<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Separating Endpoint Management from SMS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268920#M60407</link>
    <description>&lt;P&gt;This tool is nice, we used that to migrate thousands of clients from on prem endpoint management to harmony cloud.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Jan 2026 10:31:29 GMT</pubDate>
    <dc:creator>Vincent_Bacher</dc:creator>
    <dc:date>2026-01-28T10:31:29Z</dc:date>
    <item>
      <title>Separating Endpoint Management from SMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268210#M60401</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I am currently trying to find out the neccessary steps for separating an EPM from a SMS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment the SMS is doing the Endpoint Management, but our customer plans to separate that into two servers for better redundancy and to get rid of that limitation with DB revisions (Not possible to use revisions when SMS is also doing the EPM).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apart from an old Post (2017) that ended with "PS needs to be involved", I did not find anything...So I came here to see if anyone has done this before and could give some useful hints.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess at first I should be installing a second management server, importing the DB and then activating the EPM blade. But what then? I guess I cannot just disable that blade on the first server and everything will work, that sounds too easy. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Somehow the Clients will need to know that they have to connect to a different server now and that will probably bring other issues like changed fingerprint and/or certificates...and probably more stuff that I do not think of yet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So...is there a Guide or SK that I missed? Or someone who did this already?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 10:50:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268210#M60401</guid>
      <dc:creator>Kryten</dc:creator>
      <dc:date>2026-01-22T10:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Separating Endpoint Management from SMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268211#M60402</link>
      <description>&lt;P&gt;Can you do it the other way?&lt;/P&gt;
&lt;P&gt;The existing server stays there for EPM (and remove firewalls and policy) and the new one is installed (import) for the gateway management.&lt;/P&gt;
&lt;P&gt;I guess EPMaaS&amp;nbsp; is not an option to move the EPM to the Infinity Portal?&lt;/P&gt;
&lt;P&gt;You have to plan around licenses too.&lt;/P&gt;
&lt;P&gt;Another option is to leave the current server as EPM (as above) and build a new SG management server (SMS) and then build that up from scratch.&lt;/P&gt;
&lt;P&gt;You would need to do a SIC reset on the SGs and can use API to make policy 'migration' more efficient.&lt;/P&gt;
&lt;P&gt;Just initial thoughts. Hopefully someone who has done it picks this up too.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Don&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 10:56:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268211#M60402</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2026-01-22T10:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Separating Endpoint Management from SMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268301#M60403</link>
      <description>&lt;P&gt;The &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_HarmonyEndpointWebManagement_AdminGuide/Content/Topics-HEPWM-R81.20/Reconnect_Tool.htm" target="_self"&gt;reconnect tool&lt;/A&gt; is what is used to associate Endpoint clients with a different server.&lt;BR /&gt;migrate_server does have options to exclude Endpoint configuration, so this could be the basis for creating a new management server without Endpoint.&amp;nbsp;&lt;BR /&gt;Associating the firewalls with the new management server might require a small adjustment to the active policy to allow policy installation from the new management server, but after the policy install, they'll effectively be migrated to the new management server.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 17:07:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268301#M60403</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-01-22T17:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Separating Endpoint Management from SMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268337#M60404</link>
      <description>&lt;P&gt;Interesting...never knew of that tool.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 23:40:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268337#M60404</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-22T23:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: Separating Endpoint Management from SMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268686#M60405</link>
      <description>&lt;P&gt;Hey Alex,&lt;/P&gt;
&lt;P&gt;Were you able to figure this out? Had client ask me the same question today and I remembered this post, but told them would follow up.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2026 01:31:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268686#M60405</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-27T01:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Separating Endpoint Management from SMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268913#M60406</link>
      <description>&lt;P&gt;Not yet, we are still in the planning stage(long term project). So far it sounds like it would be easier to create a new management for the Gateways, but we still have not decided.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 08:48:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268913#M60406</guid>
      <dc:creator>Kryten</dc:creator>
      <dc:date>2026-01-28T08:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Separating Endpoint Management from SMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268920#M60407</link>
      <description>&lt;P&gt;This tool is nice, we used that to migrate thousands of clients from on prem endpoint management to harmony cloud.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 10:31:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268920#M60407</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-01-28T10:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Separating Endpoint Management from SMS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268934#M60408</link>
      <description>&lt;P&gt;Nice. Will see if I can test it in the lab.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 11:36:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Separating-Endpoint-Management-from-SMS/m-p/268934#M60408</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-28T11:36:39Z</dc:date>
    </item>
  </channel>
</rss>

