<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrade to New Hardware Steps in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/158017#M27509</link>
    <description>&lt;P&gt;If you have some local configuration, it will not be exported with the migration tools, some of the configuration which I found can be important are as belows:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$FWDIR/boot/modules/fwkern.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/boot/modules/vpnkern.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$PPKDIR/boot/modules/simkern.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$PPKDIR/boot/modules/sim_aff.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/fwaffinity.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/local.arp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/discntd.if&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/cphaprob.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/cpha_bond_ls_config.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/fwauthd.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/resctrl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/database/qos_policy.C&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/var/ace/sdconf.rec&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/var/ace/sdopts.rec&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/etc/snmp/snmpd.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/etc/snmp/userDefinedSettings.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/etc/snmp/snmpmonitor.conf&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 08:17:24 GMT</pubDate>
    <dc:creator>garrod</dc:creator>
    <dc:date>2022-09-26T08:17:24Z</dc:date>
    <item>
      <title>Upgrade to New Hardware Steps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/157977#M27495</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;currently my customer using 4800 HA (R77.30) and Smart-1 410 (R80.10) and they decided to upgrade to latest hardware version using 6600 HA + Smart-1 600S then targeting using latest os also R81.10.&lt;/P&gt;&lt;P&gt;anyone know how to seamlessly upgrade from old hardware and software to latest hardware and software?&lt;/P&gt;&lt;P&gt;what is coming to my mind is, i upgrade smart-1 to R81.10 then copy snapshot and import to new smart-1, is it good move? and for gateway i think there is no issue, because i only need copy via "show configuration"..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 13:42:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/157977#M27495</guid>
      <dc:creator>MtxMan</dc:creator>
      <dc:date>2022-09-25T13:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to New Hardware Steps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/157978#M27496</link>
      <description>&lt;P&gt;Snapshots only work on the exact same hardware model on which they were taken.&lt;BR /&gt;You will need to use the advanced migration process, which will involve an upgrade to R80.40 as an interim step.&lt;/P&gt;
&lt;P&gt;show configuration will get the OS configuration but will miss any manually modified files.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 14:15:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/157978#M27496</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-25T14:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to New Hardware Steps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/157979#M27497</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so mean that i need to upgrade existing and new management to R80.40 then perform system backup?&lt;/P&gt;&lt;P&gt;noted, so whats your recommendation for gateway instead?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 16:54:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/157979#M27497</guid>
      <dc:creator>MtxMan</dc:creator>
      <dc:date>2022-09-25T16:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to New Hardware Steps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/157983#M27499</link>
      <description>&lt;P&gt;Only if you can get the source and destination to have the exact same JHF level installed, otherwise you cannot use a system backup for this.&lt;BR /&gt;This limitation is documented here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk91400&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk91400&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can do one of two things for upgrading your management:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Upgrade the existing management to R80.40 in-place, take a Gaia backup, restore onto the same version/JHF level on the new hardware, then upgrade to R81.10 in-place.&lt;/LI&gt;
&lt;LI&gt;Install a fresh VM with R80.40, use the legacy migration tools to migrate the existing Smart-1 configuration to this VM, use the newer migration tools to export this configuration to the new Smart-1 on R81.10.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I like the second approach because the existing management will remain unaffected by the upgrade except for when the migrate export is run (i.e. because it requires a cpstop).&lt;/P&gt;
&lt;P&gt;On the gateway side, provided you've made all your configuration changes to the gateway only via clish/WebUI or SmartConsole a "show configuration" from the gateways should suffice as a starting point.&lt;BR /&gt;If you have modified any other files (these were documented somewhere, right?), then they will have to be backed up separately.&lt;BR /&gt;Given the large number of changes between R80.10 and R81.10, all of those changes will need to be reviewed to see if they are applicable or even necessary.&lt;BR /&gt;Which means, even if we backed up/restored those files, you might end up breaking things.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 21:47:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/157983#M27499</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-25T21:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to New Hardware Steps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/158017#M27509</link>
      <description>&lt;P&gt;If you have some local configuration, it will not be exported with the migration tools, some of the configuration which I found can be important are as belows:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;$FWDIR/boot/modules/fwkern.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/boot/modules/vpnkern.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$PPKDIR/boot/modules/simkern.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$PPKDIR/boot/modules/sim_aff.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/fwaffinity.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/local.arp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/discntd.if&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/cphaprob.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/cpha_bond_ls_config.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/fwauthd.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/conf/resctrl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;$FWDIR/database/qos_policy.C&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/var/ace/sdconf.rec&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/var/ace/sdopts.rec&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/etc/snmp/snmpd.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/etc/snmp/userDefinedSettings.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;/etc/snmp/snmpmonitor.conf&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 08:17:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/158017#M27509</guid>
      <dc:creator>garrod</dc:creator>
      <dc:date>2022-09-26T08:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to New Hardware Steps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/158203#M27563</link>
      <description>&lt;P&gt;so i need to backup manually for those file config right?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 16:52:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/158203#M27563</guid>
      <dc:creator>MtxMan</dc:creator>
      <dc:date>2022-09-27T16:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade to New Hardware Steps</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/158205#M27564</link>
      <description>&lt;P&gt;Yes, if you make ANY changes in expert mode, those changes will need to be backed up manually.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 16:55:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-to-New-Hardware-Steps/m-p/158205#M27564</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-27T16:55:04Z</dc:date>
    </item>
  </channel>
</rss>

