<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain migration with VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76264#M81470</link>
    <description>&lt;P&gt;This is a few years old document, but the idea is still the same.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dl3.checkpoint.com/paid/8f/8fcb56b00792fac2b184fec88de319fa/How_to_VSX_Migration_for_Multi-Domain_Management.pdf?HashKey=1582582115_3fd40f93424f6d5e0fc8bceb54ec59dd&amp;amp;xtn=.pdf" target="_blank"&gt;https://dl3.checkpoint.com/paid/8f/8fcb56b00792fac2b184fec88de319fa/How_to_VSX_Migration_for_Multi-Domain_Management.pdf?HashKey=1582582115_3fd40f93424f6d5e0fc8bceb54ec59dd&amp;amp;xtn=.pdf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Feb 2020 20:13:28 GMT</pubDate>
    <dc:creator>Lari_Luoma</dc:creator>
    <dc:date>2020-02-24T20:13:28Z</dc:date>
    <item>
      <title>Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76125#M81466</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running R80.20 MDM HA. We are looking to onboard several domains from different MDM (R77.30) . On R77.30 we have 1 domain with VS0 and another 2 Domains with couple dozen production VS'es.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Do we need to bring over management domain with VS0 first?&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;With R77.30 to R80.20 we should be able to migrate export/import all domains 1by1?&lt;/LI&gt;&lt;LI&gt;Should we expect to re-SIC all VS'es?&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Any other gotchas or considerations?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope somebody can throw some hints or even share some practical experience with such type of change:)&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2020 18:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76125#M81466</guid>
      <dc:creator>guesstimation</dc:creator>
      <dc:date>2020-02-23T18:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76151#M81467</link>
      <description>&lt;P&gt;The only caveat is when you change the name and the IP of the DMS (CMA), otherwise there is no problem in doing so, however I would strongly advise to upgrade the MDS to R80.30 first. Migration from R77.30 to R80.30 works a lot better than any previous version.&lt;BR /&gt;For importing the VSX Domain you will need to issue a command to make sure it will allow the import on the MDS, before each domain import, in expert run:&lt;BR /&gt;touch /AllowVsxMigration&lt;BR /&gt;Then run your import all domains 1 by 1.&lt;/P&gt;
&lt;P&gt;Only start the domains when you are done importing and start with the VS0 domain, this is a recommendation, not a need.&lt;/P&gt;
&lt;P&gt;There should be no need to reset any SIC.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 06:52:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76151#M81467</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-24T06:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76251#M81468</link>
      <description>&lt;P&gt;Thanks Maarten,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you elaborate on a caveat when changing IP addresses? We will try to maintain DMS(CMA) naming, but we will need to change IPs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also any particular reason why R80.30 is better?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 18:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76251#M81468</guid>
      <dc:creator>guesstimation</dc:creator>
      <dc:date>2020-02-24T18:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76263#M81469</link>
      <description>&lt;P&gt;If you change domain names or IP-address you will have to modify vs_slot_objects. This is a file containing links between the main CMA and target CMAs. I will try to find more specific instructions.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 20:07:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76263#M81469</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2020-02-24T20:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76264#M81470</link>
      <description>&lt;P&gt;This is a few years old document, but the idea is still the same.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dl3.checkpoint.com/paid/8f/8fcb56b00792fac2b184fec88de319fa/How_to_VSX_Migration_for_Multi-Domain_Management.pdf?HashKey=1582582115_3fd40f93424f6d5e0fc8bceb54ec59dd&amp;amp;xtn=.pdf" target="_blank"&gt;https://dl3.checkpoint.com/paid/8f/8fcb56b00792fac2b184fec88de319fa/How_to_VSX_Migration_for_Multi-Domain_Management.pdf?HashKey=1582582115_3fd40f93424f6d5e0fc8bceb54ec59dd&amp;amp;xtn=.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 20:13:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76264#M81470</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2020-02-24T20:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76284#M81471</link>
      <description>&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt; That is probably a internal document as I cannot access it.&lt;BR /&gt;TARGET DOMAIN SERVER IP ADDRESS CHANGE&lt;BR /&gt;The modification should be done as follows:&lt;BR /&gt;1. Enter the Main Domain environment using mdsenv (type: mdsenv DomainServer).&lt;BR /&gt;2. Start the dbedit utility by typing dbedit.&lt;BR /&gt;3. For each virtual object, whose Target DomainServer IP has been changed, proceed as follows:&lt;BR /&gt; rmelement vs_slot_objects &amp;lt;object_name&amp;gt; masters_addresses &amp;lt;old_target_domainserver_IP&amp;gt;&lt;BR /&gt; addelement vs_slot_objects &amp;lt;object_name&amp;gt; masters_addresses &amp;lt;new_target_DomainServer_IP&amp;gt;&lt;BR /&gt; update_all&lt;BR /&gt;4. Exit from dbedit utility by typing quit.&lt;BR /&gt;&lt;BR /&gt;Which come down to collect info from all domains with the VSs in it and issue the above commands per domain with the old IP and new IP, where the object name is the name of each VS, including switches.&lt;BR /&gt;You need to do this in the domain where your VS0 resides.&lt;BR /&gt;That should do the trick.</description>
      <pubDate>Tue, 25 Feb 2020 06:00:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76284#M81471</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-25T06:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76285#M81472</link>
      <description>To your question why R80.30 is better, experience.</description>
      <pubDate>Tue, 25 Feb 2020 06:04:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76285#M81472</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-25T06:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76382#M81473</link>
      <description>&lt;P&gt;Thanks Lari, Maarten! This helps:)&lt;BR /&gt;&lt;BR /&gt;I assume this was the document suggested by Lari: &lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=35084" target="_blank" rel="noopener"&gt;http://downloads.checkpoint.com/dc/download.htm?ID=35084&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 18:25:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76382#M81473</guid>
      <dc:creator>guesstimation</dc:creator>
      <dc:date>2020-02-25T18:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Domain migration with VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76505#M81474</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/34691"&gt;@guesstimation&lt;/a&gt;&amp;nbsp;Yep. That's the one. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 22:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-migration-with-VSX/m-p/76505#M81474</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2020-02-26T22:24:48Z</dc:date>
    </item>
  </channel>
</rss>

