Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jslimma_soloiro
Participant

Rules Migration from Smart-1 Cloud Management to Onpremise Management

Hello everyone,

I have the following scenario:

- Cloudguard R81.20 Cluster (Active/Standby). Created by Marketplace.

- Smart-1 Cloud on portal.checkpoint.com

I'm working on migrating a Manager from Smart-1 Cloud to an on-premise Manager. I created all the rules, NATs, and VPNs in the new management system and got everything ready for the day of the Manager change. During the change, I successfully performed the SIC with the Cloudguard Firewall and applied the policy.

However, when I made the change, I noticed that some services were not working correctly. One of the VPNs did not start, and other services that use the Azure environment also stopped. I restarted the gateway and the VM, and I noticed an improvement in connectivity, but still without establishing an important Site-to-Site VPN (between checkpoints); only phase-1 was established.

I would like to know if anyone has experienced a situation like this and what measures I can take to avoid this problem in the next change. I'm thinking of setting up a parallel environment so I can work on the change more safely, but I wanted to know if you had any details to share.

0 Kudos
2 Replies
the_rock
MVP Diamond
MVP Diamond

Have not had that issue myself, but just wondering, is it multiple tunnels with same phase 2 issue or just one?

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
jslimma_soloiro
Participant

The gateway has 3 VPN Tunnel. Two tunnel are with Routed-Based (Working fine) e just one vpn tunnel with Domain Based where phase-1 OK but phase-2 not working (no ipsec sa). Unfortunately during the maintenance window it was necessary a rollback and now all tunnels are up.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events