<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migrate R80.40 Full HA to distributed Management in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167314#M27794</link>
    <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;today I would like to share my experience of a customer project where we need to migrate a Full HA cluster of two 4400 appliances to new 6200 appliances with distributed management.&lt;BR /&gt;Due to the lack of an official solution, I will explain the necessary steps we did to achieve this goal:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Replicate the installation and config from 4400 Full HA cluster to 6200 Full HA cluster&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;output of “show configuration“ to quickly restore basic interface settings and so on&lt;/LI&gt;&lt;LI&gt;“migrate export” and “migrate import” to restore database and configuration&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Install new secondary security management server using the same version and Jumbo HF as the primary appliance node A&lt;/LI&gt;&lt;LI&gt;Configure a secondary security management server in SmartConsole by following the instructions in the R80.x Security Management Administration Guide in the chapter "Configuring a Secondary Server in SmartConsole"&lt;/LI&gt;&lt;LI&gt;Make sure that the management servers are synchronized (View High Availibility Status)&lt;/LI&gt;&lt;LI&gt;Execute the following commands on the primary management server appliance node A&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;cp_conf fullha del_peer&lt;/LI&gt;&lt;LI&gt;cp_conf fullha disable&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Remove secondary appliance node B from the cluster and perform a fresh installation using the same version and Jumbo HF&lt;UL&gt;&lt;LI&gt;Run First Time Wizard without management&lt;/LI&gt;&lt;LI&gt;restore basic interface settings from&amp;nbsp;output of “show configuration“&lt;/LI&gt;&lt;LI&gt;Add node B to the existing cluster again&lt;/LI&gt;&lt;LI&gt;Install security policy&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Change the former installed new secondary security management server to active&lt;UL&gt;&lt;LI&gt;“cpprod_util FwSetActiveManagement 0” on appliance node A&lt;/LI&gt;&lt;LI&gt;“cpprod_util FwSetActiveManagement 1” on new management server&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Restart SmartConsole and log in to new management server and make sure that the management servers are synchronized (View High Availibility Status)&lt;/LI&gt;&lt;LI&gt;Remove primary appliance node A from the cluster and perform a fresh installation using the same version and Jumbo HF&lt;UL&gt;&lt;LI&gt;Run First Time Wizard without management&lt;/LI&gt;&lt;LI&gt;restore basic interface settings from&amp;nbsp;output of “show configuration“&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Promote the active management server to primary&lt;UL&gt;&lt;LI&gt;"$FWDIR/bin/promote_util"&lt;/LI&gt;&lt;LI&gt;"cpstop"&lt;/LI&gt;&lt;LI&gt;Remove the&amp;nbsp;$FWDIR/conf/mgha*&amp;nbsp;files&lt;/LI&gt;&lt;LI&gt;"cpstart"&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Create a new cluster with a different name&lt;UL&gt;&lt;LI&gt;Add appliance node A to the new cluster&lt;/LI&gt;&lt;LI&gt;Configure the new cluster in the same way as the original old cluster (open a second SmartConsole session in read-only)&lt;/LI&gt;&lt;LI&gt;Install security policy&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Remove appliance node B from the old cluster, re-add it to the new cluster and install the security policy&lt;/LI&gt;&lt;LI&gt;Delete the old cluster&lt;UL&gt;&lt;LI&gt;Only after the steps 11. til 13. the old peers of the initial Full HA configuration disappears in the “View High Availibility Status”&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for reference purpose the following knowledgebase and checkmates articles were used and point us in the right direction:&lt;/P&gt;&lt;P&gt;sk154033 - How to migrate R80.x standalone management environment to a distributed environment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk154033" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk154033&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk114933 - How to migrate Full HA environment to Distributed environment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44201" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44201&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk34495 - Changing the HA status of the Management station from command line&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34495" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34495&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk114933 - How to promote the Secondary Management server to become the Primary server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114933" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114933&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk108902 - Best Practices - Backup on Gaia OS&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108902" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108902&lt;/A&gt;&lt;/P&gt;&lt;P&gt;CP_R80.40_SecurityManagement_AdminGuide&lt;BR /&gt;&lt;U&gt;&lt;A href="https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/96090/FILE/CP_R80.40_SecurityManagement_AdminGuide.pdf" target="_blank"&gt;https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/96090/FILE/CP_R80.40_SecurityManagement_AdminGuide.pdf&lt;/A&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;How to migrate Full HA R80.30 environment to Distributed R81.10 environment&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/How-to-migrate-Full-HA-R80-30-environment-to-Distributed-R81-10/m-p/161379#M26974" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/How-to-migrate-Full-HA-R80-30-environment-to-Distributed-R81-10/m-p/161379#M26974&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jan 2023 15:51:44 GMT</pubDate>
    <dc:creator>K1ngb0rA</dc:creator>
    <dc:date>2023-01-10T15:51:44Z</dc:date>
    <item>
      <title>Migrate R80.40 Full HA to distributed Management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167314#M27794</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;today I would like to share my experience of a customer project where we need to migrate a Full HA cluster of two 4400 appliances to new 6200 appliances with distributed management.&lt;BR /&gt;Due to the lack of an official solution, I will explain the necessary steps we did to achieve this goal:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Replicate the installation and config from 4400 Full HA cluster to 6200 Full HA cluster&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;output of “show configuration“ to quickly restore basic interface settings and so on&lt;/LI&gt;&lt;LI&gt;“migrate export” and “migrate import” to restore database and configuration&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Install new secondary security management server using the same version and Jumbo HF as the primary appliance node A&lt;/LI&gt;&lt;LI&gt;Configure a secondary security management server in SmartConsole by following the instructions in the R80.x Security Management Administration Guide in the chapter "Configuring a Secondary Server in SmartConsole"&lt;/LI&gt;&lt;LI&gt;Make sure that the management servers are synchronized (View High Availibility Status)&lt;/LI&gt;&lt;LI&gt;Execute the following commands on the primary management server appliance node A&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;cp_conf fullha del_peer&lt;/LI&gt;&lt;LI&gt;cp_conf fullha disable&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;Remove secondary appliance node B from the cluster and perform a fresh installation using the same version and Jumbo HF&lt;UL&gt;&lt;LI&gt;Run First Time Wizard without management&lt;/LI&gt;&lt;LI&gt;restore basic interface settings from&amp;nbsp;output of “show configuration“&lt;/LI&gt;&lt;LI&gt;Add node B to the existing cluster again&lt;/LI&gt;&lt;LI&gt;Install security policy&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Change the former installed new secondary security management server to active&lt;UL&gt;&lt;LI&gt;“cpprod_util FwSetActiveManagement 0” on appliance node A&lt;/LI&gt;&lt;LI&gt;“cpprod_util FwSetActiveManagement 1” on new management server&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Restart SmartConsole and log in to new management server and make sure that the management servers are synchronized (View High Availibility Status)&lt;/LI&gt;&lt;LI&gt;Remove primary appliance node A from the cluster and perform a fresh installation using the same version and Jumbo HF&lt;UL&gt;&lt;LI&gt;Run First Time Wizard without management&lt;/LI&gt;&lt;LI&gt;restore basic interface settings from&amp;nbsp;output of “show configuration“&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Promote the active management server to primary&lt;UL&gt;&lt;LI&gt;"$FWDIR/bin/promote_util"&lt;/LI&gt;&lt;LI&gt;"cpstop"&lt;/LI&gt;&lt;LI&gt;Remove the&amp;nbsp;$FWDIR/conf/mgha*&amp;nbsp;files&lt;/LI&gt;&lt;LI&gt;"cpstart"&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Create a new cluster with a different name&lt;UL&gt;&lt;LI&gt;Add appliance node A to the new cluster&lt;/LI&gt;&lt;LI&gt;Configure the new cluster in the same way as the original old cluster (open a second SmartConsole session in read-only)&lt;/LI&gt;&lt;LI&gt;Install security policy&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Remove appliance node B from the old cluster, re-add it to the new cluster and install the security policy&lt;/LI&gt;&lt;LI&gt;Delete the old cluster&lt;UL&gt;&lt;LI&gt;Only after the steps 11. til 13. the old peers of the initial Full HA configuration disappears in the “View High Availibility Status”&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for reference purpose the following knowledgebase and checkmates articles were used and point us in the right direction:&lt;/P&gt;&lt;P&gt;sk154033 - How to migrate R80.x standalone management environment to a distributed environment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk154033" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk154033&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk114933 - How to migrate Full HA environment to Distributed environment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44201" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk44201&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk34495 - Changing the HA status of the Management station from command line&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34495" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34495&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk114933 - How to promote the Secondary Management server to become the Primary server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114933" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114933&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk108902 - Best Practices - Backup on Gaia OS&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108902" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108902&lt;/A&gt;&lt;/P&gt;&lt;P&gt;CP_R80.40_SecurityManagement_AdminGuide&lt;BR /&gt;&lt;U&gt;&lt;A href="https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/96090/FILE/CP_R80.40_SecurityManagement_AdminGuide.pdf" target="_blank"&gt;https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/96090/FILE/CP_R80.40_SecurityManagement_AdminGuide.pdf&lt;/A&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;How to migrate Full HA R80.30 environment to Distributed R81.10 environment&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/How-to-migrate-Full-HA-R80-30-environment-to-Distributed-R81-10/m-p/161379#M26974" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/How-to-migrate-Full-HA-R80-30-environment-to-Distributed-R81-10/m-p/161379#M26974&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 15:51:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167314#M27794</guid>
      <dc:creator>K1ngb0rA</dc:creator>
      <dc:date>2023-01-10T15:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R80.40 Full HA to distributed Management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167323#M27795</link>
      <description>&lt;P&gt;Thanks for sharing&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 16:56:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167323#M27795</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-01-10T16:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R80.40 Full HA to distributed Management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167338#M27796</link>
      <description>&lt;P&gt;I'm confused, are you migrating one Full HA cluster to another Full HA cluster (different hardware) or are you migrating a Full HA cluster to a new cluster with management on separate hardware?&lt;BR /&gt;The steps seem to suggest a Full HA cluster on new hardware.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 19:14:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167338#M27796</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-10T19:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R80.40 Full HA to distributed Management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167340#M27797</link>
      <description>&lt;P&gt;Much appreciated for taking time to list all the steps, but Im with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, also slightly confused, as your steps seem to insinuate migration to another full HA config, not distributed environment.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 19:31:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167340#M27797</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-10T19:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Migrate R80.40 Full HA to distributed Management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167389#M27803</link>
      <description>&lt;P&gt;see steps 6. and 9. - the nodes were reinstalled without management.&lt;/P&gt;&lt;P&gt;and step 2. -&amp;nbsp;&lt;SPAN&gt;Install new secondary security management - that is changed to active in step 7. and promoted to primary in step 10.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;so at the end it is a cluster of two 6200 appliances with a virtual security management server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;step 1. was done for the case that the migration/conversation should not be successful - due to the mentioned lack of an official solution - to simply migrate the existing Full HA config to the new hardware.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 07:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migrate-R80-40-Full-HA-to-distributed-Management/m-p/167389#M27803</guid>
      <dc:creator>K1ngb0rA</dc:creator>
      <dc:date>2023-01-11T07:07:56Z</dc:date>
    </item>
  </channel>
</rss>

