<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using cloud smart-1 mgmt server as a backup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/104995#M77393</link>
    <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im 99% sure this is not possible, but want to ask anyway : ). I have a prospective CP customer asking me if its possible or feasible at all to have say regular physical smart-1 mgmt server managing their gateways and then also buy smart-1 cloud instance as a backup. Im almost positive that would never work, as they cant manage already managed gateways with a different server, as that only works in management HA...unless they maybe do migrate export from physical smart-1 and then use import feature in cloud instance, not sure if that would function or not...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tx for any feedback!&lt;/P&gt;</description>
    <pubDate>Thu, 10 Dec 2020 14:46:33 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2020-12-10T14:46:33Z</dc:date>
    <item>
      <title>Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/104995#M77393</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im 99% sure this is not possible, but want to ask anyway : ). I have a prospective CP customer asking me if its possible or feasible at all to have say regular physical smart-1 mgmt server managing their gateways and then also buy smart-1 cloud instance as a backup. Im almost positive that would never work, as they cant manage already managed gateways with a different server, as that only works in management HA...unless they maybe do migrate export from physical smart-1 and then use import feature in cloud instance, not sure if that would function or not...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tx for any feedback!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 14:46:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/104995#M77393</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T14:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/104998#M77394</link>
      <description>&lt;P&gt;Just something I forgot to mention...I know while back in R75 I believe, there was a customer I worked with who tried something similar on 2 different smart-1 servers and was able to make it work, but issue in that case was than say if a cluster is managed by smart-1 (lets call it mgmt1) and then you wish to manage same cluster with mgmt2, then you have to break SIC, re-establish all over again, so it was doable, but servers are not in sync, so dont know if thats really best way to go about it...&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 14:55:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/104998#M77394</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T14:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105014#M77395</link>
      <description>&lt;P&gt;Management HA between a cloud and on-prem instance is not currently supported.&lt;BR /&gt;Management HA between an on-prem instance and one you install/manage yourself in the cloud is supported.&lt;BR /&gt;However, you don’t get any of the benefits of Smart-1 Cloud that way.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 15:53:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105014#M77395</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T15:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105018#M77396</link>
      <description>&lt;P&gt;Phoneboy, you are always on top of this community, I love it man : ). Ok, so just to CLARIFY, so I am not mistaken. Are you saying below?&lt;/P&gt;&lt;P&gt;-ONLY management HA can be used? They can not use single smart-1 and sync it with Cloud? Say if they had single smart-1 on prem and wanted to sync it with cloud server, that would not work? Correct? By the way, why would they not get any benefit?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, do you know for example if they did that, would they not have to re-establish sic again? I guess maybe that would not matter too much if policies are the same, but obviously gateways can only be managed by one mgmt server at the time...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 16:05:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105018#M77396</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T16:05:03Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105023#M77397</link>
      <description>&lt;P&gt;You got it.&lt;/P&gt;
&lt;P&gt;Management HA between an on-premise Smart-1 and a self-managed instance in a public cloud is supported.&lt;BR /&gt;If you need to fail over in this case, no re-SIC required as management HA syncs the ICA (among other things) and the gateways are aware of the other manager.&lt;BR /&gt;However…lots of things traffic-wise will be required in/out from that cloud instance.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 16:29:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105023#M77397</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T16:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105024#M77398</link>
      <description>&lt;P&gt;I know once I tested copying policy from one lab mgmt to another and worked fine when I pushed the policy, but I guess that never needed sic reset since both servers and gateways were on same subnet. I think on cloud it would be wayyyyy different...2 questions, 1 related and one not : )&lt;/P&gt;&lt;P&gt;1. Is there any official doc stating what you told me?&lt;/P&gt;&lt;P&gt;2. On unrelated note, is there a way to actually JUST move network objects and hosts from one mgmt server to another? Some type of script or something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tx as always&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 16:33:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105024#M77398</guid>
      <dc:creator>35d69756-ac75-3</dc:creator>
