<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrate R77.30 standalone system to R80.10 Distributed system in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35551#M97258</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Confwiz?!&amp;nbsp;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/confused.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;First you should do a snapshot and a backup, as you said. And preferably transfer them from the device. But you cannot import snapshot/backup created for R77.30 version into R80.10.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Then, it seems you need to create a temporary R77.30 management server (distributed deployment). It could be a virtual machine with a clean install. It is not clear if you have several standalone devices, each with its own local management server, or only one standalone device to which several firewalls are connected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;There is&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61681" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61681"&gt;sk61681&lt;/A&gt;&amp;nbsp;which explains how to migrate from standalone device to separate management server on R77.30. You need also to collect cpinfo, as it is written in the SK (although, I am not sure why).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;To export the security management part (&lt;SPAN&gt;Policies, Firewall and NAT rules, Objects and services) you should use R77.30 migration tools (&lt;STRONG style="font-size: 12px; font-family: terminal, monaco, monospace;"&gt;migrate export&lt;/STRONG&gt; command). Then do some manipulations with text files and import it to the temporary R77.30 machine with &lt;STRONG style="background-color: #ffffff; font-size: 12px; font-family: terminal, monaco, monospace;"&gt;migrate import&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;Then you use R80.10 migration tools to export database from temporary R77.30 machine and import it to the newly installed Smart-1. Don't forget to install the latest Jumbo Hotfix on it too.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;There is a simpler way if you need to save only rules and objects (without certificates, users, some specific global settings). Use &lt;STRONG style="font-size: 12px; font-family: terminal, monaco, monospace;"&gt;cp_merge export_policy&lt;/STRONG&gt; to export only firewall and NAT rules (&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33751" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33751"&gt;sk33751&lt;/A&gt;), copy &lt;SPAN style="font-size: 12px; font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;$FWDIR/conf/objects_5_0.C&lt;/STRONG&gt;&lt;/SPAN&gt; file containing all objects and services from the old R77.30 device. Then use a temporary R77.30 installation configured as only a management server to import objects with&amp;nbsp;&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 12px;"&gt;&lt;STRONG&gt;cp_merge merge_objects&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;and then import&amp;nbsp;&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 12px;"&gt;&lt;STRONG style="background-color: #ffffff; font-size: 12px;"&gt;cp_merge import_policy&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;. Delete an object of old standalone device and create new firewalls objects.&amp;nbsp;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;Then use R80.10 migration tools&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;to export database from temporary R77.30 machine and import it to the newly installed Smart-1.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 17 Mar 2018 10:56:50 GMT</pubDate>
    <dc:creator>AlekseiShelepov</dc:creator>
    <dc:date>2018-03-17T10:56:50Z</dc:date>
    <item>
      <title>Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35545#M97252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone can advice what is the best approach to migrate R77.30 standalone system to R80.10 Distributed system&lt;/P&gt;&lt;P&gt;I have few firewalls running on R77.30 with hundreds of rule in it(some enabled with application filtering some not) and installed as standalone.&lt;/P&gt;&lt;P&gt;Now there is a requirement to upgrade all the firewalls to R80.10 and move all to the newly purchased Smart-1.&lt;/P&gt;&lt;P&gt;Your valuable advice is very much appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 04:32:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35545#M97252</guid>
      <dc:creator>Anoopkumar_Kuzh</dc:creator>
      <dc:date>2018-03-15T04:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35546#M97253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would migrate export the R77.30 firewall management config and follow &lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/5491-policy-migration-from-standalone-to-distributed"&gt;this procedure&lt;/A&gt; in order to properly import it to the Smart-1 Appliances (&lt;EM&gt;you may need to import to R77.30 first and then upgrade to R80.10&lt;/EM&gt;). Then I would do a fresh install of R80.10 on the gateways.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 07:35:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35546#M97253</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-03-15T07:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35547#M97254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems that &lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk61681 (it is written there in bold) as well as &lt;SPAN&gt;sk85900 (as the last change was two years ago) do NOT apply to R80.x. So the procedure would be to go for distributed R77.30, upgrade the SMS to R80.10 and then change the GW(s). I hope a way to go from R80.10 StandAlone to distibuted will be provided soon...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 09:12:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35547#M97254</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-15T09:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35548#M97255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The big issue is that he wrote, that there are more than one standalone boxes.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your approaches are fine for the first migration but others are manual work, if the destination is not a MDM environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 13:50:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35548#M97255</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2018-03-15T13:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35549#M97256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, he will need to get several rulebases together to one Smart-1 using &lt;STRONG&gt; &lt;CODE&gt;cp_merge&lt;/CODE&gt; utility&lt;/STRONG&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2018 14:24:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35549#M97256</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-15T14:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35550#M97257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Appreciate all your valuable advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the above comments and what I understood so far, here is how I am planning to proceed:&lt;/P&gt;&lt;P&gt;&amp;gt; Take a snapshot/backup of the current Security Gateway R77.30&lt;BR /&gt;&amp;gt; Export all the current configuration(Policies, firewall &amp;amp; NAT rules, Objects and services) from Security management server using Confwiz &lt;BR /&gt;&amp;gt; Do a clean installation of R80.10 as distributed and import the snapshot/backup taken earlier&lt;BR /&gt;&amp;gt; Use sk113078 to import the Security Management Server configurations to the new SMART-1 appliance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current Setup:&lt;BR /&gt;1. R77.30&lt;BR /&gt;2. Standalone installation&lt;BR /&gt;3. hotfix - 286&lt;BR /&gt;4. Logserver within management gateway&lt;/P&gt;&lt;P&gt;=============&lt;BR /&gt;New setup:&lt;BR /&gt;1. R80.10&lt;BR /&gt;2. Distributed installation&lt;BR /&gt;3. Log server in Smart-1&lt;/P&gt;&lt;P&gt;==============&lt;/P&gt;&lt;P&gt;Let me know if anything wrong with this approach.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2018 06:31:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35550#M97257</guid>
      <dc:creator>Anoopkumar_Kuzh</dc:creator>
      <dc:date>2018-03-16T06:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35551#M97258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Confwiz?!&amp;nbsp;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/confused.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;First you should do a snapshot and a backup, as you said. And preferably transfer them from the device. But you cannot import snapshot/backup created for R77.30 version into R80.10.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Then, it seems you need to create a temporary R77.30 management server (distributed deployment). It could be a virtual machine with a clean install. It is not clear if you have several standalone devices, each with its own local management server, or only one standalone device to which several firewalls are connected.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;There is&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61681" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61681"&gt;sk61681&lt;/A&gt;&amp;nbsp;which explains how to migrate from standalone device to separate management server on R77.30. You need also to collect cpinfo, as it is written in the SK (although, I am not sure why).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;To export the security management part (&lt;SPAN&gt;Policies, Firewall and NAT rules, Objects and services) you should use R77.30 migration tools (&lt;STRONG style="font-size: 12px; font-family: terminal, monaco, monospace;"&gt;migrate export&lt;/STRONG&gt; command). Then do some manipulations with text files and import it to the temporary R77.30 machine with &lt;STRONG style="background-color: #ffffff; font-size: 12px; font-family: terminal, monaco, monospace;"&gt;migrate import&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;Then you use R80.10 migration tools to export database from temporary R77.30 machine and import it to the newly installed Smart-1. Don't forget to install the latest Jumbo Hotfix on it too.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;There is a simpler way if you need to save only rules and objects (without certificates, users, some specific global settings). Use &lt;STRONG style="font-size: 12px; font-family: terminal, monaco, monospace;"&gt;cp_merge export_policy&lt;/STRONG&gt; to export only firewall and NAT rules (&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33751" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33751"&gt;sk33751&lt;/A&gt;), copy &lt;SPAN style="font-size: 12px; font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;$FWDIR/conf/objects_5_0.C&lt;/STRONG&gt;&lt;/SPAN&gt; file containing all objects and services from the old R77.30 device. Then use a temporary R77.30 installation configured as only a management server to import objects with&amp;nbsp;&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 12px;"&gt;&lt;STRONG&gt;cp_merge merge_objects&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;and then import&amp;nbsp;&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 12px;"&gt;&lt;STRONG style="background-color: #ffffff; font-size: 12px;"&gt;cp_merge import_policy&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;. Delete an object of old standalone device and create new firewalls objects.&amp;nbsp;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;Then use R80.10 migration tools&amp;nbsp;&lt;SPAN style="background-color: #ffffff;"&gt;to export database from temporary R77.30 machine and import it to the newly installed Smart-1.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Mar 2018 10:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35551#M97258</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-03-17T10:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35552#M97259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a same problem.&lt;/P&gt;&lt;P&gt;I am planning to do all configurations by manually. But we have too much network objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to export hosts and networks to csv?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current stand-alone appliance running on R77.20 and new distributed appliances are R80.10.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Apr 2018 09:34:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35552#M97259</guid>
      <dc:creator>Gomboragchaa</dc:creator>
      <dc:date>2018-04-06T09:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35553#M97260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Possible, refer to the below link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/5691-migrate-r7730-policy-to-r8010-trought-management-api" target="_blank"&gt;https://community.checkpoint.com/thread/5691-migrate-r7730-policy-to-r8010-trought-management-api&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:21:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35553#M97260</guid>
      <dc:creator>Anoopkumar_Kuzh</dc:creator>
