Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Deki
Explorer

SMS migration and IP change on VMware R82.10

I am working on migrating a SMS to a new VM in another DC. The name will stay the same however the IP has to change and my goal is to NOT have to reset SIC on 130 gateways.

Running version R82.10 and I have a migration plan in place but I've seen conflicting information and wanted to see what worked for the folks on here. Both servers will be on the same JHF. Routing is working and License is already installed on new VM.

This is what I have:

1. Create access rules for the new IP inside policy base 

2. Change the IP in SmartConsole (edit the SMS object to reflect the new IP) and publish

3. Run the export script

4. Import config on new VM with the same name

5. Push policy via the new VM (my concern is the gateway not recognizing the new SMS) - https://support.checkpoint.com/results/sk/sk40993

This in theory should re-establish SIC with the gateways. 

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

The gateways will recognize the management as SIC ultimately authenticates on certificates (not IP).
As long as your rules allow the relevant traffic from the new management, you should be good to go. 

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

It's usually easiest to create a dummy secondary SmartCenter with the new IP and push policy to everything ahead of time. The implied rules will allow traffic from all management servers to all firewalls, so that handles adding the rules for you. No need to build explicit rules or track down what services need to be allowed in which direction. Then you export the config, import on the new box, delete the dummy object, update the IP of the real object, and push policy.

Note that central licenses for firewalls are generated to the management server. If you have any central licenses, you'll need to regenerate them.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events