<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall gateway migration activity in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250239#M48880</link>
    <description>&lt;P&gt;Any one reply to this to add to this we have already created new cluster&amp;nbsp; with new gateway and tested out flow now we will add this gateway in the production cluster&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 May 2025 14:51:24 GMT</pubDate>
    <dc:creator>Sam472</dc:creator>
    <dc:date>2025-05-30T14:51:24Z</dc:date>
    <item>
      <title>Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250183#M48861</link>
      <description>&lt;P&gt;We are in process of a firewall migration activity replacing 5800 gateways to 9400 . Currently 5800 is running on R81 and 9400 is out of box&amp;nbsp; R81.20 .&lt;/P&gt;&lt;P&gt;Want to know what will be the best approach to do this activity .&lt;/P&gt;&lt;P&gt;Below is my approach if any one can validate and guide will be helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Pre configure the gateway with interface and routes and configuration same as old gateway .&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. In smart console from the existing cluster delete the old members gateway and add the new gateways establish SIC and get interfaces and push policy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 19:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250183#M48861</guid>
      <dc:creator>Sam472</dc:creator>
      <dc:date>2025-05-29T19:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250239#M48880</link>
      <description>&lt;P&gt;Any one reply to this to add to this we have already created new cluster&amp;nbsp; with new gateway and tested out flow now we will add this gateway in the production cluster&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 14:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250239#M48880</guid>
      <dc:creator>Sam472</dc:creator>
      <dc:date>2025-05-30T14:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250245#M48881</link>
      <description>&lt;P&gt;that should do it. you might inspect $FWDIR/boot/modules/fwkern.conf files to see if there are any relevant kernel parameter changes that were made in the old firewalls that you would still need in the new ones.&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Content/Topics-FWG/Kernel-Parameters/FireWall-Kernel-Parameters.htm?tocpath=Working%20with%20Kernel%20Parameters%7C_____2" target="_blank"&gt;Firewall Kernel Parameters&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 16:00:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250245#M48881</guid>
      <dc:creator>Lloyd_Braun</dc:creator>
      <dc:date>2025-05-30T16:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250246#M48882</link>
      <description>&lt;P&gt;I also suggest using&amp;nbsp;&lt;STRONG&gt;Prerequisites for Upgrading and Migrating of Security Gateways and Clusters&amp;nbsp;&lt;/STRONG&gt;- it includes a list of important files and folders&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Prerequisites-for-Upgrading-and-Migrating-of-Security-Gateways-and-Clusters.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Prerequisites-for-Upgrading-and-Migrating-of-Security-Gateways-and-Clusters.htm&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 16:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250246#M48882</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-05-30T16:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250252#M48885</link>
      <description>&lt;P&gt;Just follow below. I must have done this at least 10 times, never an issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/69216#M5286" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/69216#M5286&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 17:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250252#M48885</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-30T17:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250294#M48906</link>
      <description>&lt;P&gt;I have followed this poa and it didn't work My old cluster was in R81 we deleted the old gateway objects and added the new gateway object which is in&amp;nbsp; r81.20 and tried to install policy it failed saying cluster version miss match and cluster object was showing old r81 it was not getting updated to roll 81.20&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jun 2025 03:37:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250294#M48906</guid>
      <dc:creator>Sam472</dc:creator>
      <dc:date>2025-06-01T03:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250295#M48907</link>
      <description>&lt;P&gt;Hii as per the guides I read if our cluster is version 81 we removed r81 gateways from cluster and added new r81.20 gateways done sic pulled network topology and when we try to install policy cluster object is not getting updated to r81.20 its still showing old r81 and policy getting failed saying mvc error&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jun 2025 06:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250295#M48907</guid>
      <dc:creator>Sam472</dc:creator>
      <dc:date>2025-06-01T06:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250299#M48908</link>
      <description>&lt;P&gt;Are you saying you tried that and it failed or you plan to do it that way?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jun 2025 11:56:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250299#M48908</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-01T11:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250300#M48909</link>
      <description>&lt;P&gt;No I tried it and failed i was not able to install policy after adding new gateway in cluster it said mvc error it seems like r 81 not supports mvc&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Jun 2025 15:38:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250300#M48909</guid>
      <dc:creator>Sam472</dc:creator>
      <dc:date>2025-06-01T15:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250332#M48925</link>
      <description>&lt;P&gt;You should be able to change the object version manually on the management side.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 10:17:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250332#M48925</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-06-02T10:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250333#M48926</link>
      <description>&lt;P&gt;MVC was supported as of R80.40&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 10:20:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250333#M48926</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T10:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250345#M48934</link>
      <description>&lt;P&gt;How to update even TAC was on call they were trying to update cluster object but not able to do and had to roll back as downtime was less&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 12:41:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250345#M48934</guid>
      <dc:creator>Sam472</dc:creator>
      <dc:date>2025-06-02T12:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250346#M48935</link>
      <description>&lt;P&gt;Im happy to try assist if you allow remote...Im in EST time zone, so Im sure we can figure something out, let me know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 12:42:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250346#M48935</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T12:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250347#M48936</link>
      <description>&lt;P&gt;Ok but when we trying to install the policy cluster version was showing as r 81 it was not getting updated and was saying version error and policy getting failed in smartconsole after adding the new gateways I can see both the cluster and gateway object with r 81.20 but smartconsole it was still showing old r81&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 12:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250347#M48936</guid>
      <dc:creator>Sam472</dc:creator>
      <dc:date>2025-06-02T12:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250348#M48937</link>
      <description>&lt;P&gt;If you are allowed to do remote, Im happy to check for you. I have 45 mins now.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 12:49:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250348#M48937</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T12:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250361#M48945</link>
      <description>&lt;P&gt;Yes that will be really helpful messaged you let us know can we connect tommorow once&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:36:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250361#M48945</guid>
      <dc:creator>Sam472</dc:creator>
      <dc:date>2025-06-02T13:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250362#M48946</link>
      <description>&lt;P&gt;Just responded.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 13:37:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250362#M48946</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T13:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250389#M48954</link>
      <description>&lt;P&gt;The version in the gateway/cluster objects need to match the actual version installed on the gateway.&lt;BR /&gt;Did you install or upgrade to R81.20 on the relevant gateways?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 20:22:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250389#M48954</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-02T20:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250390#M48955</link>
      <description>&lt;P&gt;I will do remote with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/130532"&gt;@Sam472&lt;/a&gt;&amp;nbsp;tomorrow at 9.30 pm IST to see if we can sort this out, will update afterwards.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 20:54:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250390#M48955</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-02T20:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall gateway migration activity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250501#M48987</link>
      <description>&lt;P&gt;-remote with Sanil&lt;BR /&gt;-checked the config&lt;BR /&gt;-both mgmt and gateways are on R81.20&lt;BR /&gt;-discussed below:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/69216#M5286" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/69216#M5286&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;-advised best way to do this is NOT create new cluster object, but rather modify existing one to new version and hardware model, copy config from show configuration if IPs will be the same&lt;BR /&gt;and then establish SIC, get interfaces without topology and inbstall on first backup member, then do same for new one&lt;/P&gt;
&lt;P&gt;provided Sanil with my info in case they need help, and also advised to turn on mvc by running cphaconf mvc on command from expert&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 16:33:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Firewall-gateway-migration-activity/m-p/250501#M48987</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-03T16:33:13Z</dc:date>
    </item>
  </channel>
</rss>

