<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate management to AWS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128665#M74643</link>
    <description>&lt;P&gt;Assuming you are migrating the management server using the migration tools, you shouldn’t need to reset SIC even if you change IP.&lt;BR /&gt;A few things off the top of my head:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The management instance in AWS will have private addressing on its interfaces.&lt;/LI&gt;
&lt;LI&gt;It’s assumed the NAT will be done by AWS when the elastic IP is assigned.&lt;/LI&gt;
&lt;LI&gt;The main IP of the management server (in the General tab of the object) should reflect the assigned elastic IP.&lt;/LI&gt;
&lt;LI&gt;Gateways are migrated to the new management server by simply pushing policy from it (assuming all of the above was done successfully)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;it might be tricky to ensure that no logs are lost as part of this migration process.&lt;BR /&gt;Logs should probably be migrated separately and you may want to shut down the original management at some point before copying the logs over.&lt;BR /&gt;This should cause logs to queue up on the gateways, which will continue to operate normally.&lt;BR /&gt;The logs will stream to the new management once policy is pushed.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Sep 2021 20:59:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-09-02T20:59:36Z</dc:date>
    <item>
      <title>Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128616#M74640</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are soon getting rid of a datacenter and are planning the migration of hosted ressources to AWS.&lt;/P&gt;&lt;P&gt;This will include our Check Point management appliance (R81, OpenServer), that manages 40+ firewalls worldwide. We have a lot of small business firewalls in remote offices (1430/1450) and other models like 3100, etc...&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to avoid any impact, and in some cases we won't have remote hands (no personnel onsite to grant us a remote session to connect the firewall with console). So, do you have some sort of guidelines/procedures on how to handle that task ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The new management in AWS will have different IP addressing, so I guess we'll have to reset the SIC on the gateways, right ? Can all that be done remotely, is there any trick to perform that smoothly ?&lt;/P&gt;&lt;P&gt;Thanks in advance for your advises, much appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 08:47:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128616#M74640</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-02T08:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128627#M74641</link>
      <description>&lt;P&gt;I saw someone asked similar question before, but dont recall there was an easy way to do this though. Since it would be brand new management, even if its on-prem, you would definitely need to establish SIC on the gateways, so that step can be done remotely, but its a bit risky, because it would not be easy to troubleshoot it if it fails, as it may require console access. It might involve unloading the policy, which is just a simple command, but then the rest could be a bit tricky. I will let experts give you suggestions, but personally, Im not aware of one click solution to this, sorry,&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 11:00:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128627#M74641</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-02T11:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128629#M74642</link>
      <description>&lt;P&gt;I also believe there is a requirement to use private addressing in the cloud so if you are using public address space internally this may be something to consider (if the above is actually correct).&lt;/P&gt;
&lt;P&gt;I suspect a number of us are now looking to migrate the management layer into the cloud but I've seen very little on this.&amp;nbsp; Would be great to have a walk through for a SMS and for MDS.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 11:33:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128629#M74642</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-09-02T11:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128665#M74643</link>
      <description>&lt;P&gt;Assuming you are migrating the management server using the migration tools, you shouldn’t need to reset SIC even if you change IP.&lt;BR /&gt;A few things off the top of my head:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The management instance in AWS will have private addressing on its interfaces.&lt;/LI&gt;
&lt;LI&gt;It’s assumed the NAT will be done by AWS when the elastic IP is assigned.&lt;/LI&gt;
&lt;LI&gt;The main IP of the management server (in the General tab of the object) should reflect the assigned elastic IP.&lt;/LI&gt;
&lt;LI&gt;Gateways are migrated to the new management server by simply pushing policy from it (assuming all of the above was done successfully)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;it might be tricky to ensure that no logs are lost as part of this migration process.&lt;BR /&gt;Logs should probably be migrated separately and you may want to shut down the original management at some point before copying the logs over.&lt;BR /&gt;This should cause logs to queue up on the gateways, which will continue to operate normally.&lt;BR /&gt;The logs will stream to the new management once policy is pushed.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 20:59:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128665#M74643</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-02T20:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128697#M74644</link>
      <description>&lt;P&gt;Thanks for your comment ! Looks like this is the approach we'd like to achieve.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any guidelines for that or maybe a step-by-step guide or a successful scenario ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we have 40+ gateways, we'd like to phase the work over 2-3 weeks, and need assurance we could rollback if anything wrong happen. Can we have 2 management servers working at the same time, with the same DB (as I'll indeed use the migration tools to export the DB from the current and import in AWS) ?&lt;/P&gt;&lt;P&gt;Thanks for your help !&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 08:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128697#M74644</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-03T08:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128716#M74645</link>
      <description>&lt;P&gt;I don’t think it’s much more complicated than I described above.&lt;BR /&gt;I’ve done almost this exact thing in the lab when I rebuild my management server on a different IP and it generally works.&lt;BR /&gt;I would try it in the lab just so you can see how it works.&lt;/P&gt;
&lt;P&gt;Theoretically, you can keep both management servers up in parallel.&lt;BR /&gt;However, you’ll have to keep the configuration in sync somehow.&lt;BR /&gt;And I’m not sure how VPNs would handle this (thinking about fetching the CRL).&lt;BR /&gt;Not even sure you need to do this over the course of 2-3 weeks as it shouldn’t take you that long to actually push policy to all the gateways.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 15:57:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128716#M74645</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-03T15:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128844#M74646</link>
      <description>&lt;P&gt;Thanks. I'm indeed worried about how the numerous S2S VPN we have will be behaving. I'll try to start a lab and test all this.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Sep 2021 08:17:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128844#M74646</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-07T08:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128960#M74647</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I was wondering if adding a secondary management server in AWS and following R81 guide for Management HA would do the trick ? Could that work in this situation ? I would imagine having that HA environment and once synchronised, promoting the AWS instance as primary, and decomission the old one.&lt;/P&gt;&lt;P&gt;What's your opinion on this approach ?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2021 07:27:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/128960#M74647</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-09T07:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/129405#M74648</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;So I've managed to launch an EC2 instance from the AMI found in the marketplace, so far so good. I've configured it as a Management HA, so it syncs with the primary/current management appliance alright. I've tested and made the AWS one active, and push policies, all looks fine !&lt;/P&gt;&lt;P&gt;But my next question relates to the sizing of the EC2 instance. So far I've chose a m5.2xlarge, but the CPU usage is 98%. I'll move to a m5.4xlarge, which doubles the CPU cores.&lt;/P&gt;&lt;P&gt;My concern is about the storage. How can I determine the Iops and Throughput I need to set for the gp3 disks ? Is there any guidelines based on the number of gateways we manages, etc... ?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 12:19:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/129405#M74648</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2021-09-14T12:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/185133#M74649</link>
      <description>&lt;P&gt;Looks like it's been a while, but did you get this all going?&amp;nbsp; &amp;nbsp;I'm trying to do the same, one manager on prem, and the other in the cloud but the management HA wont form because the version numbers are different. I've logged a case but thought I'd mention it in case you hit that and fixed it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 05:27:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/185133#M74649</guid>
      <dc:creator>nzmatto1</dc:creator>
      <dc:date>2023-06-29T05:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate management to AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/185188#M74650</link>
      <description>&lt;P&gt;Management HA is only supported between members that have the exact same version/JHF level.&lt;BR /&gt;You will have to use the standard migration tools (migrate_server) if the versions are different.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 16:40:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-management-to-AWS/m-p/185188#M74650</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-29T16:40:07Z</dc:date>
    </item>
  </channel>
</rss>

