- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi Experts,
I’m planning to deploy a temporary (VM based) management server to support a data‑centre transition. It will only be required for a couple of days. Our current management server is managing around 100 gateways, and I need to deploy an additional secondary management server using an evaluation license.
What is the gateway management limit for a Check Point Management Server running on an evaluation license?
After performing a migrate export/import, if the newly deployed management server (VM based) uses a different IP address but still has network reachability to all managed gateways, will this affect SIC trust or require SIC to be re‑established?
What is the gateway management limit for a Check Point Management Server running on an evaluation license? I believe unlimited
After performing a migrate export/import, if the newly deployed management server (VM based) uses a different IP address but still has network reachability to all managed gateways, will this affect SIC trust or require SIC to be re‑established? I dont think thats needed
1. The 15-day "plug-and-play" eval license definitely covers an unlimited number of firewalls. The accounts.checkpoint.com > Try Our Products > Product Evaluation > All-In-One Evaluation option should also cover a single management with an unlimited number of firewalls. The Other Evaluation Option offers an MDS eval covering five domains and 50 firewalls, or a CPSB-DMNU000, which should let one CMA manage an unlimited number of firewalls.
2. Changing the management server's IP address like this does not require reestablishing SIC, as SIC is certificate-based. Just keep the same hostname on the management, and it will be fine.
That said, changing the IP may require unloading the policy to allow the connection from the new management. The firewalls get implied rules which allow the management server to talk to them, and the new management's address won't be on the list. It you know the new management's address ahead of time, you can make a dummy secondary management object with that address and push to the firewalls to make them aware of it.
3. License SKU definitely doesn't matter for management sync.
What is the gateway management limit for a Check Point Management Server running on an evaluation license? I believe unlimited
After performing a migrate export/import, if the newly deployed management server (VM based) uses a different IP address but still has network reachability to all managed gateways, will this affect SIC trust or require SIC to be re‑established? I dont think thats needed
thanks for quick response
Pleasure to help, any time!
1. The 15-day "plug-and-play" eval license definitely covers an unlimited number of firewalls. The accounts.checkpoint.com > Try Our Products > Product Evaluation > All-In-One Evaluation option should also cover a single management with an unlimited number of firewalls. The Other Evaluation Option offers an MDS eval covering five domains and 50 firewalls, or a CPSB-DMNU000, which should let one CMA manage an unlimited number of firewalls.
2. Changing the management server's IP address like this does not require reestablishing SIC, as SIC is certificate-based. Just keep the same hostname on the management, and it will be fine.
That said, changing the IP may require unloading the policy to allow the connection from the new management. The firewalls get implied rules which allow the management server to talk to them, and the new management's address won't be on the list. It you know the new management's address ahead of time, you can make a dummy secondary management object with that address and push to the firewalls to make them aware of it.
3. License SKU definitely doesn't matter for management sync.
Hi Bob:
Recently, I also have a requirement to migrate an on-premises SMS appliance to a VM.
If the target version is different during the migration (for example, R81.20 → R82), would it still be unnecessary to re-establish SIC?
SIC certificates are retained during an upgrade with migration, no need to reset anything. The R82 install and upgrade guide has the full procedure to follow.
thanks everyone
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY