cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

Best way to migrate Cluster to new mgmt

Hello, I would like to know if there is an official procedure to change a cluster to other management server without loosing its current policies and config?

I have two cluster with two diferent managament server but we need to have only one management server controling these two cluster, the management server is r80.10.

the are two management server A and B, each one have a cluster of gateways  which are C and B.

I need to migrate the cluster B to be managed in Manamenet server A without loosing the current configuration, so I understand I need to migrate the config (policies, host, netwoks, services) of management server B to A so I could install policies again to the gateway and starts to operate normally.

if there is not an offcial procedure for this,  whats is the recomended option?

11 Replies

Re: Best way to migrate Cluster to new mgmt

I'm curious to hear what folks may suggest for this one. Are you trying to accomplish this with no outage? Or are you willing to accept some downtime?

0 Kudos

Re: Best way to migrate Cluster to new mgmt

Hello Daniel, Yes, I am willing to accept some downtime!

0 Kudos

Re: Best way to migrate Cluster to new mgmt

Are you using MDS or only SMS ?

In case you want to migrate both clusters to the MDS, the best way would be to create separate CMA for each cluster. Using migrate export/import tool and job done Smiley Happy

Kind regards,
Jozko Mrkvicka
0 Kudos

Re: Best way to migrate Cluster to new mgmt

Hello Jozko, I am using SMS.

0 Kudos
Danny
Pearl

Re: Best way to migrate Cluster to new mgmt

Step 1: ExportImportPolicypackage - sk120342 (formerly cp_merge) the management configuration from management server B to A or do it manually if it isn't too much configuration / rules / objects

Step 2: Create a new cluster object for cluster B on management server A, check all settings for logging settings, nat, policy installation target etc. related to that cluster object (compare with the configuration on management server B)

Step 3: Reset SIC on cluster B (sk86521, sk65764) and re-establish with management server A

Step 4: Install security policy, check operation status, done

Re: Best way to migrate Cluster to new mgmt

Hi Danny,

   Yes, I tried that on a lab environment but I have a problem, when I import the policy package to the destination management server thair appear 1 cluster object, and 1 gateway objetc for each site to site VPN in the "GW and server tab".

    the problem with this is that I cant delete this objects and I can't install policies because that objects are having some issues like "the cluster object is empty" and "there is not sync with the gateway objects" (I mean the new ones, those that appear with the imported policie package).

0 Kudos
Danny
Pearl

Re: Best way to migrate Cluster to new mgmt

I understand. Then delete a new cluster object manually as I outlined in Step 2 and use this one for policy installation. Delete the one that was create during the import.

0 Kudos

Re: Best way to migrate Cluster to new mgmt

I cant delete those objects, it do not allow me that. if I could delete the object then I would have no issues xD

0 Kudos
Danny
Pearl

Re: Best way to migrate Cluster to new mgmt

Delete on managenent server B before doing the export.

Vladimir
Pearl

Re: Best way to migrate Cluster to new mgmt

cp_merge is no longer supported unfortunately:

"cp_merge" tool support on Security Management Server R80 and above 

There is a python utility that allows you to perform these tasks, but I do not believe it is officially supported by Check Point either

 

0 Kudos

Re: Best way to migrate Cluster to new mgmt

Hi Vladimir,

Yes, I tried that on a lab environment but I have a problem, when I import the policy package to the destination management server thair appear 1 cluster object, and 1 gateway objetc for each site to site VPN in the "GW and server tab".

 

    the problem with this is that I cant delete this objects and I can't install policies because that objects are having some issues like "the cluster object is empty" and "there is not sync with the gateway objects" (I mean the new ones, those that appear with the imported policie package).

0 Kudos