- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hi,
I would like to understand how I can do this ip managament change on a checkpoint cluster:
It involves switching from a Vlan X, to a VLAN Y on another subnet
let's say the current configuration is:
VIP: 10.10.0.1
GW1: 10.10.0.2
GW2: 10.10.0.3
New Firewall IPs
VIP: 10.10.12.1
GW1: 10.10.12.2
GW2: 10.10.12.3
Currently the interface configuration of gw has as this ip 10.10.0.x
Side switch eth x (mgmt of the cluster) is connected on an interface put in access on the VLAN (the old one)
i want to keep the same interface but with the new IPs, how can I do it?
Below is EXACTLY how to do it and its 100% right 🙂
Andy
So the only way to change ip of cluster mgmt (keeping the same interface) is to connect to firewalls in console?
Not really, BUT, keep in mind, if thats how you web UI to the fw, then you would lose the access. Alternatively, you could change it from clich, but then again, if that is the IP you use to ssh into the appliance, same thing would happen.
Andy
I already tried to change the firewall management IP's (so to access it) GAIA side and I lost connectivity, rightly so, and you couldn't access it anymore, clish side also...
That's why I'm asking, if I wanted to change the IP of the firewall mgmt, maybe I'd better send someone physically there to connect in the console?
I know fisciamnete means physically lol. But yes, I agree 100%, better to do that.
Andy
Just have them follow that link exactly how it was described.
Andy
in case you decide to use another interface for mangemnte instead, it is not necessary to have someone connected in the console right?
Thats right
Though, personally, I would still make sure someone has access to the appliance physically, but thats just me.
Andy
I agree with that
thank, Andy
For what its worth, I NEVER even take a risk assuming installing jumbo will go 100% right and I dont say this in context of Check Point, I do this for any vendor (Cisco, PAN, Fortinet, etc...). I hope for the best, plan for the worst, so better be safe than sorry and have someone on site, JUST IN CASE.
Anyway, just my personal take on it.
Andy
Hey mate,
Were you able to get this done?
Andy
Hi Andy,
Not yet, I will almost certainly send a person to physically plug into the console.
K, sounds good!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 16 | |
| 15 | |
| 14 | |
| 9 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 |
Thu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!Thu 30 Oct 2025 @ 02:00 PM (EDT)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - AMERThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!Thu 30 Oct 2025 @ 02:00 PM (EDT)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - AMERWed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesThu 06 Nov 2025 @ 10:00 AM (CET)
CheckMates Live BeLux: Get to Know Veriti – What It Is, What It Does, and Why It MattersAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY