<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate stand alone to cluster with new hardware in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163843#M29251</link>
    <description>&lt;P&gt;Well here is the approach that I had taken and I use to take.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Copy object_5_o.c file from management server.&lt;/LI&gt;&lt;LI&gt;Find out/grep out IP addresses and/or object from that file.&lt;/LI&gt;&lt;LI&gt;Create a linux script using management API for automatic creation of hosts on new mgmt server. This is pretty simple with bash scripting.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Then its just then creating a rules basis on those object and create a cluster object&lt;/LI&gt;&lt;LI&gt;On isolated L3 switch create the L3 vlans and exact same IP addresses and networks for firewall/mgmt server.&lt;/LI&gt;&lt;LI&gt;Connect the mgmt server with firewall establish SIC and installed policy.&lt;/LI&gt;&lt;LI&gt;Then take a backup of that mgmt server or dbexport; put that on a production server and just a small downtime for firewalls installing firewalls in rack.&lt;/LI&gt;&lt;LI&gt;Swap the cables and since SIC and policy is already installed even though&amp;nbsp; while booting up&amp;nbsp; if it does not find mgmt server.&lt;/LI&gt;&lt;LI&gt;It will boot up with last successful install policy and process the traffic&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the mgmt in network - Install the policy and install database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 12:25:50 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2022-12-01T12:25:50Z</dc:date>
    <item>
      <title>Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163821#M29246</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I currently have a 5200 (standalone on r81.10).&lt;/P&gt;&lt;P&gt;I am looking to utilize the same name/IP and replace this gateways with two 6500s on R81.10.&lt;/P&gt;&lt;P&gt;I just wanted to brain storm on the easiest way to accomplish this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, seems like this should be a common ask. Are there any Check Point guides for something like this?&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 01 Dec 2022 09:08:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163821#M29246</guid>
      <dc:creator>Michou</dc:creator>
      <dc:date>2022-12-01T09:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163829#M29247</link>
      <description>&lt;P&gt;Yes, this is a pretty common operation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Prepare the new cluster in the lab. You can either re-apply Gaia config or re-build it manually. Mind, interface names may be changing between the GWs.&lt;BR /&gt;&lt;BR /&gt;Set up a service window, disconnect the management interfaces only from the old cluster, and connect to the new cluster members. Re-establish SIC, push policy, and re-cable the rest of the network.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Should be straight forward.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 10:49:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163829#M29247</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-12-01T10:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163832#M29248</link>
      <description>&lt;P&gt;Indeed - Its a straight forward. Even further I used to setup a L3 switch and replicate the exact customer scenario. Establish SIC, policy push, license install everything same that I would do at customer place and then just plug the devices out and put the devices in. You are out of DC in flat 30 mins.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 11:03:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163832#M29248</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-01T11:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163837#M29249</link>
      <description>&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk154033&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk154033: How to migrate R80.x standalone management environment to a distributed environment&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regardless of the title of the SK, this is also applicable for R81.10, assuming that by Standalone 5200 you mean what the Check Point terminology assumes.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 11:17:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163837#M29249</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-12-01T11:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163838#M29250</link>
      <description>&lt;P&gt;He has to deploy a new SMS from the StandAlone first, so not really easy...&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 11:21:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163838#M29250</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-01T11:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163843#M29251</link>
      <description>&lt;P&gt;Well here is the approach that I had taken and I use to take.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Copy object_5_o.c file from management server.&lt;/LI&gt;&lt;LI&gt;Find out/grep out IP addresses and/or object from that file.&lt;/LI&gt;&lt;LI&gt;Create a linux script using management API for automatic creation of hosts on new mgmt server. This is pretty simple with bash scripting.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Then its just then creating a rules basis on those object and create a cluster object&lt;/LI&gt;&lt;LI&gt;On isolated L3 switch create the L3 vlans and exact same IP addresses and networks for firewall/mgmt server.&lt;/LI&gt;&lt;LI&gt;Connect the mgmt server with firewall establish SIC and installed policy.&lt;/LI&gt;&lt;LI&gt;Then take a backup of that mgmt server or dbexport; put that on a production server and just a small downtime for firewalls installing firewalls in rack.&lt;/LI&gt;&lt;LI&gt;Swap the cables and since SIC and policy is already installed even though&amp;nbsp; while booting up&amp;nbsp; if it does not find mgmt server.&lt;/LI&gt;&lt;LI&gt;It will boot up with last successful install policy and process the traffic&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the mgmt in network - Install the policy and install database.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 12:25:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163843#M29251</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-01T12:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163845#M29252</link>
