<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migration from 5200 appliance to 9100 appliance - Standalone in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220052#M42106</link>
    <description>&lt;P&gt;Best option is not to use StandAlone deployment at all ! If the GW is under heavy load you will not be able to manually fight this situation.&lt;/P&gt;
&lt;P&gt;migrate_server: This command is used to migrate the management database from &lt;SPAN class="mc-variable Vars_Versions.r_halo_m1 variable"&gt;R80.20.M1&lt;/SPAN&gt;, &lt;SPAN class="mc-variable Vars_Versions.r_halo variable"&gt;R80.20&lt;/SPAN&gt;, &lt;SPAN class="mc-variable Vars_Versions.r_halo_m2 variable"&gt;R80.20.M2&lt;/SPAN&gt;, &lt;SPAN class="mc-variable Vars_Versions.r_heat variable"&gt;R80.30&lt;/SPAN&gt;, and higher versions.&lt;/P&gt;
&lt;P&gt;For more information, see:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/CLI/migrate_server.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/CLI/migrate_server.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For gateway migration see &lt;A href="https://support.checkpoint.com/results/sk/sk108902" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108902&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2024 08:16:01 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2024-07-09T08:16:01Z</dc:date>
    <item>
      <title>Migration from 5200 appliance to 9100 appliance - Standalone</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220049#M42104</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Currently, we are preparing a plan to replace three 5200 devices on three office sites with three 9100 devices, all of which will run standalone.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current product&lt;/STRONG&gt;: 5200 appliance, standalone, R81.20 hotfix take 65&lt;BR /&gt;&lt;STRONG&gt;New replacement product&lt;/STRONG&gt;: 9100 appliance&lt;BR /&gt;&lt;STRONG&gt;Blade uses&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Network Security&lt;/STRONG&gt;: Firewall, Application, URL Filtering, Threat Prevention, IPSec VPN (Site-to-Site VPN, Remote Access VPN)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Management&lt;/STRONG&gt;: Network Security Management, Logging &amp;amp; Status&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We plan to do so according to the following document: &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Migrating-Database-Between-SecMmgt-Servers.htm?tocpath=Special%20Scenarios%20for%20Management%20Servers%7C_____3" target="_blank"&gt;Migrating Database Between R81.20 Security Management Servers (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But we have a few concerns:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Following the above document, "./migrate_server" will be used. Does someone know which configurations below will be migrated:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Gateway&lt;/STRONG&gt;: Interfaces, VLANs, and Routes&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Management&lt;/STRONG&gt;: Security Policy, VPN, Object (especially about 100 local users on the checkpoint we created, using a cert for authentication. If the users and certs cannot be migrated, it will take a lot of time to create and give a cert file for each employee.)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Based on your experience, are there any issues we need to pay attention to to avoid problems?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;Or is there another best-practice way to migrate standalone configurations?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please help me the answer.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;Thank you so much,&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Best Regards.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 07:56:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220049#M42104</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-07-09T07:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from 5200 appliance to 9100 appliance - Standalone</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220052#M42106</link>
      <description>&lt;P&gt;Best option is not to use StandAlone deployment at all ! If the GW is under heavy load you will not be able to manually fight this situation.&lt;/P&gt;
&lt;P&gt;migrate_server: This command is used to migrate the management database from &lt;SPAN class="mc-variable Vars_Versions.r_halo_m1 variable"&gt;R80.20.M1&lt;/SPAN&gt;, &lt;SPAN class="mc-variable Vars_Versions.r_halo variable"&gt;R80.20&lt;/SPAN&gt;, &lt;SPAN class="mc-variable Vars_Versions.r_halo_m2 variable"&gt;R80.20.M2&lt;/SPAN&gt;, &lt;SPAN class="mc-variable Vars_Versions.r_heat variable"&gt;R80.30&lt;/SPAN&gt;, and higher versions.&lt;/P&gt;
&lt;P&gt;For more information, see:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/CLI/migrate_server.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/CLI/migrate_server.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For gateway migration see &lt;A href="https://support.checkpoint.com/results/sk/sk108902" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108902&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 08:16:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220052#M42106</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-07-09T08:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from 5200 appliance to 9100 appliance - Standalone</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220077#M42107</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A class="" href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294" target="_self"&gt;&lt;SPAN class=""&gt;G_W_Albrecht&lt;/SPAN&gt;&lt;/A&gt;,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks&amp;nbsp;for your advice and information.