- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'm adding a new sub-interface to an existing cluster. I'm going to be following this guide:
https://support.checkpoint.com/results/sk/sk57100
My new sub-interface will be used to route traffic to a remote site (172.16.100.0/24) I will add a static route on each member pointing to this subnet via this new interface.
After creating the interface on each member in Gaia portal, I'm going to use the "get interfaces without topology" in Smart Dashboard. How should I setup the "Leads to" section? Which one of the following two options should I use?
I don't want to "get interfaces with topology" because I don't want to mess with any existing setup. I recall I read somewhere that if you're using the "defined by static routes" option you might need to use "get interfaces with topology"
I want to use the lowest impact, least chance of risk option because it's an important environment.
Thanks
Hi @velo
I suggest you that the "get interfaces with topology" is not safe to use on an working setup. If you use it, all of the Interface information will be overwritten. If somewhere is set an anti-spoofing group, that will be overwritten too, so don't use it.
This is the suggested method in the mentioned SK too.
About your question, how to set up the new interface:
Akos
Thanks Akos
I'm not going to use the "get interfaces with topology" option as that will make changes like you say.
But I thought I read somewhere that if you use the "Network defined by static routes" option, you needed to get the "get interfaces with topology" option for it to pick up the routes, but maybe that is not the case.
You are correct, IP and Mask will represent the network behind the new interface. I will use:
Hopefully that shout be OK.
Thanks
Hi @velo
This statement is misleading. 😉
You can change this setting anytime.
akos
Yes you're quite right, that would be silly. Thanks!
If you are using the option "Network defined by routes" (it's not static routes; just routing in general), then the gateway will poll the Gaia routing daemon (RouteD) every few seconds to learn the contents of the routing table (the FIB). With this information, the gateway will auto-adjust the anti-spoofing topology without needing to make new objects manually.
You will use this option in dynamic routing environments, but you can just as easily do it with static routes ("static routes" are a routing protocol; just not a dynamic routing protocol)
Great to know, thank you. Makes sense.
Just another question. Do I need to add any firewall policy to allow CPP to communicate on these new interfaces?
Look at the SK article, I think it's actually incomplete. There is no mention of pushing a policy after the change.
Hi
Do I need to add any firewall policy to allow CPP to communicate on these new interfaces? No.
You won't be notified to push a policy, just simle push it 🙂
Akos
Thanks for the info. I only mention the push because I think it enabled clustering on that interface only after the push.
Thanks for the info.
The policy install is that movement wich enable the clustering on the interface. All the settings are remain on the Management until you push policy,
Therefore the first investigation step is the pushing policy 🙂
100%, thanks for the info. That's why I think it might be a good idea to mention that in the SK article.
Thanks 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 16 | |
| 13 | |
| 12 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY