt;&lt;STRONG data-start="660" data-end="699"&gt;Change the IP on the gateway itself&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="705" data-end="951"&gt;
&lt;LI data-start="705" data-end="794"&gt;
&lt;P data-start="707" data-end="794"&gt;On SMB appliances: done via WebUI or CLI (&lt;CODE data-start="749" data-end="764"&gt;set interface&lt;/CODE&gt;, &lt;CODE data-start="766" data-end="784"&gt;set static-route&lt;/CODE&gt;, etc.).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="798" data-end="886"&gt;
&lt;P data-start="800" data-end="886"&gt;On Gaia: via &lt;CODE data-start="813" data-end="820"&gt;clish&lt;/CODE&gt; or WebUI (update interface IP, update default route if needed).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="890" data-end="951"&gt;
&lt;P data-start="892" data-end="951"&gt;Verify routing so return traffic goes back via the new WAN.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="953" data-end="1169"&gt;
&lt;P data-start="956" data-end="1004"&gt;&lt;STRONG data-start="956" data-end="1002"&gt;Update the object/topology in SmartConsole&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="1008" data-end="1169"&gt;
&lt;LI data-start="1008" data-end="1083"&gt;
&lt;P data-start="1010" data-end="1083"&gt;Edit the Gateway object → update external interface IP(s) and topology.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1087" data-end="1158"&gt;
&lt;P data-start="1089" data-end="1158"&gt;Make sure the new IP is correctly marked as “External” if relevant.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1162" data-end="1169"&gt;
&lt;P data-start="1164" data-end="1169"&gt;Save.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="1171" data-end="1337"&gt;
&lt;P data-start="1174" data-end="1197"&gt;&lt;STRONG data-start="1174" data-end="1195"&gt;Push policy again&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="1201" data-end="1337"&gt;
&lt;LI data-start="1201" data-end="1257"&gt;
&lt;P data-start="1203" data-end="1257"&gt;Install policy to the gateway with updated topology.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1261" data-end="1337"&gt;
&lt;P data-start="1263" data-end="1337"&gt;Verify SIC trust if needed (if management IP is changing, see note below).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI data-start="1339" data-end="1452"&gt;
&lt;P data-start="1342" data-end="1356"&gt;&lt;STRONG data-start="1342" data-end="1354"&gt;Clean up&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL data-start="1360" data-end="1452"&gt;
&lt;LI data-start="1360" data-end="1410"&gt;
&lt;P data-start="1362" data-end="1410"&gt;Remove the temporary rule you added in Step 1.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1414" data-end="1452"&gt;
&lt;P data-start="1416" data-end="1452"&gt;Push policy again to tidy things up.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-start="1454" data-end="1457" /&gt;
&lt;H3 data-start="1459" data-end="1505"&gt;Common gotchas / additional considerations&lt;/H3&gt;
&lt;UL data-start="1507" data-end="2234"&gt;
&lt;LI data-start="1507" data-end="1844"&gt;
&lt;P data-start="1509" data-end="1844"&gt;&lt;STRONG data-start="1509" data-end="1532"&gt;Management (SIC) IP&lt;/STRONG&gt;&lt;BR data-start="1532" data-end="1535" /&gt;If the management server itself talks to the gateway over this WAN IP, you’ll need to update the gateway’s “General Properties” → “IP Address” field to the new one. Otherwise SIC trust will break.&lt;BR data-start="1734" data-end="1737" /&gt;&lt;EM data-start="1740" data-end="1844"&gt;If management connectivity is via another interface (e.g. internal LAN), you don’t need to worry here.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1846" data-end="1984"&gt;
&lt;P data-start="1848" data-end="1984"&gt;&lt;STRONG data-start="1848" data-end="1861"&gt;NAT rules&lt;/STRONG&gt;&lt;BR data-start="1861" data-end="1864" /&gt;If the old WAN IP was explicitly used in NAT rules (static NATs, hide behind, etc.), you’ll need to update those too.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1986" data-end="2119"&gt;
