- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
CheckMates Fest 2026
Watch Now!AI Security Masters
Hacking with AI: The Dark Side of Innovation
CheckMates Go:
CheckMates Fest
Hello gentlemen,
We've lost our SMS Virtual Machine and have no backups and no way to recover it. We have 2 Security Gateways in ClusterXL. Gateways are working fine but we are unable to change anything in policy because of the lack of SMS.
1. Is there any way to recover policy (access rules, objects, exceptions etc.) from gateways and import it to SMS?
2. If first option is impossible what is the safest method of reinstalling SMS in our situation ? By safest I mean anything which allows us to save as much as possible from working configuration and has minimal impact on our production environment?
Thank you for all your answers, I hope there is a solution other then creating everything from scratch.
Step1: Backup your gateways now
Step2: Install ccc on your gateways to check what IP your SMS had and what the security policy‘s name was, VPN gateways IP addresses, VPN topology, interface topology and much more
Step3: Set up a new SMS VM with the same IP it had before
Step4: Create a cluster object with the two cluster nodes that you have
Step5: Establish SIC to the new SMS using this procedure.
Step6: Read in the entire cluster topology
Step7: Recreate the rules using the $FWDIR/state/local/FW1/local.rule file on your gateways.
Step8: Install the new security policy
Step9: Check if everything is fine. In case it‘s not, restore the backup from Step1 and rework your security policy before trying again from Step5
Depending on the version, the answer might be different. Best is to request Check Point Professional Services to help you out.
Version is 80.30.
Step1: Backup your gateways now
Step2: Install ccc on your gateways to check what IP your SMS had and what the security policy‘s name was, VPN gateways IP addresses, VPN topology, interface topology and much more
Step3: Set up a new SMS VM with the same IP it had before
Step4: Create a cluster object with the two cluster nodes that you have
Step5: Establish SIC to the new SMS using this procedure.
Step6: Read in the entire cluster topology
Step7: Recreate the rules using the $FWDIR/state/local/FW1/local.rule file on your gateways.
Step8: Install the new security policy
Step9: Check if everything is fine. In case it‘s not, restore the backup from Step1 and rework your security policy before trying again from Step5
Unfortunately such tool hasn't been created yet. I'm planning to do this later this year and add it to ccc.
Did you, by any chance, opened a support request and sent CPINFO file from your management to Check Point TAC in the past?
First of all, thank you for all the answers.
Unfortunately we have never sent CPINFO to CheckPoint TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 54 | |
| 41 | |
| 15 | |
| 14 | |
| 12 | |
| 11 | |
| 11 | |
| 11 | |
| 10 | |
| 8 |
Thu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANThu 19 Feb 2026 @ 03:00 PM (EST)
Americas Deep Dive: Check Point Management API Best PracticesTue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY