<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Full HA R77.30 to R80.40 Distributed architevture with VM Open server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111512#M76607</link>
    <description>&lt;P&gt;In between those moments, the cp_conf gullah disable and the import Database on the VM, will I've downtime? In that case, how can I reduce that?&lt;/P&gt;</description>
    <pubDate>Mon, 22 Feb 2021 14:24:41 GMT</pubDate>
    <dc:creator>Cesar_Santos</dc:creator>
    <dc:date>2021-02-22T14:24:41Z</dc:date>
    <item>
      <title>Full HA R77.30 to R80.40 Distributed architevture with VM Open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111360#M76601</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;I would like to have your thougs on a migration from a deployment of a Full HA of two 5100 in R77.30 to a Distributed deployment in R80.40. On the new deployment I'll have a VM on Hyper-V dedicated as the management station.&lt;/P&gt;&lt;P&gt;So far I've installed the VM with the R77.30 software and with the same Jumbo version of my Full HA deployment on the production environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've read some quite of the documentation available on this in the security knowledge base and here in Checkmates, but I'm still not comfartable with the whole process.&lt;/P&gt;&lt;P&gt;I know that first I need to go with the conversion to the Distributed architecture. But how can I proceed safely? Should I migrate export on the HA cluster first and migrate import on the VM and then disable the management role on my 5100? Or should I go the other way around?&lt;/P&gt;&lt;P&gt;What should be my approach on this? It is possible to avoid any downtime on this? If it was just an upgrade I know it is possible to have different versions on the cluster members, avoiding downtime. But with conversion I don't know if it is possible to achieve that.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 11:33:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111360#M76601</guid>
      <dc:creator>Cesar_Santos</dc:creator>
      <dc:date>2021-02-20T11:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Full HA R77.30 to R80.40 Distributed architevture with VM Open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111374#M76602</link>
      <description>&lt;P&gt;I would suggest making the change to distributed prior to upgrading to R80.40.&lt;BR /&gt;The procedure on R77.30 is:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44201&amp;amp;partition=Advanced&amp;amp;product=ClusterXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44201&amp;amp;partition=Advanced&amp;amp;product=ClusterXL&lt;/A&gt;,&lt;BR /&gt;There is no “zero downtime” option for this sort of conversion.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2021 18:07:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111374#M76602</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-20T18:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: Full HA R77.30 to R80.40 Distributed architevture with VM Open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111478#M76603</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Thanks for your reply. I've already checked the&amp;nbsp;&lt;SPAN&gt;sk44201 and my question here is not about the steps, but about the process. Can I do it&amp;nbsp;remotely in one member at a time? Or should I do it on site? What is the expected time window to do this? Please be aware this is a customer on the public healthcare system.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;César Santos&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 08:58:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111478#M76603</guid>
      <dc:creator>Cesar_Santos</dc:creator>
      <dc:date>2021-02-22T08:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Full HA R77.30 to R80.40 Distributed architevture with VM Open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111494#M76604</link>
      <description>&lt;P&gt;I would not suggest to do this remotely ! The important step is to get the SMS database from the primary Management node and install it in a VM.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 11:55:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111494#M76604</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-02-22T11:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Full HA R77.30 to R80.40 Distributed architevture with VM Open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111501#M76605</link>
      <description>&lt;P&gt;Hi G_W_Albrecht,&lt;/P&gt;&lt;P&gt;Thanks for your input. I'll schedule a maintenance window to run the procedure on site.&lt;/P&gt;&lt;P&gt;About the important step, should I import the SMS database on the VM right now? Or only after the "Convert to host..." step of the procedure.&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 12:47:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111501#M76605</guid>
      <dc:creator>Cesar_Santos</dc:creator>
      <dc:date>2021-02-22T12:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Full HA R77.30 to R80.40 Distributed architevture with VM Open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111504#M76606</link>
      <description>&lt;P&gt;According to sk44201, you will perform migrate export only after cp_conf fullha disable, Convert to Host... and Install Database...&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 12:58:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111504#M76606</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-02-22T12:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Full HA R77.30 to R80.40 Distributed architevture with VM Open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111512#M76607</link>
      <description>&lt;P&gt;In between those moments, the cp_conf gullah disable and the import Database on the VM, will I've downtime? In that case, how can I reduce that?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 14:24:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111512#M76607</guid>
      <dc:creator>Cesar_Santos</dc:creator>
      <dc:date>2021-02-22T14:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Full HA R77.30 to R80.40 Distributed architevture with VM Open server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111513#M76608</link>
      <description>&lt;P&gt;Not if you follow the steps. The Secondary Full HA cluster member will run as the Active member in the cluster to continue passing traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 14:30:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Full-HA-R77-30-to-R80-40-Distributed-architevture-with-VM-Open/m-p/111513#M76608</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-02-22T14:30:39Z</dc:date>
    </item>
  </channel>
</rss>

