<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Move S1C to On-prem in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235599#M63686</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks you for your advises. let me include the mention step with my plan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard,&lt;/P&gt;</description>
    <pubDate>Fri, 13 Dec 2024 03:05:16 GMT</pubDate>
    <dc:creator>kaka</dc:creator>
    <dc:date>2024-12-13T03:05:16Z</dc:date>
    <item>
      <title>Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235119#M63676</link>
      <description>&lt;P&gt;Hello guy!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the user experience with S1C we decided to move from cloud to on-prem. I have 2 gateway run as clusterxl. Currently SIC version R82 and the new mgmt run R81.20 latest HF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;May I know the best practices for preparation during move gw to new mgmt?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: The new mgmt setup completely with import database from SIC and object and policies was synced.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard,&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 04:40:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235119#M63676</guid>
      <dc:creator>kaka</dc:creator>
      <dc:date>2024-12-10T04:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235121#M63677</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;To be sure syc is already active between new onprem mgmt and all gateways? If you have done import and policies are in place you are good to go. Did you already installed policy with new mgmt?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 06:11:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235121#M63677</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-10T06:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235124#M63678</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Install policy from new mgmt not yet do, due to gateway connected to SIC through tunnel interfaces.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard,&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 06:31:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235124#M63678</guid>
      <dc:creator>kaka</dc:creator>
      <dc:date>2024-12-10T06:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235470#M63679</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I assume the on-prem SmartCenter has a new IP?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When you import the database, SIC is already OK. But gateways have the old IP-address in the database.&lt;BR /&gt;- On old SmartCenter, create a dummy object for the new SmartCenter IP.&lt;BR /&gt;- On old SmartCenter, include the dummy object in rules between SmartCenter and gateways&lt;BR /&gt;- On old SmartCenter, push policy to gateways.&lt;BR /&gt;- Traffic between gateways and new SmartCenter IP is allowed now.&lt;BR /&gt;&lt;BR /&gt;- On the new SmartCenter, make sure traffic between new SmartCenter IP and gateways is allowed.&lt;BR /&gt;- On the new SmartCenter push policy.&lt;BR /&gt;&lt;BR /&gt;You can also follow&amp;nbsp;&lt;SPAN&gt;sk86521-&amp;nbsp;How to reset SIC without restarting the Check Point services&lt;BR /&gt;&lt;/SPAN&gt;But make sure traffic between new SmartCenter IP and gateways is allowed by adding a dummy object.&lt;BR /&gt;&lt;BR /&gt;Good luck.&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 12:44:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235470#M63679</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2024-12-12T12:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235475#M63680</link>
      <description>&lt;P&gt;Personally, I would not move from S1C to on-prem, but if thats decision user made, o well : - ). Anyway, what both&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;had said is valid and I would follow those steps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 13:56:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235475#M63680</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T13:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235515#M63681</link>
      <description>&lt;P&gt;Why not contact TAC ? They could give you hints and be prepared for RAS during the maintenance window when switching over to resolve any unforseen issues !&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 15:46:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235515#M63681</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-12-12T15:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235546#M63682</link>
      <description>&lt;P&gt;We're thinking of going the other way: prem -&amp;gt; cloud for logging and management (10 gw clusters).&amp;nbsp; Can you expand on the reasons why you're going back to prem?&amp;nbsp; &amp;nbsp;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 17:05:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235546#M63682</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2024-12-12T17:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235590#M63683</link>
      <description>&lt;P&gt;Hi mate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main reason's latency and user experience. cloud is a bit slow then on-prem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard, thanks&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 02:17:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235590#M63683</guid>
      <dc:creator>kaka</dc:creator>
      <dc:date>2024-12-13T02:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235592#M63684</link>
      <description>&lt;P&gt;I found and this is just my personal opinion, back in 2020, when I initially started working with S1C, it was not that great, I will admit. But now, I find its great and has gotten way better since then. All customers are already upgraded to R82 version in the cloud and I find the portal is actually even more responsive than before.&lt;/P&gt;
&lt;P&gt;Again, my honest feedback about it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 02:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235592#M63684</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-13T02:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235598#M63685</link>
      <description>&lt;P&gt;yes, obsoletely R82 better then oldest for SIC. but it's customer choice.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 03:03:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235598#M63685</guid>
      <dc:creator>kaka</dc:creator>
      <dc:date>2024-12-13T03:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235599#M63686</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks you for your advises. let me include the mention step with my plan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regard,&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 03:05:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235599#M63686</guid>
      <dc:creator>kaka</dc:creator>
      <dc:date>2024-12-13T03:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235600#M63687</link>
      <description>&lt;P&gt;I think the fact you can make rulebase change from literally any computer with Internet access from anywhere in the world, is a biggest advantage, in my opinion.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 03:18:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/235600#M63687</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-13T03:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/236080#M63688</link>
      <description>&lt;P&gt;Hi guys,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The success migration step with below detail:&lt;/P&gt;&lt;DIV&gt;Checkpoint Firewall Management migration plan&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;1. Change firewall IP address that connect to existing management&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- Go to New mgmt on-prem via SmartConsole --&amp;gt; GATEWAYS &amp;amp; SERVERS&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- Double click on gateway properties, On IPv4 Address: change from MaaS tunnel IP to MGMT IP.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;2. Turn off the management tunnel where connected to existing management&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- SSH to Gateways perform command:maas off &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- Disable/Delete the maas_tunnel interface from topology: [Option]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;3. Reset SIC on Firewall&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- SSH to Gateway with export mode (without restart services)&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;cp_conf sic init [OTP] norestart&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;cpwd_admin stop -name CPD -path "$CPDIR/bin/cpd_admin" -command "cpd_admin stop"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;cpwd_admin start -name CPD -path "$CPDIR/bin/cpd" -command "cpd"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;4. Rejoin checkpoint gateways to new management&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- Gateway Properies&amp;nbsp; &amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- Secure Internal Communication &amp;gt; Communication &amp;gt; Reset &amp;gt; Fill One-time password: [OTP]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- Install policy on gateways &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;6. Verification step&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- Checkpoint firewall status on Dashboard.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- No alert on smartconsole dashboard&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- Testing all blad are working fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;7. Troubleshooting&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;- TAC involve&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Thanks you for your help!!&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 18 Dec 2024 03:48:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/236080#M63688</guid>
      <dc:creator>kaka</dc:creator>
      <dc:date>2024-12-18T03:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Move S1C to On-prem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/236081#M63689</link>
      <description>&lt;P&gt;Awesome job!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 03:59:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Move-S1C-to-On-prem/m-p/236081#M63689</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-18T03:59:36Z</dc:date>
    </item>
  </channel>
</rss>

