cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

Migrate from distributed R75 (smart-1 + 2 clustered IP appliances) to R80.30 Full HA Cluster (5400)

Hi team.

I´m going to upgrade a customer environment with the following:

2 IP appliances with IPSO and R75 version with IP Clustering
1 Smart 1 appliance (I have no information about the model) also with R75 version.

The approach will be migrate from distributed to a Full HA environment moving to a 5400 appliances, and upgrading to R80.30 version.

I´ve reviewed sk33896 "How to migrate a distributed SmartCenter to a Full HA Cluster", but it appears to only apply wit SPLAT, also searched SKs relevant to r80.x with Gaia without success.

My plan is to upgrade the SM to R80.30 in a lab environmnent, export the configuration and then import the configuration in the 5400 appliances (with R80.30 fresh install), building the Full HA cluster.

Is there any guide lines that should be followed in order to acomplish this?

Many thanks in advance.

Best regards.

0 Kudos
4 Replies
Highlighted
Admin
Admin

Re: Migrate from distributed R75 (smart-1 + 2 clustered IP appliances) to R80.30 Full HA Cluster (54

Usually you migrate FROM a FullHA Cluster, not too one.
The splat-specific steps in sk33896 are about recovering the OS settings, which you can do manually.
The config export/import process should work the same.
0 Kudos
Highlighted

Re: Migrate from distributed R75 (smart-1 + 2 clustered IP appliances) to R80.30 Full HA Cluster (54

Please! Do not build a Full HA Cluster ! Keep the SMS in a VM and away from the GWs...

0 Kudos
Highlighted
Silver

Re: Migrate from distributed R75 (smart-1 + 2 clustered IP appliances) to R80.30 Full HA Cluster (54

Seconded.   It really is a false economy to use the Management and Gateway in a Full HA Cluster.

You end up using a larger appliance then necessary as have to support not just the Gateway Inspection but also the Management.

Whilst yes you can split so that have Management Active on the Standby Cluster Member it really isn't a good idea.

I personally think that Check Point did it just so that could show didn't HAVE to use a seperate server as I know a lot of the smaller review sites mark them down compared to "others" where can do via WebUI on the Firewall.

0 Kudos
Highlighted

Re: Migrate from distributed R75 (smart-1 + 2 clustered IP appliances) to R80.30 Full HA Cluster (54

Hi to all

Sorry for the delayed response.

After several months of planning this, I realized that the customer shared us wrong information.

In fact, the customer configuration consisted on a distributed environment, 1 SMS managing a cluster, not as initially described.

So the migration simply was to migrate GWs to newer appliances (configured manually) and migrate the SMS to a MDS; this recently was successfully carried out.

Many thanks for your comments

Best regards.

0 Kudos