&lt;BR /&gt;Currently, we are being asked by customers to configure a standalone configuration because their system is already operating familiarly. Changing to a distributed configuration may be implemented in the future.&lt;BR /&gt;&lt;BR /&gt;Sorry, but at the two links you give me, I can't see the confirmation of which configurations will be migrated using the command "./migrate_server". I'm very sorry if I missed anything. I also searched for this but couldn't find anything related.&lt;BR /&gt;&lt;BR /&gt;Thanks &amp;amp; Best Regard.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 10:12:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220077#M42107</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-07-09T10:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from 5200 appliance to 9100 appliance - Standalone</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220078#M42108</link>
      <description>&lt;P&gt;migrate_server does not save any GAiA configuration ! This is found in the second link, chapter&lt;/P&gt;
&lt;H3 id="Comparison of backup methods"&gt;8. Comparison of Backup Methods&lt;/H3&gt;
&lt;TABLE id="Unique_IDTable" style="text-align: center;" border="1" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR style="text-align: center; font-weight: bold; background-color: lightgray;"&gt;
&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD&gt;Snapshot&lt;BR /&gt;Management&lt;/TD&gt;
&lt;TD&gt;System&lt;BR /&gt;Backup&lt;/TD&gt;
&lt;TD&gt;"show&lt;BR /&gt;configuration"&lt;/TD&gt;
&lt;TD&gt;"migrate export"&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;How much time&lt;BR /&gt;does it take?&lt;/TD&gt;
&lt;TD&gt;30 - 60 minutes&lt;/TD&gt;
&lt;TD&gt;5 - 30 minutes&lt;/TD&gt;
&lt;TD&gt;Few seconds&lt;/TD&gt;
&lt;TD&gt;Depends on&lt;BR /&gt;configuration&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Size of output file&lt;BR /&gt;on Security Gateway&lt;/TD&gt;
&lt;TD&gt;5-100 GB&lt;/TD&gt;
&lt;TD&gt;Depends on&lt;BR /&gt;configuration&lt;/TD&gt;
&lt;TD&gt;Few KB&lt;/TD&gt;
&lt;TD&gt;N/A&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Size of output file&lt;BR /&gt;on Management Server&lt;/TD&gt;
&lt;TD&gt;5-100 GB&lt;/TD&gt;
&lt;TD&gt;5-100 GB&lt;/TD&gt;
&lt;TD&gt;Few KB&lt;/TD&gt;
&lt;TD&gt;Depends on&lt;BR /&gt;configuration&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Does it back up&lt;BR /&gt;Gaia OS configuration?&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Does it back up&lt;BR /&gt;Products configuration?&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Does it back up&lt;BR /&gt;Hotfixes?&lt;/TD&gt;
&lt;TD&gt;Yes&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;No&lt;/P&gt;
&lt;P&gt;(does not apply to "&lt;CODE&gt;mds_backup&lt;/CODE&gt;")&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Does it back up&lt;BR /&gt;Check Point&lt;BR /&gt;logs?&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;No&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Not by default.&lt;/P&gt;
&lt;P&gt;Use the flag "&lt;EM&gt;-l&lt;/EM&gt;"&lt;BR /&gt;in the syntax&lt;BR /&gt;to back up the&lt;BR /&gt;SmartView Tracker&lt;BR /&gt;logs as well.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 10:18:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220078#M42108</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-07-09T10:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from 5200 appliance to 9100 appliance - Standalone</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220084#M42109</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294" target="_self"&gt;&lt;SPAN class=""&gt;G_W_Albrecht&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you so much. I have seen it will not migrate GAiA configuration.&lt;BR /&gt;&lt;BR /&gt;But&amp;nbsp;there are still a few points at Management:&amp;nbsp; "./migrate_server" is it possible to migrate VPN configuration (S2S, C2S), Object?&lt;BR /&gt;Especially for local users, after migrating to the 9100 appliance, can employees still use the certificate previously issued on the 5200 appliance to connect to remote access VPN?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks &amp;amp; Best Regard.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 09 Jul 2024 11:18:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220084#M42109</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-07-09T11:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from 5200 appliance to 9100 appliance - Standalone</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220134#M42118</link>
      <description>&lt;P&gt;If it's defined through SmartConsole, migrate_server covers it.&lt;/P&gt;
&lt;P&gt;If it's defined on the command line or in a web interface of some kind, migrate_server does not cover it.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 17:41:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220134#M42118</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-07-09T17:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Migration from 5200 appliance to 9100 appliance - Standalone</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220195#M42128</link>
      <description>&lt;P&gt;Thanks for your information.&amp;nbsp;I really appreciate it.&lt;BR /&gt;&lt;BR /&gt;Best Regards.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 08:40:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migration-from-5200-appliance-to-9100-appliance-Standalone/m-p/220195#M42128</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-07-10T08:40:40Z</dc:date>
    </item>
  </channel>
</rss>

