Hello everyone,
I have the following scenario:
- Cloudguard R81.20 Cluster (Active/Standby). Created by Marketplace.
- Smart-1 Cloud on portal.checkpoint.com
I'm working on migrating a Manager from Smart-1 Cloud to an on-premise Manager. I created all the rules, NATs, and VPNs in the new management system and got everything ready for the day of the Manager change. During the change, I successfully performed the SIC with the Cloudguard Firewall and applied the policy.
However, when I made the change, I noticed that some services were not working correctly. One of the VPNs did not start, and other services that use the Azure environment also stopped. I restarted the gateway and the VM, and I noticed an improvement in connectivity, but still without establishing an important Site-to-Site VPN (between checkpoints); only phase-1 was established.
I would like to know if anyone has experienced a situation like this and what measures I can take to avoid this problem in the next change. I'm thinking of setting up a parallel environment so I can work on the change more safely, but I wanted to know if you had any details to share.