Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cdooer
Contributor
Jump to solution

Best way to deploy remote EOL devices

Hey folks. We've got a number of 5000 series appliances that are coming up on EOL, and we need to replace them. In some cases, the devices are remote, with no technical staff nearby to support them. Is the easiest way simply to configure them with the proper IP's and SIC info, have the onsite person rack and cable it, shut the old one off and bring the new one online, SIC it and push a policy to it?

My only concern is that we've sometimes seen a new firewall load the local policy upon startup, and block all access to it. I see something called SmartProvisioning...would this work in our scenario? Running R81.10.

Thx in advance. 

1 Solution

Accepted Solutions
the_rock
MVP Platinum
MVP Platinum

You could use smart provision, though needs separate license, I believe.

https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SmartProvisioning_AdminGuide...

Now, for local (aka initial policy), keep in mind, it STILL allows access to port 443 and ssh via implied rules, so that would work as well. Honestly, person on site does not even need to be that technical, as long as they know how to navigate through device manager if console is needed and connect console cable, thats it.

Best,
Andy

View solution in original post

0 Kudos
7 Replies
the_rock
MVP Platinum
MVP Platinum

You could use smart provision, though needs separate license, I believe.

https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SmartProvisioning_AdminGuide...

Now, for local (aka initial policy), keep in mind, it STILL allows access to port 443 and ssh via implied rules, so that would work as well. Honestly, person on site does not even need to be that technical, as long as they know how to navigate through device manager if console is needed and connect console cable, thats it.

Best,
Andy
0 Kudos
cdooer
Contributor

Thx Andy, I guess the best way is to just keep it simple, and maybe make sure to include a console cable when they ship. Thx for the advice.

the_rock
MVP Platinum
MVP Platinum

You know, remind me of chat I had with great guy last week, he lives in the same city as me, works for Canadian government, I said to him "You know Rob, cloud is the future" and he says "Is it really, Andy?" haha

Im starting to think maybe he is right, look at outages that happened recently, Azure, WS, now Cloudflare...sometimes, old school is the best, console and pen and paper 🤣

Best,
Andy
0 Kudos
cdooer
Contributor

Couldn't agree more. PS I also live in a Canadian city with a very heavy dose of government employees...wonder if it's the same one. lol

the_rock
MVP Platinum
MVP Platinum

Ottawa? lol

Best,
Andy
0 Kudos
cdooer
Contributor

Yessir.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

You may know him then, haha

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events