&lt;P data-start="1988" data-end="2119"&gt;&lt;STRONG data-start="1988" data-end="2005"&gt;Anti-Spoofing&lt;/STRONG&gt;&lt;BR data-start="2005" data-end="2008" /&gt;Double-check anti-spoofing settings on the external interface. The new WAN subnet should be reflected there.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2121" data-end="2234"&gt;
&lt;P data-start="2123" data-end="2234"&gt;&lt;STRONG data-start="2123" data-end="2134"&gt;Routing&lt;/STRONG&gt;&lt;BR data-start="2134" data-end="2137" /&gt;Make sure the new default route points correctly, otherwise you’ll lose outbound connectivity.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="2236" data-end="2239" /&gt;
&lt;H3 data-start="2241" data-end="2289"&gt;Your question about “lockout” and recovery&lt;/H3&gt;
&lt;P data-start="2291" data-end="2393"&gt;Yes — if you forget to allow traffic to the new IP in advance, you can absolutely lock yourself out.&lt;/P&gt;
&lt;P data-start="2395" data-end="2415"&gt;On a Gaia gateway:&lt;/P&gt;
&lt;UL data-start="2416" data-end="2651"&gt;
&lt;LI data-start="2416" data-end="2485"&gt;
&lt;P data-start="2418" data-end="2485"&gt;You’d need console access (serial/ILO/DRAC/VM console) to get in.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2486" data-end="2599"&gt;
&lt;P data-start="2488" data-end="2599"&gt;Run &lt;CODE data-start="2492" data-end="2508"&gt;fw unloadlocal&lt;/CODE&gt; — that unloads the policy and leaves only the implicit accept (basically open firewall).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2600" data-end="2651"&gt;
&lt;P data-start="2602" data-end="2651"&gt;Fix the interface, topology, push policy again.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="2653" data-end="2675"&gt;On an SMB appliance:&lt;/P&gt;
&lt;UL data-start="2676" data-end="2757"&gt;
&lt;LI data-start="2676" data-end="2757"&gt;
&lt;P data-start="2678" data-end="2757"&gt;Similar idea, but you’d use WebUI/CLI locally to reset policy if it blocks you.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-start="2759" data-end="2762" /&gt;
&lt;P data-start="2764" data-end="2847"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG data-start="2766" data-end="2814"&gt;So your original steps are basically correct&lt;/STRONG&gt; — the only extras I’d add are:&lt;/P&gt;
&lt;UL data-start="2848" data-end="3023"&gt;
&lt;LI data-start="2848" data-end="2881"&gt;
&lt;P data-start="2850" data-end="2881"&gt;Update anti-spoofing settings&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2882" data-end="2922"&gt;
&lt;P data-start="2884" data-end="2922"&gt;Update any NATs involving the old IP&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2923" data-end="3023"&gt;
&lt;P data-start="2925" data-end="3023"&gt;Be mindful of SIC/management connectivity if SMS → gateway communication depended on that WAN IP&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 22 Aug 2025 12:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/255738#M13144</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-22T12:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Change gateway IP address (Centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/256029#M13162</link>
      <description>&lt;P&gt;Thanks for that Andy.&lt;/P&gt;&lt;P&gt;The problem with AI is that it often just makes up things which are not true.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 08:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/256029#M13162</guid>
      <dc:creator>velo</dc:creator>
      <dc:date>2025-08-27T08:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Change gateway IP address (Centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/256041#M13164</link>
      <description>&lt;P&gt;Well, it was invented by humans lol&lt;/P&gt;</description>
      <pubDate>Wed, 27 Aug 2025 10:23:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Change-gateway-IP-address-Centrally-managed/m-p/256041#M13164</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-27T10:23:53Z</dc:date>
    </item>
  </channel>
</rss>

