- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi everyone,
We are planning to migrate our firewall management interface from an old subnet (e.g., 192.168.0.0/26) to a new one (e.g., 192.168.100.0/26), and I would like to ask for best practices to perform the change without losing connectivity to the firewall during the transition.
Current situation:
Static routes will be updated accordingly:
All current static routes pointing to 192.168.0.X will be switched to point to the new IP 192.168.100.10.
Question:
We identified two possible migration options, but we’re looking for advice on the safest path:
Option 1: Use a free physical interface (e.g., eth1-02)
Option 2: Reuse the existing interface by switching port mode to trunk
Objective:Perform the migration with no loss of connectivity, particularly for remote management and routing.
If anyone has gone through a similar migration or has specific recommendations (including hidden gotchas), your input would be highly appreciated!
Thanks in advance!
Typically a separate interface would likely be the pick of these.
Do the gateways have a working LOM or OOB console connection, are you attempting the changes remotely?
Hi @Chris_Atkinson
So you prefer using a separate interface rather than a trunk from the switch site.
Yes, we’re planning to make the change remotely.
If we proceed with the separate interface, should we expect any downtime?
There are details missing about your environment/ topology etc but converting the existing port to a trunk has a higher risk in my opinion.
why it's higher risk?
It just is namely because your proposing to make changes to the very port used to access the device and currently it's a clustered interface. But perhaps you have all the necessary mitigations in place.
What other traffic flows leverage the existing interface is it the "internal" LAN side port for all traffic or dedicated to MGMT currently?
If I wanted to use another interface as the Management one, would there be any downtime? (Also considering moving the old static routes from the old IP to the new IP)? Is there a procedure for this?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY