We are planning to change the IP address of the SMS and management IP addresses on all gateways because the old management network is complex and we want to create a single firewall management network with all gateways and SMS. The idea is to create the new management network in parallel for ease of rollback.
To be able to do that we want to perform the following steps:
1) change the SMS IP address following this article, making sure the gateways <-> SMS comms are allowed, I believe it would be best to simply add interface in Gaia and then change it in Smartconsole (without loosing connectivity)
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
usign the command cpca_client lscert -kind SIC -stat Valid I confirm that most important ICA certs are valid until 2024
2) change the IP address on each gateway by adding a new interface in Gaia with the new management network and add to the topology.
One question here is do we need to define this new interface in Gaia interface settings there is a feature called set management interface, what does it actually do and is this required to change it?
Do we need to configure this new interface as private in Smartconsole so it wont perform any cluster link state monitoring on this management interface?
3) perform SIC reset on each gateway using this procedure (norestart) to be able to renew the ICA cert IP to the new management IP
I believe this would be the least impactful procedure to include all into the new network management subnet and would this renew the ICA certs?
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Thanks in advance.