<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate from Smart-1 HA SMS to Virtual SMS with new IP in AI Network Firewall</title>
    <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/59093#M84792</link>
    <description>&lt;P&gt;Good Point Vladimir. Does R80.30 support R77.30 gateways and UTM Edge gateways? We are managing UTM Edge gateways through smart provisioning.&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jul 2019 11:53:38 GMT</pubDate>
    <dc:creator>Michael_Thompso</dc:creator>
    <dc:date>2019-07-28T11:53:38Z</dc:date>
    <item>
      <title>Migrate from Smart-1 HA SMS to Virtual SMS with new IP</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/58904#M84788</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I am planning on migrating from a Smart-1 77.30 HA SMS to a Virtual 77.30 SMS with a new IP and ideally new hostname. The gateways managed by the smart-1 SMS perform site-to-site vpns and remote access vpns with the checkpoint client. Also, checkpoint utm edge servers and smb devices are managed by the Smart-1 SMS; these devices are also configured with site-to-site VPNs. I have seen other articles that explain that you need to retain the same IP on the new manager, perform configuration changes e.g. licensing, firewall rules, migrate-import, then you can use the new IP. A couple of questions. How do I connect to the new Virtual SMS with the old IP to make those changes when it is not routable to that part of the network?&amp;nbsp;Second what is the correct procedure to perform this migration? Also what would be the rollback?&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 14:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/58904#M84788</guid>
      <dc:creator>Michael_Thompso</dc:creator>
      <dc:date>2019-07-24T14:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from Smart-1 HA SMS to Virtual SMS with new IP</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/58993#M84789</link>
      <description>When you do the initial install on the new management VM, you can configure it with the new IP.&lt;BR /&gt;Once you migrate import the configuration into the new VM, you will need to change the IP on the management object.&lt;BR /&gt;The gateways will change to the new management IP once you push policy from the new manager to the gateway(s).&lt;BR /&gt;Rollback is pushing policy from the old manager.</description>
      <pubDate>Fri, 26 Jul 2019 01:33:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/58993#M84789</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-26T01:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from Smart-1 HA SMS to Virtual SMS with new IP</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/58994#M84790</link>
      <description>&lt;P&gt;If you are already in the process of migrating, why do so to a new 77.30?&lt;/P&gt;
&lt;P&gt;It is scheduled to be out of support in a few months. Go to R80.30 not to waste the effort.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2019 01:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/58994#M84790</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-07-26T01:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from Smart-1 HA SMS to Virtual SMS with new IP</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/59092#M84791</link>
      <description>&lt;P&gt;Thank you for your response. So that I understand correctly when I migrate import on the new manager it will start using the management IP of the old manager. At that point, the only way I would be able to access the new manager is through the console; since it is a VM and in a different part of the network. In that case, I would have to change the management IP back to the new IP from the cli. Then connect using smartdashboard and change to the new ip on the management object. Finally, push policy to the gateways. Does that sound about right?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 11:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/59092#M84791</guid>
      <dc:creator>Michael_Thompso</dc:creator>
      <dc:date>2019-07-28T11:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from Smart-1 HA SMS to Virtual SMS with new IP</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/59093#M84792</link>
      <description>&lt;P&gt;Good Point Vladimir. Does R80.30 support R77.30 gateways and UTM Edge gateways? We are managing UTM Edge gateways through smart provisioning.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 11:53:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/59093#M84792</guid>
      <dc:creator>Michael_Thompso</dc:creator>
      <dc:date>2019-07-28T11:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from Smart-1 HA SMS to Virtual SMS with new IP</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/59096#M84793</link>
      <description>R77.30 gateways are supported.&lt;BR /&gt;UTM-1 EDGE devices? Depends on the vintage.&lt;BR /&gt;Most of them are End of Support.&lt;BR /&gt;&lt;BR /&gt;The pre-upgrade verifier for R80.30 can be used to validate if you have any "out of support" gateways.&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/html_frameset.htm&lt;/A&gt;</description>
      <pubDate>Sun, 28 Jul 2019 13:11:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/59096#M84793</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-28T13:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from Smart-1 HA SMS to Virtual SMS with new IP</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/62797#M84794</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;Per the upgrade guide of R80.20 and R80.30... "&lt;STRONG&gt;Important:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="tpbodytext"&gt;The IP addresses of the source and target R80.30 Security Management Servers&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;must be the same&lt;/STRONG&gt;. If you need to have a different IP address on the R80.30 Security Management Server, you can change it only after the upgrade procedure. Note that you have to issue licenses for the new IP address. For applicable procedures, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk40993&amp;amp;js_peid=P-114a7bc3b09-10006&amp;amp;partition=General&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk40993&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A title="" href="http://supportcontent.checkpoint.com/solutions?id=sk65451" target="_blank" rel="noopener"&gt;sk65451&lt;/A&gt;."&lt;/P&gt;&lt;P class="tpbodytext"&gt;Does this mean I can follow the same steps PhoneBoy suggested for R80.20 and R80.30? Does "Upgrade procedure" mean after the migrate import or the install database from the upgrade guide?&amp;nbsp;&lt;/P&gt;&lt;P class="tpbodytext"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Sep 2019 12:45:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/62797#M84794</guid>
      <dc:creator>Michael_Thompso</dc:creator>
      <dc:date>2019-09-15T12:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate from Smart-1 HA SMS to Virtual SMS with new IP</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/62817#M84795</link>
      <description>In this case, the "upgrade procedure" is the migrate export/import.&lt;BR /&gt;I believe you can configure the new management VM with the new IP before the migrate import.&lt;BR /&gt;After that, you can apply the new licenses and change the configuration to support the new IP as described in sk65451 and sk40993 as needed.</description>
      <pubDate>Sun, 15 Sep 2019 23:37:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Migrate-from-Smart-1-HA-SMS-to-Virtual-SMS-with-new-IP/m-p/62817#M84795</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-15T23:37:43Z</dc:date>
    </item>
  </channel>
</rss>

