<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Smart Event and Log Server Replacement in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235493#M45652</link>
    <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;The Smart-1 server was racked but no initial config applied as yet should I be able to console to it and login using default login admin/admin. &amp;nbsp; Some reason not working. I was going to apply config using the console reverse SSH.&lt;/P&gt;&lt;P&gt;The server has a SmartEvent blade on it , &amp;nbsp;does the database need to be migrated off using migrate export ? &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 14:44:23 GMT</pubDate>
    <dc:creator>JayM1</dc:creator>
    <dc:date>2024-12-12T14:44:23Z</dc:date>
    <item>
      <title>Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/230909#M44454</link>
      <description>&lt;P&gt;I am looking to migrate our old smart-1 log and event server with another replacement smart-1 physical appliance.&lt;/P&gt;&lt;P&gt;Id like to keep the existing IP details does anyone have a step by step process on best way to migrate the old appliance out?&lt;/P&gt;</description>
      <pubDate>Sun, 27 Oct 2024 12:16:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/230909#M44454</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-10-27T12:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/230914#M44455</link>
      <description>&lt;P&gt;I dont know if there is an official guide per se for things like that, but what I always personally give to customers is this. We run something like this on existing server -&amp;gt; clish -c "show configuration" &amp;gt; /var/log/current_config.txt (you run this from expert and you can output it into any dir and give whatever file name, just keep txt extension).&lt;/P&gt;
&lt;P&gt;Then, you get the file using winscp (make sure /bin/bash shell is enabled) , and it will have all the current config of the appliance, which you can copy over the new one, just make sure not to copy anything that might be different. (copy in clish mode)&lt;/P&gt;
&lt;P&gt;I never had an issue doing it that way.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;P.S. Now, IF this was say management server and you wanted to copy all the policies/objects over (import them I shall say), then you would follow below process.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk135172" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk135172&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Oct 2024 14:28:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/230914#M44455</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-27T14:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/230922#M44458</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks Andy, will give this ago.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;This is just a secondary log server to management server. &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Oct 2024 19:35:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/230922#M44458</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-10-27T19:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/230924#M44459</link>
      <description>&lt;P&gt;K, then I would follow clish method I gave, would make most sense. I mean, you could technically do backup/restore as well, but that would restore exact same settings, so would work, as long as its same type of hardware, as interfaces would need to match.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 27 Oct 2024 19:42:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/230924#M44459</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-27T19:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235493#M45652</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;The Smart-1 server was racked but no initial config applied as yet should I be able to console to it and login using default login admin/admin. &amp;nbsp; Some reason not working. I was going to apply config using the console reverse SSH.&lt;/P&gt;&lt;P&gt;The server has a SmartEvent blade on it , &amp;nbsp;does the database need to be migrated off using migrate export ? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 14:44:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235493#M45652</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-12-12T14:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235499#M45654</link>
      <description>&lt;P&gt;Migrate server would work, yes.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 15:14:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235499#M45654</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T15:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235863#M45735</link>
      <description>&lt;P&gt;Sorry what impact does it have on endpoint clients if the smartevent server is down ?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 13:17:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235863#M45735</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-12-16T13:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235873#M45742</link>
      <description>&lt;P&gt;Im not an endpoint expert myself, but I believe if server is down, then endpoint clients obviously cant be managed by it or get any updates from it either.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 13:42:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235873#M45742</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-16T13:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235914#M45749</link>
      <description>&lt;P&gt;The endpoints communicate with SMS server which is not being migrated only the dedicated SmartEvent and secondary log server. &amp;nbsp; I assume its only the reporting that will be impacted but not clear if the threat feeds and policies to block new vulnerabilities will be missed during this time?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 16:32:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235914#M45749</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-12-16T16:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235923#M45752</link>
      <description>&lt;P&gt;Well, think of it this way...its sort of same if fw license expires, it wont stop working, just wont get new ips/urlf updates and so on. Same here, feeds and policies will continue to work, just wont be updates if communication is "missing".&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 19:55:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235923#M45752</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-16T19:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235963#M45756</link>
