CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-01-08
pop_alex pop_alex is offline
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default IP change on interface

Hi,

I'm going to change the public IP on our external interface of firewall to a new one. I'm aware if I change it, I have to update and re-install the policies accordingly in order it to take an immediate effect. Any other things that I should look into before proceed with this?

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2006-01-09
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: IP change on interface

If your license is bound to the external IP address you will have to get it changed to the new IP address.
Reply With Quote
  #3 (permalink)  
Old 2006-01-09
herrmadbeef herrmadbeef is offline
Junior Member
 
Join Date: 2005-09-26
Posts: 19
Rep Power: 0
herrmadbeef has an average reputation (10+)
Default Re: IP change on interface

just in case refresh ur topology
Reply With Quote
  #4 (permalink)  
Old 2006-01-10
pop_alex pop_alex is offline
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: IP change on interface

Thanks,

What about changing the hostname? Is it ok by just refreshing the network topology after applied?

Regards.
Reply With Quote
  #5 (permalink)  
Old 2006-01-10
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: IP change on interface

If you change the hostname of the management station, you will have to reset sic with all of your firewalls as this is based on hostname.
Reply With Quote
  #6 (permalink)  
Old 2006-01-10
pop_alex pop_alex is offline
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: IP change on interface

Quote:
Originally Posted by Lackie
If you change the hostname of the management station, you will have to reset sic with all of your firewalls as this is based on hostname.
No. I'm not going to change the hostname of management station. Only the enforcement server.
Reply With Quote
  #7 (permalink)  
Old 2006-01-10
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: IP change on interface

Sorry, mis-understood. If you change the hostname of the enforcement point, you will have to reset sic on to that enforcement point.
Reply With Quote
  #8 (permalink)  
Old 2006-01-10
pop_alex pop_alex is offline
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: IP change on interface

Quote:
Originally Posted by Lackie
Sorry, mis-understood. If you change the hostname of the enforcement point, you will have to reset sic on to that enforcement point.
Yeap! Correct! :)
Reply With Quote
  #9 (permalink)  
Old 2006-04-10
pop_alex pop_alex is offline
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: IP change on interface

Oh! By the way, if I want to change IP of management server, I need to reset SIC on enforcement servers as well. But, will it disrupt the firewall operation ? If I'm not mistaken, it will restart the firewall services after reset via CPCONFIG.
Reply With Quote
  #10 (permalink)  
Old 2006-04-10
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: IP change on interface

It is not necessarily to do cprestart right now, you can do it later. You cannot to establishe SIC after reset until you do "cprestart" and you module will be use old policy from your SmartCenter.
Reply With Quote
  #11 (permalink)  
Old 2006-04-11
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: IP change on interface

I thought that since SIC is SSL-based, that you do not have to reset it for an IP address change, just a name change.

BTW, don't forget to update the HOSTS file on the SmartCenter and enforcement module for the IP address change.

Ray
Reply With Quote
  #12 (permalink)  
Old 2006-06-01
olumide olumide is offline
Junior Member
 
Join Date: 2006-06-01
Posts: 1
Rep Power: 0
olumide has an average reputation (10+)
Default Re: IP change on interface

Quote:
Originally Posted by pop_alex
Hi,

I'm going to change the public IP on our external interface of firewall to a new one. I'm aware if I change it, I have to update and re-install the policies accordingly in order it to take an immediate effect. Any other things that I should look into before proceed with this?

Thanks.
I am looking to do the same thing, Have you had a solution yet
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:58.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0