- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
We all know how helpful "smartconsole changes (former workflow)" is when you make changes. It gives confidence and totally awareness of what configuration changes you make in the firewalls when you install a policy.
I am facing an issue at the moment with this feature.
When I add a new cluster interface in smarconsole and I run the "changes" functionality, smartconsole shows me not only the new interface addition but also it shows me other interfaces (active clusterxl interfaces in production ) to delete.
So it is quite disturbing, because this functionality is supposed to give you confidence in your change management process however it shows you changes that have nothing to do with the real changes that you have just done.
We have tested it in the lab and push these configuration changes and apparently smartconsole doesn't remove these interfaces in the gateways, but it is still quite configusing.
I would like to know if someone has seen something similar and/or someone knows how to troubleshoot it and find the root cause of this misleading behaviour.
I never had such a thing happen to me, either in R81.20 or R82. Can you send an example, ie screenshot? Just blur out any sensitive data.
Andy
It's consistent with the fact modifying gateway interfaces with the API requires you to add ALL interfaces to the gateway object if you make ANY interface changes.
SmartConsole does the same thing under the covers, which is why it shows in the Change Report the way it does.
On the plus side, R82 has APIs to manipulate individual interfaces associated with gateway objects.
When I tried to add an interface to an existing gateway on my system (and I also did a "Get Interfaces" without Topology), it did mention other interfaces were "edited" but only showed details about the one interface that WAS added.
It did note the other interfaces were "edited" with no details.
In short: this should be fixed in R82 for regular gateway objects only.
I suspect other types of gateways in R82 (Legacy VSX, SMB Gateways, ClusterXL gateways) will still have the same behavior that you asked about here, which appears to be expected behavior.
Hey Luis,
Its barelvy visible what you attached, do you have regular screenshot?
Andy
Have you zoomed in? You can see it very well, no?
Cant see it...
Andy
I have attached screenshots in the next post
I completely understand why this looks scary 🙂
Having said that, it's (very likely) expected in this case.
I would verify what could be different with other clusters.
Andy
Even if the behavior is somewhat different, the underlying cause is likely the same (namely how the backend handles updating interfaces in an existing gateway object).
You're in TAC case territory in any case.
Interface edited is one thing but interface about to be deleted is more concerning 😉
I was hoping that a R&D engineer/manager could read this post.
TAC was happy to reproduce the case and see that interface wasn't removed. But to me it is quite disturbing to see random live interfaces about to be deleted every time I create a new one. I think Checkpoint should try to find root cause.
Ask the TAC to open a CFG task to have this issue investigated.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
14 | |
12 | |
11 | |
9 | |
9 | |
7 | |
5 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY