- CheckMates
- :
- Products
- :
- General Topics
- :
- change management's ip of cluster
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
change management's ip of cluster
Hi,
I would like to understand how I can do this ip managament change on a checkpoint cluster:
It involves switching from a Vlan X, to a VLAN Y on another subnet
let's say the current configuration is:
VIP: 10.10.0.1
GW1: 10.10.0.2
GW2: 10.10.0.3
New Firewall IPs
VIP: 10.10.12.1
GW1: 10.10.12.2
GW2: 10.10.12.3
Currently the interface configuration of gw has as this ip 10.10.0.x
Side switch eth x (mgmt of the cluster) is connected on an interface put in access on the VLAN (the old one)
i want to keep the same interface but with the new IPs, how can I do it?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Below is EXACTLY how to do it and its 100% right 🙂
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So the only way to change ip of cluster mgmt (keeping the same interface) is to connect to firewalls in console?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not really, BUT, keep in mind, if thats how you web UI to the fw, then you would lose the access. Alternatively, you could change it from clich, but then again, if that is the IP you use to ssh into the appliance, same thing would happen.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I already tried to change the firewall management IP's (so to access it) GAIA side and I lost connectivity, rightly so, and you couldn't access it anymore, clish side also...
That's why I'm asking, if I wanted to change the IP of the firewall mgmt, maybe I'd better send someone physically there to connect in the console?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know fisciamnete means physically lol. But yes, I agree 100%, better to do that.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just have them follow that link exactly how it was described.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
in case you decide to use another interface for mangemnte instead, it is not necessary to have someone connected in the console right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thats right
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Though, personally, I would still make sure someone has access to the appliance physically, but thats just me.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with that
thank, Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For what its worth, I NEVER even take a risk assuming installing jumbo will go 100% right and I dont say this in context of Check Point, I do this for any vendor (Cisco, PAN, Fortinet, etc...). I hope for the best, plan for the worst, so better be safe than sorry and have someone on site, JUST IN CASE.
Anyway, just my personal take on it.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey mate,
Were you able to get this done?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Andy,
Not yet, I will almost certainly send a person to physically plug into the console.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
K, sounds good!