      <description>&lt;P&gt;I read process&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;gave and it definitely makes sense. The article&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;provided you is also what Im ware of as supported method.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 12:41:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163845#M29252</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-01T12:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163900#M29270</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;sorry, I misspoke.&lt;BR /&gt;When I say it's a stand alone, it's a single gateway. The smartcenter is already detached on a VM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 17:12:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163900#M29270</guid>
      <dc:creator>Michou</dc:creator>
      <dc:date>2022-12-01T17:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163901#M29271</link>
      <description>&lt;P&gt;In that case, please follow below process that TAC gave me for customer that wanted to do EXACT same thing. Version makes no difference, so would not sweat about that.&lt;/P&gt;
&lt;P&gt;Link to a document:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dl3.checkpoint.com/paid/48/4808360334cfd91e38eb192da36ea686/CP_R80.30_ClusterXL_AdminGuide.pdf?HashKey=1669922907_dca4cb6270d5eb21ec9785880fd43045&amp;amp;xtn=.pdf" target="_blank"&gt;https://dl3.checkpoint.com/paid/48/4808360334cfd91e38eb192da36ea686/CP_R80.30_ClusterXL_AdminGuide.pdf?HashKey=1669922907_dca4cb6270d5eb21ec9785880fd43045&amp;amp;xtn=.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The documentation mentions the Standalone deployment for those who have a Standalone firewall and would like to convert it to ClusterXL. In your situation, you can go straight to page 151. "Creating the ClusterXL Object"&lt;BR /&gt;&lt;BR /&gt;Computer B refers to your new firewall and Computer A is your current firewall.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Basically here are the steps:&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Install and configure the new cluster member. (Computer B)&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;make sure that the new firewall can talk to the old firewall and vice versa.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Configure the local configuration such as&amp;nbsp;authentication server,&amp;nbsp;hostname, static route, dynamic route etc.&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;In the policy, remove any references to the old firewall.&lt;/LI&gt;
&lt;LI&gt;Create a new cluster object in SmartConsole.&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;Configure the interfaces, Antispoofing, Office mode etc.&amp;nbsp;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;The cluster VIP will be the old firewall local IP&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;LI&gt;Open the Cluster object and in the "Cluster Members" page, click Add, and select New Cluster Member.&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;Establish SIC&lt;/LI&gt;
&lt;LI&gt;Get interface without topology&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Define a Sync interface&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;Install the policy on the cluster currently including member B only.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;On the old firewall.&amp;nbsp;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;Disconnect all proposed cluster and Synchronization interfaces. New connections now open&lt;BR /&gt;through the cluster, instead of through computer 'A'.&lt;/LI&gt;
&lt;LI&gt;Change the addresses of these interfaces to some other unique IP address which is on the&lt;BR /&gt;same subnet as computer B.&lt;/LI&gt;
&lt;LI&gt;Connect each pair of interfaces of the same subnet using a dedicated network. Any hosts or&lt;BR /&gt;Security Gateways previously connected to the Security Gateway must now be connected to&lt;BR /&gt;both members, using a hub/switch.&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;Update the topology of the Security Gateway that you just added by clicking Get Topology without interface.&lt;/LI&gt;
&lt;LI&gt;In the Cluster Members page, click Add and select "Add Security Gateway to Cluster"&amp;nbsp;&lt;/LI&gt;
&lt;OL&gt;
&lt;LI&gt;Select the&amp;nbsp;old firewall&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;In the "Edit Topology" page, determine the interface type.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI&gt;Configure the Policy base. (VPN domain, rule base, NAT if needed)&lt;/LI&gt;
&lt;LI&gt;Install the policy.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 01 Dec 2022 17:30:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163901#M29271</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-01T17:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate stand alone to cluster with new hardware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163914#M29278</link>
      <description>&lt;P&gt;Btw, I would follow process I gave you, as I did it with 3 customers, never a single problem. TAC guy I worked with on it 2 years ago was AMAZING!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 21:08:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-stand-alone-to-cluster-with-new-hardware/m-p/163914#M29278</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-01T21:08:02Z</dc:date>
    </item>
  </channel>
</rss>

