CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-14
detsh detsh is offline
Junior Member
 
Join Date: 2006-08-09
Posts: 12
Rep Power: 0
detsh has an average reputation (10+)
Default getting new public ip addresses...

Hello,
in the next weeks we will get a new public ip address block from our isp.
This meets, of course, our vpn's. We don't want to change it all at the same time. On our NOKIA Cluster we have one interface unconfigured, at this time.
At this interface, I will configure the new ip address.

And now my question:

Should I leave the old address on the firewallobject, configure the vpn's to the new ipaddresses and, when all vpn's points to the new ipaddress, I change the firewallobject to the new ipaddress

or

First I change the firewallobjects ipaddress to the new one and do then the configuration for the vpn's. Will this going on?

The configuration change to the VPN's will take several days. Through this time, we cannot interrupt vpn's for long time.

Any idea?

Thanks a lot
Reply With Quote
  #2 (permalink)  
Old 2008-01-15
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,030
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: getting new public ip addresses...

I would configure the new interface up,

add static routes onto the box so that the VPN tunnels are routed down the existing interface.

Change Default Gateway to the new line.

Leave the IP alone initially.

You can migrate the VPN's over one at a time, as you do remove the static route for the remote VPN Gateway so moves over to the new interface.

Change the IP to the new range.
Reply With Quote
  #3 (permalink)  
Old 2008-01-15
detsh detsh is offline
Junior Member
 
Join Date: 2006-08-09
Posts: 12
Rep Power: 0
detsh has an average reputation (10+)
Default Re: getting new public ip addresses...

Hello Mcnallym,
and should I change my firewall object's IP-address to the new range?
Could this produce problems for the existing vpn's?
What do you think?
Reply With Quote
  #4 (permalink)  
Old 2008-01-15
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,030
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: getting new public ip addresses...

You can get around this with Link Selection initially and then change the IP of the object when completed
Reply With Quote
  #5 (permalink)  
Old 2008-01-15
donshoutarp donshoutarp is offline
Member
 
Join Date: 2005-09-23
Posts: 75
Rep Power: 4
donshoutarp has an average reputation (10+)
Default Re: getting new public ip addresses...

If you are using "ongoing probing-probe the following address" for your VPN link selection you will need add this new IP address. And you might want change the primary address eventually.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:38.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0