- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Looking to upgrade management from R77.30 to R80.10. In QA I'm getting validation errors for the firewalls in bridge mode which have no IP addresses on the fail-open interfaces (so 0.0.0.0/0.0.0.0). I don't have the ability to push from QA so I need to confirm if this is an issue installing policy? I cant seem to find any documentation on it.

Those interfaces shouldn't have IPs on them for sure.
Which version of SmartConsole are you using?
Also, let me put this in https://community.checkpoint.com/community/management/policy-management?sr=search&searchId=d0b7782c-....
It's R80.10 SmartConsole Build 024
Hi, for this kind of problems I really recommend that you open a support ticket, so that Check Point support will be able to identify the root cause and see how this problem cannot happen for other customers as well.
Hi, You have to make sure that bridge interfaces are not a part of topology tab in Dashboard.
I believe you mean: not defining topology on the interface (i.e. not as internal or external).
My Bad) Topology still can be defined for single FW, but as I've said, in cluster, bridge interface do not part of topology tab at all and it is External by design. (Security Gateway R77 Versions Technical Administration Guide)
Having just installed a Mirror Port gateway on R80.10, the correct answer is: the mirror port should not be defined on the Gateway object at all.
When I fetched topology from my R80.10 Mirror Port gateway, the interface that was the mirror port did not even come across in the topology.
Further, your management Interface for the device should probably have the topology "Undefined" and Anti-Spoofing disabled.
Hi Dameon, this is expected as mirror port is only for POC/testing and it will get all traffic (external + internal) from the corresponding mirror port of the switch. So bridge interface and mirror port, though might seem to be similar, are quite different.
True, I misread ![]()
That said I wonder if a similar solution shouldn't apply.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY