Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Pawel_
Explorer

Get interfaces or manually add an interface - is there any difference?

Hi Team,

I'd like to understand if there is any functional difference between adding interfaces in Network Topology manually against using 'Get Interfaces' feature.

We used to add all interfaces manually. It worked, no issues.

Recently I tried to create a GRE tunnel on a cluster (R81.20). I followed sk169794. The only difference was that I added GRE interfaces manually instead of using 'Get Interfaces with Topology'.

GRE tunnel was up and running however all GRE packets sent by a cluster member were sent with the active cluster member physical interface IP as a source, not VIP.

I've been told that running 'Get Interfaces with Topology' and installing policy should solve the issue. I ran 'Get Interfaces with Topology' however that created about a hundred configuration changes and I'm not happy to publish them.

I always believed that 'Get Interfaces' is a helpful shortcut used to make all interface name/ip/spoofing group/etc creation easier. Is there anything else that happens behind the scene?

Regards,

Pawel

0 Kudos
8 Replies
PhoneBoy
Admin
Admin

I fail to see how Get Interfaces with Topology would resolve this issue.
I assume Cluster NAT isn't happening on GRE traffic.

0 Kudos
Pawel_
Explorer

Thank you for the reply.

That's exactly what I thought and I wasn't happy to follow the support recommendation and mess up my current config.

I had also created a manual NAT for GRE traffic however it did not work, neither.

Finally I decided to give up and moved GRE to other vendor devices.

Thank you again.

 

0 Kudos
HeikoAnkenbrand
Champion Champion
Champion

Hi @Pawel_;

Here is a comparison between adding interfaces manually in Network Topology and using the 'Get Interfaces' feature in SmartConsole:

Manual Configuration:
Recommended for environments where precision and customization are critical, especially for special interfaces like loopback interfaces.
Allows for the inclusion of special interfaces like loopback interfaces, which are not retrieved by the 'Get Interfaces' feature.

Get Interfaces Feature:
Suitable for environments where efficiency and consistency are prioritized, and the number of interfaces is manageable.
Automatically retrieves and configures multiple interfaces quickly, saving time. There is a higher chance of configuration errors due to manual input.
Does not retrieve interfaces without assigned IP addresses (e.g., 0.0.0.0 or 127.0.0.1) or loopback interfaces.

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
Pawel_
Explorer

Hi,

Got it, so 'Get Interfaces' is just an automatic way that helps to avoid configuration errors. If the interfaces are manually configured correctly 'Get Interfaces' should not bring any additional value.

Thank you for your reply.

0 Kudos
Timothy_Hall
Legend Legend
Legend

Correct.  One other note that I mention in my classes is to NEVER do a "Get interfaces with topology" on an existing gateway that is in production, since as you saw doing so may attempt to reconfigure the topology of dozens or hundreds of interfaces and get you into anti-spoofing trouble.  Use "Get interfaces without topology" on production gateways instead then manually verify the topology settings for any new interfaces.  "Get interfaces with topology" is fine for a new gateway you are deploying that is not in production yet, but you'll still need to manually verify the topology settings of all interfaces.

Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones
Hugo_vd_Kooij
Advisor

With over 100 interfaces (VLAN's) it is still a lot of changes to push. And the time increases on some sort of exponential scale with the number of interfaces involved.

<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>
0 Kudos
Alex-
Leader Leader
Leader

There are specific cases. For instance, VTI implementation asks you to perform a "Get interfaces without topology" as you can't create them manually, which is always a great feeling to have when clicking on this option on a production environment.

0 Kudos
the_rock
Legend
Legend

Get interfaces without topology would simply "fetch" whats on the OS level. 

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events