- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi Community,
Has anyone fresh experience with moving Standalone SMS servers to MDS environment? I have some questions, and maybe someone can answer them 🙂
Akos
Can you share more details?
Standalone means that it includes SG in the SMS which you probably don't have.
It is a new MDS or an existing where you will import to a new DMS (CMA in old money)?
What versions are involved?
Sorry for the weak explanation
Thats all 🙂
Akos
Then i'd suggest to first having a look at the sk shared by @TurgutKaplanogl
That should be a standard operation; it is documented in sk156072, as already mentioned
Assuming you are familiar with MDSM (Multi-Domain Security Management):
If not, start here: https://www.youtube.com/watch?v=edvVqKD_hYA) <-- that is free.
Your scenario is covered in the labs of the training course for MDSM - https://igs.checkpoint.com/courses/3010 <-- that is not free.
Planning is important.
That includes, for example and non-exhaustive list:
With all the planning done and pre-sales and sales taken care of the actual migration can be straight forward.
Apart from the list above there are other things you need to think about, for example: You need to decide if you want to include logs (or not) when exporting.
The migration essentially comes down to:
migrate_server verify -v ...
mgmt_cli export-management ...
mgmt_cli import-management domain-name ...
Hopefully someone who has done it recently can share experiences/notes here.
If you share the versions you are working with and planning to install to (on the MDS) that might help too.
PS. See attached for the training course topology and the example spreadsheet that I share with students on the training course (as a way of capturing the IP addresses).
Note: The IP addressing in there is a bad example (does not scale) because it sticks to a non-MDMS training lab IP subnet plan (good for CCSA and CCSE but not so much MDSM)
We're facing a similar scenario. For a site with SMS HA, I wonder if we need to delete the HA system from the Primary to avoid importing it in a CMA where it could be trickier to remove.
I'll run a few tests in a lab environment.
Yes, I would take snapshots of every management ahead of time, then delete any secondary managements and log servers before attempting to migrate. It's easy to add a CMA on another management once you've migrated.
That said, unless you're an MSP, I personally wouldn't move towards an MDS.
I'm working to move my company away from our MDSs because it makes so much stuff more painful for minimal benefit. For example, global objects are normally differentiated by name (e.g, people put a "g_" in front of the name, or similar), but domain objects match based on the name of the object. If you allow somebody in one CMA to connect to a particular domain, then you want to promote the rule to be global, you now have to make global domain objects for the domain. The problem is once you have, you can't assign global policy to the CMA which has its own instances of those domains until after you have deleted the objects from the CMA's rules. So now you have to rename the domains in the CMA, publish, assign global policy, go back into the CMA, and replace the renamed domain objects with the new global versions.
Thanks for the clarification.
Well, I don't call all the shots.
One of our high-security environments has a strict requirement of resource and information segregation going forward, so client A can't see logs, policies and objects from client B and so on.
Right now with the SMS, this isn't really possible. All gateways and VS, policies, logs and objects are in the same domain.
Hello Akos,
You can follow this sk;
https://support.checkpoint.com/results/sk/sk156072
3-A and 3-B
Thank you
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 63 | |
| 19 | |
| 13 | |
| 12 | |
| 12 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY