Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
peaanedu
Explorer

Migration Check smart-1 405 to smart-1 700s

Dear Support Team,

We are currently running a Smart-1 405 appliance, which we understand has reached End of Life (EOL). We are planning to migrate to the new Smart-1 700S and would appreciate your guidance to ensure a smooth transition.

Since this is our first migration of this kind, could you please share the following:

1. Prerequisites and requirements for the migration (supported software versions, licensing, and any required upgrades before migrating)
2. The recommended migration procedure or best-practice documentation
3. Known critical issues, limitations, or compatibility concerns we should be aware of
4. Recommended backup and rollback plan in case of issues
5. Estimated downtime and any impact on managed gateways or logging

If possible, we would also appreciate any reference to relevant SK articles or the option to schedule a call with a support engineer to review our migration plan.

Thank you for your support. I look forward to your reply.

Best regards,
Pea An

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

The actual plan will vary depending on the source and target versions of software involved.
For example, the Smart-1 405 could be running versions anywhere from R77.30 to R82.
The Smart-1 700 supports R82 and above.

Depending on the gateways managed by the Smart-1 405, they may need to be upgraded to a supported version.
In any case, you should read the Installation/Upgrade guide for the target version.
Here is the one for R82.10: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Installation_and_Upgrade_Gui... 
Migrating management between hardware is usually done with the Advanced Migration procedure, which does not impact gateways until policy is installed from the NEW management server, which will have the same SIC.
If you are using a different IP for the new management, you may need to configure the access policy to allow policy installation from the new management server.

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

This is easiest if you upgrade the existing management to R82 and keep the same hostname and IP on the new management. As part of the migration, you just disconnect the old box's network interface (you can leave the LOM connected). If you need to roll back, you just disconnect the new box and reconnect the old one. Easy.

If you want to change the IP so you can leave the old box on the network, that's possible, but annoying. You should make a fake secondary management with the address of the new system, and push policy to all of the firewalls. Export the configuration from the existing management, import it on the new management, delete the secondary management object, set the primary management object to the new IP, make a new secondary management object with the old IP, and push policy to everything.Rolling back involves just pushing policy from the old management to everything.

If you want to upgrade during this migration, I would urge you to reconsider. Upgrade first, then bring the config from R82 to R82. It lets you be confident any problems relate to the new box, not to the upgrade. Still, it's possible to upgrade during the migration. Read the new version's Installation and Upgrade Guide, and focus on the Advanced Upgrade section.

If you want to change the hostname during this, you're in for an enormous amount of trouble. Seriously, keep the original management's hostname on the new box. If you really need to change it, do so after the migration as a separate change window.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events