Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
MVP Silver
MVP Silver
Jump to solution

Dependencies in FW Configuration

Hello everyone,
Whenever a change is made at the routing level (dynamic or static) on a firewall managed by an SMS or a CMA from an MDS… or, for example, when modifying NTP/SNMP settings…
Is it ‘mandatory’ to implement policies?
Or is the change simply made on the firewall and the implementation ignored?
Thank you for your clarification.

0 Kudos
1 Solution

Accepted Solutions
Lesley
MVP Platinum
MVP Platinum

Virtual Systems support:

OSPF

RIP

BGP

PIM

Static routes, you change via Smart Console. But if you want to change SNMP / NTP or other gaia config it is local gaia CLISH and no push needed. Indeed save config

-------
Please press "Accept as Solution" if my post solved it 🙂

View solution in original post

0 Kudos
(1)
7 Replies
Chris_Atkinson
MVP Diamond CHKP MVP Diamond CHKP
MVP Diamond CHKP

For static routing changes in VSX yes.

Other changes typically only require policy to be pushed if the policy needs to be updated to take the settings change into account to allow the traffic to pass including things like anti-spoofing etc.

CCSM R77/R80/ELITE
0 Kudos
Matlu
MVP Silver
MVP Silver

Hello,
In a ‘traditional environment’ without VSX, if you need to work with BGP,
I plan to carry out the configuration via my firewall’s CLI, but once I’ve finished doing that, do I need to install policies from the MDS?
Thank you.

0 Kudos
Lesley
MVP Platinum
MVP Platinum

If you change BGP routing via local GAIA clish no policy push is needed from MGMT.

If you change the NTP servers in GAIA no push is needed.

BUT if there is a rule that the firewall uses to reach the NTP server it needs to be changed. 

Source: Firewall , destination: NTP server old port 123

A policy push is to change this rule policy. It does not tell the firewall to change the GAIA config or something. All changes in GAIA config are active after you do save config, no push needed

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
Matlu
MVP Silver
MVP Silver

Hey Lesley
Just for the record:
This logic applies in the same way in VS environments, doesn’t it?
Let’s imagine I have four VS's on my VSX, and on one of them I’m using BGP whilst on another I’m using OSPF, and I make changes to the configuration via the CLI…
Is it enough just to run ‘save config’ on the configuration I’ve made, right?
There’s no need to send policies for installation

0 Kudos
Lesley
MVP Platinum
MVP Platinum

Virtual Systems support:

OSPF

RIP

BGP

PIM

Static routes, you change via Smart Console. But if you want to change SNMP / NTP or other gaia config it is local gaia CLISH and no push needed. Indeed save config

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
(1)
Bob_Zimmerman
MVP Gold
MVP Gold

Generally, yes. With VSX, some things must be done through the CLI (dynamic routing, bonding), while others must be done through SmartConsole (static routes, interface IP/mask changes, VLANs). Certain interface changes need a policy push simply because antispoofing is part of the policy.

Routing changes (whether static or dynamic) never need a policy push to take effect. They may send traffic through different paths, which could cause it to no longer match existing rules (for example, if you change the route to a destination, it might be in a different zone), and it can take a policy push to fix that, but that's technically not part of the routing change.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events