<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrading Checkpoint management to R80.X from R77.30 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64143#M83748</link>
    <description>To be frank I would skip R80.10 altogether, I have a MDS which was migrated many times as well and I moved a number of domains manually from that server to another MDS running R80.10. I had loads of problems with validation errors and other stuff that did not work properly.&lt;BR /&gt;When we upgraded that R80.10 MDS to R80.30 we again ran into a lot of issues with validations on the same domains. Both times TAC and R&amp;amp;D were needed to resolve the problems.&lt;BR /&gt;Recently I migrated the R77.30 to R80.30 and had no problems of the sort at all.</description>
    <pubDate>Wed, 02 Oct 2019 09:41:38 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-10-02T09:41:38Z</dc:date>
    <item>
      <title>Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/63804#M83745</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a 17 years old Checkpoint standalone management server, was originally 4.1 and was upgrade through the years to R77.30.&lt;/P&gt;&lt;P&gt;I would like to upgrade the management server to R80.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was able to export and import the configuration on a new R80.10 server, but the CPM service was not started.&lt;/P&gt;&lt;P&gt;I was found it is related to the ICA.&lt;/P&gt;&lt;P&gt;I understand I would need to upgrade the ICA certificate to a new version. (SHA-256)&lt;/P&gt;&lt;P&gt;I have many VPNs the relays on this ICA. In addition, I have many users in the internal database, that are using user certificates for remote access authentication, issued by the ICA.&lt;/P&gt;&lt;P&gt;What would be the best way to update the ICA certificate without causing problems to the VPNs and the user authentication?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 11:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/63804#M83745</guid>
      <dc:creator>Michael-Polevoy</dc:creator>
      <dc:date>2019-09-27T11:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/63829#M83746</link>
      <description>&lt;P&gt;Have you seen &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103840&amp;amp;partition=General&amp;amp;product=Security" target="_self"&gt;this sk?&lt;/A&gt;&amp;nbsp;I think it explains how to accomplish what it is you need to do.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2019 13:21:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/63829#M83746</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2019-09-27T13:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64139#M83747</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks for the article.&lt;/P&gt;&lt;P&gt;What about the ICA itself which is&lt;/P&gt;&lt;P&gt;Not Valid Before: Wed Jun 19 11:53:44 2002 Local Time&lt;BR /&gt;Not Valid After: Tue Jun 14 11:53:44 2022 Local Time&lt;BR /&gt;Serial No.: 1&lt;BR /&gt;Public Key: RSA (1024 bits)&lt;BR /&gt;Signature: RSA with SHA1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will it block me from upgrading to R80.X?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 08:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64139#M83747</guid>
      <dc:creator>Michael-Polevoy</dc:creator>
      <dc:date>2019-10-02T08:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64143#M83748</link>
      <description>To be frank I would skip R80.10 altogether, I have a MDS which was migrated many times as well and I moved a number of domains manually from that server to another MDS running R80.10. I had loads of problems with validation errors and other stuff that did not work properly.&lt;BR /&gt;When we upgraded that R80.10 MDS to R80.30 we again ran into a lot of issues with validations on the same domains. Both times TAC and R&amp;amp;D were needed to resolve the problems.&lt;BR /&gt;Recently I migrated the R77.30 to R80.30 and had no problems of the sort at all.</description>
      <pubDate>Wed, 02 Oct 2019 09:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64143#M83748</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-02T09:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64144#M83749</link>
      <description>&lt;P&gt;You can start by downloading the R80.30 Migrate Tools and running the Pre-Upgrade Verifier&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=84076" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=84076&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 09:47:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64144#M83749</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2019-10-02T09:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64156#M83750</link>
      <description>&lt;P&gt;Tal,&lt;/P&gt;&lt;P&gt;I run the pre-upgrade tool of R80.30.&lt;/P&gt;&lt;P&gt;It did not stated any problems with the ICA, certificates, or SHA-1.&lt;/P&gt;&lt;P&gt;This is the behavior I had once I tried to migrate to R80.10, but once the migrate import had finished the CPM service was not started.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 12:36:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64156#M83750</guid>
      <dc:creator>Michael-Polevoy</dc:creator>
      <dc:date>2019-10-02T12:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64157#M83751</link>
      <description>&lt;P&gt;Hi Micheal&lt;/P&gt;
&lt;P&gt;Thanks for updating me. I will check why this is not part of the Pre-Upgrade Verifier checks (and look into adding it to newer versions of the Migrate Tools.)&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Tal&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2019 12:40:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64157#M83751</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2019-10-02T12:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64158#M83752</link>
      <description>Tal,&lt;BR /&gt;&lt;BR /&gt;While you are at that, could you also ask why the user.def file is not reported in the Pre-Upgrade Verifier?&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Oct 2019 12:58:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/64158#M83752</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-02T12:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading Checkpoint management to R80.X from R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/65138#M83753</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I got a fix and below procedure from the support&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;install provided hotfix&lt;/LI&gt;&lt;LI&gt;cpca_client set_sign_hash sha256&lt;/LI&gt;&lt;LI&gt;cpca_client re_sign_ca&lt;/LI&gt;&lt;LI&gt;sicRenew -d&lt;/LI&gt;&lt;LI&gt;mv $CPDIR/conf/new_sic_cert.p12 $CPDIR/conf/sic_cert.p12&lt;/LI&gt;&lt;LI&gt;cpstop; cpstart (make sure the server is up again)&lt;/LI&gt;&lt;LI&gt;mcc lca (copy the presented ca name)&lt;/LI&gt;&lt;LI&gt;mcc replace ~/new_ica.cer&lt;/LI&gt;&lt;LI&gt;cpstop; cpstart&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I completed steps 1 to 6 and was able to start the management services including the CPM.&lt;/P&gt;&lt;P&gt;Do someone knows what steps 7 to 9 are doing?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 18:48:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrading-Checkpoint-management-to-R80-X-from-R77-30/m-p/65138#M83753</guid>
      <dc:creator>Michael-Polevoy</dc:creator>
      <dc:date>2019-10-16T18:48:26Z</dc:date>
    </item>
  </channel>
</rss>

