- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Do you want to rename your gateways?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you want to rename your gateways?
Dear community,
for a very long time now I am now struggling with the fact that you can not easily rename objects that have a certificate/SIC from the management CA like gateways, clusters, CMAs, management servers etc.
Almost every 5 years we are changing our concept how to name network devices.
Without having the possibility to rename those objects without impact we have several naming concepts online which is very anoying and confusing.
I already opened an RFE, but the RFE was rejected.
So I would like to ask the community:
Am I the only one who has this need?
I would like to use this post to show Check Point that solving this issue will make a lot of people happier.
So please vote for change! 8)
Thanks
Sven
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are definitely NOT the only one lol. Im sure lots of people would like that implemented. Just curious, did they give a reason why RFE was rejected?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The guess is pretty easy. To rename a gateway object, you need to scratch all the certificates issues to it, and reset SIC. It is virtually impossible to do without an interruption. The infrastructure and architecture do not allow doing it any other way.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yeah, thats true.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How about working with two different fields within an object?
A name showed in the gui and a kind of UID that is used for certificates/SIC?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Sven_Glock
It's been a while, hope you're well 😃
Indeed this is challenging due to the above technical reasons, but I will take advantage of your post as an opportunity to challenge ourselves again and look into it, while also considering mitigations like the one you suggested, which is an interesting idea! As we're finalizing our plans and roadmap ahead, we'll have this in mind.
Eran
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Eran_Habad
I am happy to welcome you to my post 🤗
Thank you for taking this challenge.
It would be a pleasure if we could discuss the outcome of your plannings with a cold drink at CPX in Vienna!
Sven
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AFAIK you can reset SIC without interruption. sk86521 describes it for "normal" gateways.
From a technical point of view you can trust more then one certificate. CP can implement it, if the have the will......
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Mind the sk86521 does not cover the name change on the certificate. It allows you to reset SIC between a defined MGMT and GW objects, and that's it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I could not agree more @Daniel_
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have to admit it is inconvenient as you can not delight that management guy coming on with a new naming concept. But i can not understand why you call that an issue - regarding security, this is just n.a.p. 8) There surely are many much more important issues that really matter and would be good if fixed..
