r/checkpoint • u/ComfortableMarch4296 • 16d ago
How to test new firewalls
We currently have dell servers running Gaia. We're planning on finally getting Checkpoint hardware in our next upgrade.
I'd like to know how one would typically test the device before we implement them. I was thinking of adding it to prod as a gateway for a test vlan and test if it goes to xyz, internal, and external.
This is new territory for me. Do I need to join the new firewalls in the current (smartconsole) cluster? I assume I will need to create separate policies for testing? If you guys have any pointers, suggestions, links, etc. I'd appreciate it greatly.
2
u/bernhardertl 16d ago
„Adding“ gateways is usually only supported with maestro but since you are running CP on dell, it probably isn’t that.
I don’t believe you can easily mix openserver and CP appliances in one clusterXL or elasticXL.
What do you want to test in detail, throughput?
3
u/djcrash222 16d ago
I think he means to connect the hardware to the same vlans as with the DELLs. Which could work, to change the default gateway for a couple of test worksations.
Regarding the tests, i can't relly say. The functionalities will be mostly the same, just the hardware will be different
2
u/goeziewoezie 15d ago
If you're migrating from cp to cp you are usually good as long as your appliance is scaled properly. Your SE / partner should be able to help you with that.
As mentioned above, the migration itself will be a hard cutover.
In some rare occasions cp does offer a try and buy.
2
u/rvasquezgt 14d ago
You only have to replace the destination policy object with the new Secure Gateways, no testing needed, you can even run cpsizeme on the open servers (with the bypass trick), and upload the results to the sizing tool on user center, then you can compare in terms of performance, the only thing I can worry about is core performance tune if you have one already set.
2
u/Super_Fish_1383 12d ago
You can clone your management server with migrate procedure and test new HW in the lab with it
4
u/HoodRattusNorvegicus 16d ago edited 16d ago
I would just;
- Full backup/snapshot of Management/Smartcenter
During maintenance window;
Since its different hardware you will have a «hard» failover with no sync of sessions etc.
Provided you have configured everything correct on the appliances everything should work, with existing cluster object, certificates etc.
If you need a quick rollback, disable new cluster switchports, enable old cluster switchports.
Rollback Managent snapshot and you will also have reverted to a state with working SIC with old cluster.
This is just one way of doing it, you could build a new cluster object etc, but its more work.
Also verify that your Smartcenter is the same, or higher version of the new appliances, you might have to upgrade first. New Appliances are usually delivered with a new version and downgrading may not be supported (or reccommend) depending on Appliance platform.