      <dc:date>2019-06-21T09:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35554#M97261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all your feedback, really appreciate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Considering the complexity and lesser&amp;nbsp;downtime allowed to me, below are the method I followed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Configure all the policies in existing R80.10 management server(MDM) and kept it ready before my activity&lt;/P&gt;&lt;P&gt;&amp;gt; During the downtime, i reset&amp;nbsp;Firewall 2 into default R77.30 image&lt;/P&gt;&lt;P&gt;&amp;gt; Brought up the Firewall 2 and configured it as Gateway only (distributed)&lt;/P&gt;&lt;P&gt;&amp;gt; Upgraded the&amp;nbsp;Firewall 2 from CPUSE (from R77.30 to R80.10)&lt;/P&gt;&lt;P&gt;&amp;gt; Configured basic settings such as interface and all from GUI/CLI&lt;/P&gt;&lt;P&gt;&amp;gt; Did the same&amp;nbsp;to Firewall 1&lt;/P&gt;&lt;P&gt;&amp;gt; Created a cluster object and added both Firewall 1 and Firewall 2 into it (by initializing SIC)&lt;/P&gt;&lt;P&gt;&amp;gt; Marked the pre-configured policy file to the cluster and pushed the policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manual work is a lot for policy creation in the new R80.10 management server however this method worked.. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2018 06:56:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35554#M97261</guid>
      <dc:creator>Anoopkumar_Kuzh</dc:creator>
      <dc:date>2018-04-09T06:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35555#M97262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tried the last option you have suggested to import only rules and objects. It worked fine however didn't serve my purpose as my SMART-1 is not clean. It has other gateways/clusters added and policy files installed. When I import the new Object/Policy package,&amp;nbsp;old ones are getting removed. Not sure if there is anyway to add-on rather than overwriting the existing DB.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 05:05:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35555#M97262</guid>
      <dc:creator>Anoopkumar_Kuzh</dc:creator>
      <dc:date>2018-04-12T05:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35556#M97263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Usually that happens when I just replace &lt;STRONG style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold; font-size: 12px;"&gt;$FWDIR/conf/objects_5_0.C&amp;nbsp;&lt;/STRONG&gt;file. But with &lt;STRONG style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold; font-size: 12px;"&gt;cp_merge merge_objects&amp;nbsp;&lt;/STRONG&gt;command everything should be fine, it adds new objects from the copied file to the current database and shouldn't delete old objects. Basically, you should copy old&amp;nbsp;&lt;STRONG style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold; font-size: 12px;"&gt;$FWDIR/conf/objects_5_0.C&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;file to some temp folder (&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 12px;"&gt;/var/log/tmp&lt;/SPAN&gt;), go there (&lt;SPAN style="font-family: terminal, monaco, monospace; font-size: 12px;"&gt;cd /var/log/tmp&lt;/SPAN&gt;) and run&amp;nbsp;&lt;STRONG style="color: #333333; background-color: #ffffff; border: 0px; font-weight: bold; font-size: 12px;"&gt;cp_merge merge_objects&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;command there.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was referring to this part of &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33751" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33751"&gt;sk33751&lt;/A&gt;&amp;nbsp;:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;H2 style="color: #333333; background-color: #ffffff; font-weight: bold; font-size: 22px; margin: 0px; padding: 10px 0px 0px;"&gt;Procedure: Import on target Security Management server&lt;/H2&gt;&lt;OL style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;LI&gt;Go to the target (merging) machine and create a temporary&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;import&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;directory, for example&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;/home/admin/import&lt;/EM&gt;.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Transfer all files that were exported from the source machine to the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;import&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;directory.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Run the following from the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;import&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;directory:&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;To merge the object files, run:&lt;/P&gt;&lt;EM&gt;[Expert@HostName]# cp_merge merge_objects&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;To import Security policy, run:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[Expert@HostName]# cp_merge import_policy -f &amp;lt;&lt;EM&gt;policy_name&lt;/EM&gt;&amp;gt;.pol -n &amp;lt;&lt;EM&gt;new_policy_name&lt;/EM&gt;&amp;gt;&lt;/EM&gt;&lt;/P&gt;Each Security policy should be installed separately and named accordingly.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;Repeat the previous step until all Security policies will be installed.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;UL style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;LI&gt;The merge operation uses the object name as a key. Objects with the same names in both the source and destination databases will not be merged, even if other properties (like IP address) are different. It is up to the administrator to resolve any issues with name collisions (this is best done by editing the source or destination databases before export / import).&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;cp_merge&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;does not overwrite ANY duplicated entry - it will not enter any duplicate entry that already exists. (An entry is considered to be a duplicate if both the name and IP address are identical, no other values will be considered (NAT settings, object color etc.)).&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 07:57:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35556#M97263</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-04-12T07:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R77.30 standalone system to R80.10 Distributed system</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35557#M97264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am referring to this remark :- '&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Then use R80.10 migration tools&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; border: 0px;"&gt;to export database from temporary R77.30 machine and import it to the newly installed Smart-1' . In this scenario, my Smart-1 is not clean, it has few clusters and policy packages. When I import the new database to it, existing policies and other configurations are removed.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 09:17:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Migrate-R77-30-standalone-system-to-R80-10-Distributed-system/m-p/35557#M97264</guid>
      <dc:creator>Anoopkumar_Kuzh</dc:creator>
      <dc:date>2018-04-12T09:17:52Z</dc:date>
    </item>
  </channel>
</rss>

