<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sk156072 - Domain migration - SMS to DMS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276369#M105179</link>
    <description>&lt;P&gt;It worked perfectly in production. A pleasure to have an SK so clear to follow.&lt;/P&gt;
&lt;P&gt;The transition from the 600 to the 7000 manager series with bonded 10G series is impressive, the performance is on another level.&lt;/P&gt;</description>
    <pubDate>Fri, 01 May 2026 14:42:07 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2026-05-01T14:42:07Z</dc:date>
    <item>
      <title>sk156072 - Domain migration - SMS to DMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276110#M105104</link>
      <description>&lt;P&gt;I'm going to lab this up but I'm looking at moving an SMS to a brand new MDS that's just been staged to R82 T91 and has no other configuration for now.&lt;/P&gt;
&lt;P&gt;The process seems straightforward:&lt;/P&gt;
&lt;P&gt;- Export the SMS with the documented API call&lt;/P&gt;
&lt;P&gt;- Import the TGZ in the MDS withe the documented API call, in our scenario the IP remains the same&lt;/P&gt;
&lt;P&gt;- Connect to the imported domain and start from there&lt;/P&gt;
&lt;P&gt;A few questions for anyone familiar with this:&lt;/P&gt;
&lt;P&gt;- Is this as straightforward as the SK implies, considering we keep the IP?&lt;/P&gt;
&lt;P&gt;- Is SIC and so on maintained?&lt;/P&gt;
&lt;P&gt;- Are there gotchas like using the same name for the domain than the SMS or anything else?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 08:03:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276110#M105104</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-04-27T08:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: sk156072 - Domain migration - SMS to DMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276112#M105105</link>
      <description>&lt;P&gt;hi Alex,&lt;/P&gt;
&lt;P&gt;Yes the procedure is pretty slick these days. As long as you have the latest versions of the upgrade tools then it works well in pretty much all scenarios.&lt;/P&gt;
&lt;P&gt;Yes SIC is maintained, even if you do change the IP (in your case you are not)&lt;/P&gt;
&lt;P&gt;You can use the same name for the domain, or call it something different.&lt;/P&gt;
&lt;P&gt;If you do need to change IP of the domain (in future migrations) - just add a rule on the gateways affected, so you do not cut yourself off from them (but then again you can always connect to them from the previous management server)&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 08:12:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276112#M105105</guid>
      <dc:creator>Peter_Lyndley</dc:creator>
      <dc:date>2026-04-27T08:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: sk156072 - Domain migration - SMS to DMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276127#M105107</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;we did that exercise a while ago with multiple SMS.&amp;nbsp; At least I remember that an outdated IPS on the Source SMS stopped the import process on MDS side. I would have a look that the versions (IPS db, ) are more or less identical.&lt;/P&gt;
&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 13:46:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276127#M105107</guid>
      <dc:creator>S_E_</dc:creator>
      <dc:date>2026-04-27T13:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: sk156072 - Domain migration - SMS to DMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276266#M105126</link>
      <description>&lt;P&gt;The lab went succesfully, which presages well for the production part. It was also a reminder of how long I stayed without using an MDS. Here's how it went.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Install VMWare Workstation Pro on a spare laptop, create a RH8 image with sufficient disk space for partitioning in a segment with the same IP subnet than production&lt;/LI&gt;
&lt;LI&gt;FTW R82, install CPUSE, T91, upgrade tools&lt;/LI&gt;
&lt;LI&gt;Install a lab/eval MDS license - without this, the domain won't start&lt;/LI&gt;
&lt;LI&gt;Use the API call to import the TGZ and wait completion.&lt;/LI&gt;
&lt;LI&gt;Connect to the MDS and assign the domain to the user(s), without this, a misleading "Your IP is not authorized" message is displayed when trying to connect to the domain&lt;/LI&gt;
&lt;LI&gt;Using the FTW "admin" account, I got a loop constantly asking to confirm the fingerprint, it was solved by creating another with mdsconfig and log with it&lt;/LI&gt;
&lt;LI&gt;After this, connecting to the MDS and starting the imported domain showed all systems on the current SMS&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 17:04:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276266#M105126</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-04-29T17:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: sk156072 - Domain migration - SMS to DMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276369#M105179</link>
      <description>&lt;P&gt;It worked perfectly in production. A pleasure to have an SK so clear to follow.&lt;/P&gt;
&lt;P&gt;The transition from the 600 to the 7000 manager series with bonded 10G series is impressive, the performance is on another level.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2026 14:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/sk156072-Domain-migration-SMS-to-DMS/m-p/276369#M105179</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-05-01T14:42:07Z</dc:date>
    </item>
  </channel>
</rss>

