<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management server relocation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58049#M84992</link>
    <description>&lt;P&gt;If you have to change the IP of the management server anyway, consider creating new VM with the new loopback interface located in /32 network and declaring it as your management interface and two additional interfaces, with IPs in each of your DC networks.&lt;/P&gt;
&lt;P&gt;Re-license your management server to this new IP.&lt;/P&gt;
&lt;P&gt;If you can route to this IP from either location, you should be able to either move the VM into new DC or migrate export/import without further IP changes.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jul 2019 17:18:15 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2019-07-11T17:18:15Z</dc:date>
    <item>
      <title>Management server relocation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58027#M84989</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We need to relocate the management server from a DC that is closing to a new DC environment.&amp;nbsp; We are running the management server as a virtual machine. Currently we have a single management server.&lt;/P&gt;&lt;P&gt;I was wondering if anyone following scenario is possible or if anyone has experience with such a task:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Set up new management server in the new DC using a temporary license.&lt;/LI&gt;&lt;LI&gt;Configure the management server as a secondary management server.&lt;/LI&gt;&lt;LI&gt;Failover the to make the new management server the active server.&lt;/LI&gt;&lt;LI&gt;Move the license to the new management server.&lt;/LI&gt;&lt;LI&gt;Remove old management server.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I have concerns about this process as with a temporary license.&lt;/P&gt;&lt;P&gt;Normally you&amp;nbsp;cannot download and upgrade the new management server to the same version as the old management server. Is it possible to manually import the jumbo Hot fix packages and install them when using a temporary license?&lt;/P&gt;&lt;P&gt;Can I form the management HA when using a temporary license?&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 13:50:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58027#M84989</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2019-07-11T13:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Management server relocation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58031#M84990</link>
      <description>&lt;P&gt;I would assume that just moving the SMS without changing the IP does not need any secondary SMS as step in between - a short maintenance window should be sufficient as long as the managed gateways are still running...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you just copy the SMS VM, transfer it to the new DC, switch the old one off and the new one on all you will loose is the logs during transfer time (although it is possible to get them, too).&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 14:22:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58031#M84990</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-07-11T14:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Management server relocation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58032#M84991</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am not sure if it possible to just transfer the VM to the new location, as the VM environments are completely separated. I will check this. We would still need to change IPs after the migration.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 14:51:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58032#M84991</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2019-07-11T14:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Management server relocation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58049#M84992</link>
      <description>&lt;P&gt;If you have to change the IP of the management server anyway, consider creating new VM with the new loopback interface located in /32 network and declaring it as your management interface and two additional interfaces, with IPs in each of your DC networks.&lt;/P&gt;
&lt;P&gt;Re-license your management server to this new IP.&lt;/P&gt;
&lt;P&gt;If you can route to this IP from either location, you should be able to either move the VM into new DC or migrate export/import without further IP changes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 17:18:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58049#M84992</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-07-11T17:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Management server relocation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58060#M84993</link>
      <description>Which  version are you running at this moment in the old data center?&lt;BR /&gt;With R80.x there are no official migration tools like there were with R77.30 and there it was very well possible to export a SMS and import it to another newly installed machine with R77.30</description>
      <pubDate>Thu, 11 Jul 2019 21:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58060#M84993</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-07-11T21:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Management server relocation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58062#M84994</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are currently running R80.20. Interesting to know there are no official migration tools for this version.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 22:03:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58062#M84994</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2019-07-11T22:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Management server relocation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58063#M84995</link>
      <description>&lt;P&gt;Migration tools are where they always were:&lt;/P&gt;
&lt;P&gt;$FWDIR/bin/upgrade_tools&lt;/P&gt;
&lt;P&gt;use ./migrate export /var/log/nameofthefilewithoutextension&lt;/P&gt;
&lt;P&gt;to produce a tgz&amp;nbsp;&lt;/P&gt;
&lt;P&gt;download it using SCP&lt;/P&gt;
&lt;P&gt;create new VM with new IPs, upload the tgz to it and import the database on it.&lt;/P&gt;
&lt;P&gt;Licenses must be re-issued for new IP address and re-applied.&lt;/P&gt;
&lt;P&gt;If your ICA must be accessible from the outside, the routing to and from new SMS and the rules on the gateways pertaining to your management server must be adjusted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_Installation_and_Upgrade_Guide/207144" target="_self"&gt;Migrating Database Between R80.20 Security Management Servers&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 22:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Management-server-relocation/m-p/58063#M84995</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-07-11T22:33:42Z</dc:date>
    </item>
  </channel>
</rss>

