- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi, we have a situation on this customer and we want to know what are our options. (I made a drawing with the topology for better understanding)
They have a Mgmt server in the main office, we created a dummy object on smartconsole to represent the external IP adress of their MGmt server, to reach the internet, the traffic from the Mgmt server goes thru the internal checkpoint cluster, that has 3 IPS configured.
This Mgmt server communicates with the centrally managed SMB appliances via its external IP address. the issue is that on the SMB appliances we can only put 1 Mgmt ip address, but when this specific ISP goes down on the main office, we lose management of the SMB appliaces, because they all are configured to talk to a single IP of the Mgmt server.
The question is: what can we do in this scenario? is it possible to put more than 1 Mgmt IP adresses on the SMB firewalls?
Not an expert is SMB appliances by any means, but I dont believe you can have more than 1 mgmt IP address, unless there is way to create alias IP or something. Let me spin up quick demo lab and will check.
Andy
Just re-read your post again and I see its centrally managed, so demo lab wont help, as its locally managed appliance there. Can you check below option in smart console?
Andy
hi andy, the issue is that here on this screen, we can only set one IP address, and here we put one specific external IP from the Mgmt server, but when this IPS drops, we lose management of the SMBs
Isee what you mean. Might be worth TAC case to confirm for sure.
Andy
yeah, I did that, they said they only work with "break & fix " scenarios, and told me to ask my account service, which I did, still waiting for the info, meanwhile I decided to see if someone here on checkmates can help
Well, thats not really "break/fix", but still...Anywho, yes, let us know what your Sales person says. Personally, I would ask TAC to maybe check with tech lead/escalation team if this is possible, just to verify.
Best,
Andy
This problem also occurs on regular Quantum gateways when the management is behind a gateway that is doing ISP Redundancy...for more or less the same reason.
Unfortunately, there is not a good solution to this problem at current.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY