- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Checkpoint connectivity between management & gatew...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint connectivity between management & gateway over vpn
Hi Friends,
I am facing a issue that we got a project to replace the existing check point firewall and place the new check point but check point management is on Delhi and check point getaway is on Pune. Exiting was ipsec connectivity between gateway and management so how will I replace the Exiting firewall without or without snapshot backup?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Putting management traffic (which is already encrypted, FYI) through a VPN is not recommended as it requires editing implied rules and you can end up in a situation where it is impossible to manage your remote gateway if the VPN is down.
The official procedure for doing this is in an internal SK (sk115215) that requires consultation with TAC.
See also these public threads on CheckMates:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
More details about the existing environment are needed:
- Appliances and Software versions used currently (version/JHF levels)
- Appliances you are adding/replacing
- A simple network diagram showing all components
- Confirming someone didn’t disable the various implied rules to force management traffic through VPN (easy enough to see with a tcpdump on the external interface when, say, pushing policy or when the remote gateway sends logs).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhoneBoy,
Thanks for your reply , so senerio is simple that we have management in different location and gateway in other location they are working 81.10 version and we have to add the gateway with management checkpoint through ipsec.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Putting management traffic (which is already encrypted, FYI) through a VPN is not recommended as it requires editing implied rules and you can end up in a situation where it is impossible to manage your remote gateway if the VPN is down.
The official procedure for doing this is in an internal SK (sk115215) that requires consultation with TAC.
See also these public threads on CheckMates:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I definitely misunderstood your question. Yes, what Phoneboy said is 100% correct.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In case like that, I would get show configuration fdrom existing gateway and copy "bits and pieces" to new fw clish config, as long as you make sure relevant interfaces match. Unless its same hardware, backup/restore method would not sadly work.
Otherwise, you could technically try below method, though it was written for a cluster, but I did use it for single appliances as well.
Andy
Solved: Re: Replace/Upgrade Cluster - Check Point CheckMates