      <description>&lt;P&gt;Does the software version need to be exact to perform a migrate export , down to hotfix version ? &amp;nbsp; Both are now on R81.20 but not sure about hotfix if both need to be on lastest jumbo fix before doing the migrate? &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 05:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235963#M45756</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-12-17T05:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235964#M45757</link>
      <description>&lt;P&gt;Yes that's the recommendation:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When you use the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Advanced Upgrade&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;or the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Migration and Upgrade&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;method,&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;before&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;you import the management database on the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Book_Variables_Common.tp_cpversion variable"&gt;R81.20&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Servers, we strongly recommend to install the latest Recommended Take of the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm" target="_blank" rel="noopener"&gt;R81.20 Jumbo&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;Hotfix&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Accumulator&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Prerequisites-for-Upgrading-and-Migrating-of-Mgmt-Servers-and-Log-Servers.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Prerequisites-for-Upgrading-and-Migrating-of-Mgmt-Servers-and-Log-Servers.htm&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also make sure to use the most up to date Upgrade Tools package:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk135172" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk135172&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 09:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235964#M45757</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-12-17T09:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235973#M45759</link>
      <description>&lt;P&gt;Is that the hotfix recommended jumbo take 89 or accumulator take 92 ? &amp;nbsp;&lt;BR /&gt;Does JHF also need to be applied to SMS and gateways as well or can I just install it on Smart-1 servers for now and apply JHF to others later?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 09:25:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235973#M45759</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-12-17T09:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235975#M45760</link>
      <description>&lt;P&gt;For migration flow it "only" has to be on the Source and Destination machines.&lt;/P&gt;
&lt;P&gt;As a general rule it should be on all the machines in the environment.&lt;/P&gt;
&lt;P&gt;Take 89 is the Recommended one. Take 92 is the Latest one.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20_Downloads.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20_Downloads.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 09:50:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235975#M45760</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2024-12-17T09:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235977#M45761</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/101160"&gt;@JayM1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a good question. But why should you keep the IP? Do you not have free IP in the subnet?&lt;/P&gt;
&lt;P&gt;A&lt;/P&gt;</description>
      <pubDate>Tue, 17 Dec 2024 10:04:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/235977#M45761</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-12-17T10:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236078#M45777</link>
      <description>&lt;P&gt;Yes, it is recommended, as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;advised as well. Though, when it comes to migrate_server, you can certainly do it with different versions, as per sk below, sort of like with migrate export in the old days.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk135172" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk135172&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 03:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236078#M45777</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-18T03:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236097#M45778</link>
      <description>&lt;P&gt;I am going to reset server to factory as it was built as checkpoint management server and not gateway so no option to reset SIC. &amp;nbsp; Its a pain it cant be converted easily without a factory reset from Gaia. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 10:08:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236097#M45778</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-12-18T10:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236130#M45787</link>
      <description>&lt;P&gt;But hang on a second...IF all you are ding is migrating policies/objects, then use migrate server, but if you want to copy everything else, then backup/restore would not work if its different hardware. Now, what does work is if you copy bits and pieces from show configuration, as long as you MAKE SURE interfaces do match.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 12:41:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236130#M45787</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-18T12:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236134#M45788</link>
      <description>&lt;P&gt;Migrating from 525 to 600-M server so backup/restore not an option. &amp;nbsp; How can you check how original server was deployed as ? &amp;nbsp; &amp;nbsp;I assume its a gateway if SIC is available in cpconfig on old server? &amp;nbsp; During the initial setup using wizard it can get confusing as you need to know the Deployment options and Installation Type is correctly selected. &amp;nbsp; There is nothing on Gaia portal to confirm is there ?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 13:14:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236134#M45788</guid>
      <dc:creator>JayM1</dc:creator>
      <dc:date>2024-12-18T13:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Smart Event and Log Server Replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236138#M45790</link>
      <description>&lt;P&gt;Are you allowed to do remote? Happy to have zoom and check this for you. If yes, just message me directly and I can send you the link. We use MS teams for corporate communication, but I have my own zoom with 40 minutes remote limit, but that should be more than enough.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 13:27:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smart-Event-and-Log-Server-Replacement/m-p/236138#M45790</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-18T13:27:10Z</dc:date>
    </item>
  </channel>
</rss>

