<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX hardware replacment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/93164#M8916</link>
    <description>&lt;P&gt;Thanks, seems great !&lt;/P&gt;&lt;P&gt;Only 2 min of downtime would be amazing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Aug 2020 13:23:38 GMT</pubDate>
    <dc:creator>Arthur_DENIS1</dc:creator>
    <dc:date>2020-08-03T13:23:38Z</dc:date>
    <item>
      <title>VSX hardware replacment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/92845#M8911</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need you advise about one of my coming migration.&lt;/P&gt;&lt;P&gt;I have currently 1 VSX cluster running version R80.20 under 12600 appliance, and we planned to replace the hardware with 7000.&lt;BR /&gt;Current interfaces used 10Gb directly on the config, and now we want to use 2Gb under bond interface for each VS.&lt;/P&gt;&lt;P&gt;My idea is this:&lt;BR /&gt;- deploy new boxes with &lt;SPAN&gt;GAIA settings (interfaces, bond, users, DNS, routing for VS0, backups, licenses etc)&lt;/SPAN&gt;&lt;BR /&gt;- integrate into management&lt;BR /&gt;- create all VS/vlan with other unused IP&lt;BR /&gt;- assign same policy package for actual and new VS&lt;/P&gt;&lt;P&gt;Day of the migration:&lt;BR /&gt;- unplug actual box&lt;BR /&gt;- use VSX provisionning tool to replace all temporary IP on new boxes by actual one&lt;/P&gt;&lt;P&gt;Could you please give me you're thinking about this plan? Any better ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Arthur&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 10:16:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/92845#M8911</guid>
      <dc:creator>Arthur_DENIS1</dc:creator>
      <dc:date>2020-07-30T10:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: VSX hardware replacment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/92878#M8912</link>
      <description>&lt;P&gt;I would ask TAC, backed by the local CP SE you should receive any help you need from there. VSX is a complicated product so i would be extreme carefull here...&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 14:59:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/92878#M8912</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-30T14:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: VSX hardware replacment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/92990#M8913</link>
      <description>&lt;P&gt;Indeed, I'm already in liase with my local SE, but get another idea and feedback from previous migration is already great to have &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 09:39:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/92990#M8913</guid>
      <dc:creator>Arthur_DENIS1</dc:creator>
      <dc:date>2020-07-31T09:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: VSX hardware replacment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/93003#M8914</link>
      <description>&lt;P&gt;First of all we connect the new VSX to MAIN01 so all the configuration can be done and box is up and ready for production.&lt;BR /&gt;&lt;BR /&gt;When we do hardware replacement we more or less copy paste with help of VSX provisioning.&lt;BR /&gt;We create the VS the same with all IP and everything but we dont allow the VLAN on the bond interfaces in the switches.&lt;BR /&gt;Communicate with the VSX over VS0 so you are able to push policys etc.&lt;BR /&gt;(We have VS0 on dedicated interface)&lt;BR /&gt;&lt;BR /&gt;Before cut over we normally turn off statefull inspection.&lt;BR /&gt;2-3 hours before the cutover we "freeze" the mgmt station and move all VPN communities etc.&lt;BR /&gt;The only as we see it is that we need to generate a massive amount of eval licenses to put on the CMA as we use DMN VSX licens in all CMA.&lt;BR /&gt;During migration its "only" to remove the VLAN on the trunks to old boxes and add the VLAN on the trunk to the new boxes.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Magnus&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 11:51:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/93003#M8914</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-07-31T11:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: VSX hardware replacment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/93008#M8915</link>
      <description>&lt;P&gt;I would suggest to&amp;nbsp;designate new IPs for new VSX mng inf and configured whole boxes before migration day (all inf expect mng unpluged).&amp;nbsp;&lt;/P&gt;&lt;P&gt;So whole migration take only to unplug old box and plug new ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We used this scenario many times and it make around 2 mins of downtime.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 12:17:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/93008#M8915</guid>
      <dc:creator>Michal_Gans</dc:creator>
      <dc:date>2020-07-31T12:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: VSX hardware replacment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/93164#M8916</link>
      <description>&lt;P&gt;Thanks, seems great !&lt;/P&gt;&lt;P&gt;Only 2 min of downtime would be amazing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 13:23:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-hardware-replacment/m-p/93164#M8916</guid>
      <dc:creator>Arthur_DENIS1</dc:creator>
      <dc:date>2020-08-03T13:23:38Z</dc:date>
    </item>
  </channel>
</rss>