      <dc:date>2020-12-10T16:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105026#M77399</link>
      <description>&lt;P&gt;Thanks as always. So, I have 2 questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Is there any official document as to what you told me and why would management HA be needed instead of single management, just curious?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) More unrelated, but just wondering, is there a script or some way say if you wanted to export ONLY objects and hosts from one mgmt to another without migrating the whole policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tx as always&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 16:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105026#M77399</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T16:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105029#M77400</link>
      <description>&lt;P&gt;Theoretically, you can do what you describe: change the management server to a different one without HA.&lt;BR /&gt;However, it means manually syncing the data and a re-SIC whenever you want to switch over to the other management.&lt;BR /&gt;And...relicensing.&lt;BR /&gt;All of this involves some amount of downtime.&lt;BR /&gt;If you use management HA, you won't have to worry about any of this.&lt;BR /&gt;Your secondary management is effectively a hot standby.&lt;BR /&gt;Note: this doesn't remove the need to do regular backups.&lt;/P&gt;
&lt;P&gt;If you just want to have some way to recover in case your on-premise Smart-1 fails, then your best bet is to take a Migrate Export on a periodic basis.&lt;BR /&gt;This can be restored on another Smart-1 (either appliance or VM) or even stood up in Smart-1 Cloud.&lt;BR /&gt;You will still have to re-license if the management IP/hardware changes, but you can get this up and running fairly quickly.&lt;/P&gt;
&lt;P&gt;There are ways (with the API) to copy out objects if you want to do that.&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/CLI-API-Example-for-exporting-importing-and-deleting-different/m-p/40850#M2766" target="_blank"&gt;https://community.checkpoint.com/t5/API-CLI-Discussion-and-Samples/CLI-API-Example-for-exporting-importing-and-deleting-different/m-p/40850#M2766&lt;/A&gt;&amp;nbsp;is one example (and there are others).&lt;/P&gt;
&lt;P&gt;It really depends on your goal and the amount of downtime you're willing to tolerate.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 17:22:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105029#M77400</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T17:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105034#M77401</link>
      <description>&lt;P&gt;Thanks Dameon...it would be nice if there was an official document or something stating whats supported for this and whats not...otherwise, makes it bit harder for this customer to make a decision. Anyway, on the other hand, for that link you sent, I did see that before, but was not sure which script is right one...any idea? All I want is to export ALL the objects (hosts, networks...etc) from one mgmt server and import them into another one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me look via clish, as I know with some vendors, you just get the config and copy whatever you need without uuid for objects.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 17:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105034#M77401</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-10T17:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Using cloud smart-1 mgmt server as a backup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105041#M77402</link>
      <description>&lt;P&gt;For Security Management information (objects, etc), you need to query using the API or using CLI-based API commands.&lt;BR /&gt;What I pointed you at was the one that has the information separated out so you can import/export just the information you asked for in a relatively easy-to-consume format (CSV).&lt;BR /&gt;The Python Export/Import script (findable on the community) gives you everything relevant to a given Policy Package.&lt;/P&gt;
&lt;P&gt;For the larger issue of documentation, problem is: it's not clear to me what problem the customer is actually trying to solve.&lt;BR /&gt;Even so,&amp;nbsp;I suspect the answer is not contained in a single document as you've presented numerous scenarios.&lt;/P&gt;
&lt;P&gt;For backups of your Security Management (and related items):&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108902&amp;amp;partition=Basic&amp;amp;product=All" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108902&amp;amp;partition=Basic&amp;amp;product=All&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you restore a migrate export in Smart-1 Cloud? Yes, but you need to use the correct migration tool.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-Guide/Topics-Smart-1-Cloud/Using-the-Settings.htm#Migrate" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-Guide/Topics-Smart-1-Cloud/Using-the-Settings.htm#Migrate&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Management HA is covered in the relevant Security Management admin guide.&lt;/P&gt;
&lt;P&gt;Partial copy of configuration from one management to another? Yes, possible using the API.&lt;/P&gt;
&lt;P&gt;Which one is appropriate for the customer? It depends.&lt;BR /&gt;In general, we recommend employing multiple backup/HA strategies as it gives you multiple recovery options in case something goes pear-shaped.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 18:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Using-cloud-smart-1-mgmt-server-as-a-backup/m-p/105041#M77402</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T18:59:03Z</dc:date>
    </item>
  </channel>
</rss>

