@Anatoly. I understand. It is a best practice, not a requirement.
FYI: If the Main IP doesn't match the Gaia management interface IP, tools like this will fail, because $FWDIR/state/local/FW1/local.set and /etc/hosts don't have a match for the gateway object.
Key Considerations
Main IP in SmartConsole:
- This is the IP used for Secure Internal Communication (SIC) between the Security Management Server and the gateway.
- It should be reachable from the management server and typically corresponds to the interface used for management traffic.
Gaia Management Interface IP:
- This is the IP address used to access the Gaia Portal or CLI for system-level configuration.
- It may be on a different interface than the one used for SIC or policy installation.
Best Practice
Ideally, the Main IP in SmartConsole should match the IP of the interface used for management access, which is often the same as the Gaia management interface.
However, if your gateway has multiple interfaces and you manage it through a different one (e.g., internal vs external), the Main IP can be set to whichever interface is used for SIC and policy pushes.
Important Notes
If you change the Main IP in SmartConsole, you’ll need to:
- Reset and re-establish SIC
- Possibly renew VPN certificates
- Reinstall policies to ensure proper communication