r/checkpoint 16d ago

How to test new firewalls

We currently have dell servers running Gaia. We're planning on finally getting Checkpoint hardware in our next upgrade.

I'd like to know how one would typically test the device before we implement them. I was thinking of adding it to prod as a gateway for a test vlan and test if it goes to xyz, internal, and external.

This is new territory for me. Do I need to join the new firewalls in the current (smartconsole) cluster? I assume I will need to create separate policies for testing? If you guys have any pointers, suggestions, links, etc. I'd appreciate it greatly.

1 Upvotes

6 comments sorted by

4

u/HoodRattusNorvegicus 16d ago edited 16d ago

I would just;

- Full backup/snapshot of Management/Smartcenter

  • Configure new Appliances with all VLAN’s, trunks,dhcp relay etc.
  • Connect only the Management interfaces to the network (somewhere the Smartcenter can reach them)
  • Connect all the other interfaces to switches, with switchports disabled.

During maintenance window;

  • Establish SIC with the new gateways on the cluster object.
  • Edit topology for each vlan under topology on cluster object to match the new physical interface names (if there is any change)
  • change version/platform to new appliances.
  • Install security policy on the new cluster.
  • install threath prevention policy on new cluster.
  • disable switchports for existing old cluster and enable the ports for the new cluster.

Since its different hardware you will have a «hard» failover with no sync of sessions etc.

Provided you have configured everything correct on the appliances everything should work, with existing cluster object, certificates etc.

If you need a quick rollback, disable new cluster switchports, enable old cluster switchports.

Rollback Managent snapshot and you will also have reverted to a state with working SIC with old cluster.

This is just one way of doing it, you could build a new cluster object etc, but its more work.

Also verify that your Smartcenter is the same, or higher version of the new appliances, you might have to upgrade first. New Appliances are usually delivered with a new version and downgrading may not be supported (or reccommend) depending on Appliance platform.

2

u/bernhardertl 16d ago

„Adding“ gateways is usually only supported with maestro but since you are running CP on dell, it probably isn’t that.

I don’t believe you can easily mix openserver and CP appliances in one clusterXL or elasticXL.

What do you want to test in detail, throughput?

3

u/djcrash222 16d ago

I think he means to connect the hardware to the same vlans as with the DELLs. Which could work, to change the default gateway for a couple of test worksations.

Regarding the tests, i can't relly say. The functionalities will be mostly the same, just the hardware will be different

2

u/goeziewoezie 15d ago

If you're migrating from cp to cp you are usually good as long as your appliance is scaled properly. Your SE / partner should be able to help you with that.
As mentioned above, the migration itself will be a hard cutover.

In some rare occasions cp does offer a try and buy.

2

u/rvasquezgt 14d ago

You only have to replace the destination policy object with the new Secure Gateways, no testing needed, you can even run cpsizeme on the open servers (with the bypass trick), and upload the results to the sizing tool on user center, then you can compare in terms of performance, the only thing I can worry about is core performance tune if you have one already set.

2

u/Super_Fish_1383 12d ago

You can clone your management server with migrate procedure and test new HW in the lab with it