Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sven_Glock
Advisor

Do you want to rename your gateways?

Dear community,

for a very long time now I am now struggling with the fact that you can not easily rename objects that have a certificate/SIC from the management CA like gateways, clusters, CMAs, management servers etc. 

Almost every 5 years we are changing our concept how to name network devices.

Without having the possibility to rename those objects without impact we have several naming concepts online which is very anoying and confusing.

I already opened an RFE, but the RFE was rejected.

So I would like to ask the community:
Am I the only one who has this need?

I would like to use this post to show Check Point that solving this issue will make a lot of people happier.

So please vote for change! 😎

Thanks
Sven

(4)
10 Replies
the_rock
Legend
Legend

You are definitely NOT the only one lol. Im sure lots of people would like that implemented. Just curious, did they give a reason why RFE was rejected?

Andy

0 Kudos
_Val_
Admin
Admin

The guess is pretty easy. To rename a gateway object, you need to scratch all the certificates issues to it, and reset SIC. It is virtually impossible to do without an interruption. The infrastructure and architecture do not allow doing it any other way. 

0 Kudos
the_rock
Legend
Legend

Yeah, thats true.

0 Kudos
Sven_Glock
Advisor

How about working with two different fields within an object?
A name showed in the gui and a kind of UID that is used for certificates/SIC?

(1)
Eran_Habad
Employee
Employee

Hi @Sven_Glock 

It's been a while, hope you're well 😃

Indeed this is challenging due to the above technical reasons, but I will take advantage of your post as an opportunity to challenge ourselves again and look into it, while also considering mitigations like the one you suggested, which is an interesting idea! As we're finalizing our plans and roadmap ahead, we'll have this in mind. 

Eran

 

Sven_Glock
Advisor

Hi @Eran_Habad 

I am happy to welcome you to my post 🤗

Thank you for taking this challenge. 
It would be a pleasure if we could discuss the outcome of your plannings with a cold drink at CPX in Vienna!

Sven

Daniel_
Advisor

AFAIK you can reset SIC without interruption. sk86521 describes it for "normal" gateways.

From a technical point of view you can trust more then one certificate. CP can implement it, if the have the will......

(1)
_Val_
Admin
Admin

Mind the sk86521 does not cover the name change on the certificate. It allows you to reset SIC between a defined MGMT and GW objects, and that's it.

0 Kudos
the_rock
Legend
Legend

I could not agree more @Daniel_ 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

I have to admit it is inconvenient as you can not delight that management guy coming on with a new naming concept. But i can not understand why you call that an issue - regarding security, this is just n.a.p. 😎 There surely are many much more important issues that really matter and would be good if fixed..

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events