- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Looking to upgrade management from R77.30 to R80.10. In QA I'm getting validation errors for the firewalls in bridge mode which have no IP addresses on the fail-open interfaces (so 0.0.0.0/0.0.0.0). I don't have the ability to push from QA so I need to confirm if this is an issue installing policy? I cant seem to find any documentation on it.

Those interfaces shouldn't have IPs on them for sure.
Which version of SmartConsole are you using?
Also, let me put this in https://community.checkpoint.com/community/management/policy-management?sr=search&searchId=d0b7782c-....
It's R80.10 SmartConsole Build 024
Hi, for this kind of problems I really recommend that you open a support ticket, so that Check Point support will be able to identify the root cause and see how this problem cannot happen for other customers as well.
Hi, You have to make sure that bridge interfaces are not a part of topology tab in Dashboard.
I believe you mean: not defining topology on the interface (i.e. not as internal or external).
My Bad) Topology still can be defined for single FW, but as I've said, in cluster, bridge interface do not part of topology tab at all and it is External by design. (Security Gateway R77 Versions Technical Administration Guide)
Having just installed a Mirror Port gateway on R80.10, the correct answer is: the mirror port should not be defined on the Gateway object at all.
When I fetched topology from my R80.10 Mirror Port gateway, the interface that was the mirror port did not even come across in the topology.
Further, your management Interface for the device should probably have the topology "Undefined" and Anti-Spoofing disabled.
Hi Dameon, this is expected as mirror port is only for POC/testing and it will get all traffic (external + internal) from the corresponding mirror port of the switch. So bridge interface and mirror port, though might seem to be similar, are quite different.
True, I misread ![]()
That said I wonder if a similar solution shouldn't apply.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 8 | |
| 8 | |
| 8 | |
| 8 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY