<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migration to new GW with new Mgmt server in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25974#M5248</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Xavier,&lt;/P&gt;&lt;P&gt;Thank you for your response and Advice&amp;nbsp;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The new&amp;nbsp;GW was used for some other services,&amp;nbsp;so I have wiped out all network management&amp;nbsp;configuration (Route, Interface and host entry).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;both Nokia IP690 (Old FW) and Checkpoint 12200 (New FW)&amp;nbsp;image is&amp;nbsp;R77.30 Gaia&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New Gateway is prepared with false IP address.&lt;/P&gt;&lt;P&gt;Policy has been replicated to new management server (There are other firewalls integrated with this mgmt server).&lt;/P&gt;&lt;P&gt;SIC established and I am able to push the policy to the new gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but we are facing issues in&amp;nbsp;configuring&amp;nbsp;ClusterXL and VRRP in the new mgmt server cluster object, it is throwing error "Different members cannot have interfaces with the same IP address and Net Mask".&lt;/P&gt;&lt;P&gt;both members are using different ip address and Net Mask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In&amp;nbsp;Old Nokia&amp;nbsp;firewall,&amp;nbsp;we are using VRRP, So HA&amp;nbsp;has been set in&amp;nbsp;the 3rd Party configuration tab on the cluster properties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jegan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Jun 2018 15:24:21 GMT</pubDate>
    <dc:creator>jegan_s</dc:creator>
    <dc:date>2018-06-07T15:24:21Z</dc:date>
    <item>
      <title>Migration to new GW with new Mgmt server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25972#M5246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently a&amp;nbsp;cluster of Nokia&amp;nbsp;GW&amp;nbsp;is running with a Management server, we would like to migrate from Nokia to Checkpoint GW but with different mgmt. server. new mgmt. server has already many gateway integrated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steps that I am thinking to do,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Configuring the new GW.&lt;/P&gt;&lt;P&gt;2.creating a checkpoint object in the new mgmt. server.&lt;/P&gt;&lt;P&gt;3.replicating the policy.&lt;/P&gt;&lt;P&gt;4.establishing SIC&amp;nbsp;on both GW&lt;/P&gt;&lt;P&gt;5.On the new mgmt server, establishing SIC&amp;nbsp;from the cluster member of the new checkpoint object.&lt;/P&gt;&lt;P&gt;6.modifying the topology in the checkpoint object.&lt;/P&gt;&lt;P&gt;7.updating the&amp;nbsp;antispoofing folder.&lt;/P&gt;&lt;P&gt;8.pushing the policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can any one&amp;nbsp;assist me if I have missed anything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2018 09:18:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25972#M5246</guid>
      <dc:creator>jegan_s</dc:creator>
      <dc:date>2018-05-25T09:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migration to new GW with new Mgmt server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25973#M5247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, this is an ideal situation &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Prepare your new Security Gateways : configure/update O.S., configure network and all needed local little things (could be CoreXL, kernel values, files for RemoteAccess, ...) ; I propose you to even set up false IP addresses so that you can test all the setup in parallel of the actual Production environment you're replacing&lt;/LI&gt;&lt;LI&gt;Creating all your target rules and objects on the target Security Management Server ; BTW: do you know how to proceed? how many objects/rules you'll have to create? What is the actual version of SMS: pre-R80 or R80x?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;At this step: you should have all configured, maybe using false IP address so that you can test new functionalities/inspection engines, maybe new blades, ... My advise is: take your time to test all of that especially if there is a big gap between actual version running on Nokia and your target version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, when you'll be ready: just have to change interfaces' IP address and pushing policy.&lt;/P&gt;&lt;P&gt;Again, this is still ideal situation because if anything goes wrong and if you have a short period for cut-over: "unplug new SGs / plug old ones" &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some things should be also prepared before cut-over:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ISP/providers availability for assistance just in case ; for ARP issues: just force failover between nodes of your cluster so that Gratuitous ARP Requests will be sent&lt;/LI&gt;&lt;LI&gt;If you change/add new blades, prepare yourself to test such new functionalities (surely with other application owners or system owners)&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2018 13:26:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25973#M5247</guid>
      <dc:creator>XavierBens</dc:creator>
      <dc:date>2018-05-26T13:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Migration to new GW with new Mgmt server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25974#M5248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Xavier,&lt;/P&gt;&lt;P&gt;Thank you for your response and Advice&amp;nbsp;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The new&amp;nbsp;GW was used for some other services,&amp;nbsp;so I have wiped out all network management&amp;nbsp;configuration (Route, Interface and host entry).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;both Nokia IP690 (Old FW) and Checkpoint 12200 (New FW)&amp;nbsp;image is&amp;nbsp;R77.30 Gaia&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New Gateway is prepared with false IP address.&lt;/P&gt;&lt;P&gt;Policy has been replicated to new management server (There are other firewalls integrated with this mgmt server).&lt;/P&gt;&lt;P&gt;SIC established and I am able to push the policy to the new gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but we are facing issues in&amp;nbsp;configuring&amp;nbsp;ClusterXL and VRRP in the new mgmt server cluster object, it is throwing error "Different members cannot have interfaces with the same IP address and Net Mask".&lt;/P&gt;&lt;P&gt;both members are using different ip address and Net Mask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In&amp;nbsp;Old Nokia&amp;nbsp;firewall,&amp;nbsp;we are using VRRP, So HA&amp;nbsp;has been set in&amp;nbsp;the 3rd Party configuration tab on the cluster properties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jegan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:24:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25974#M5248</guid>
      <dc:creator>jegan_s</dc:creator>
      <dc:date>2018-06-07T15:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: Migration to new GW with new Mgmt server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25975#M5249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I forgot to remove Checkpoint mgmt IP address from the topology. after&amp;nbsp;remove, I am able to change the cluster settings to VRRP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jegan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2018 13:45:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Migration-to-new-GW-with-new-Mgmt-server/m-p/25975#M5249</guid>
      <dc:creator>jegan_s</dc:creator>
      <dc:date>2018-06-13T13:45:23Z</dc:date>
    </item>
  </channel>
</rss>

