- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello CheckMates Community,
does anyone have experience with Commissioning new SMS and running productive gateways without existing MDS or SMS?
What is the best way to connect two running Checkpoint two node clusters and one vsx two node cluster (2 vs) to a new created SMS. The policys was exported from an MDS (other service provider) and imported on the new installed SMS. The SMS is a CP15400 Appliances. With as little downtime as possible.
The IP on the new SMS has been changed. I don't think that's possible without a breakdown. Management and gateways are located in different countries and data centers. Only a LOM Interfaces available on the external Gateways and the new CP15400 Management SMS and the LOM IP and the management GW IP must be exchanged before the new SMS system is put into operation. The biggest problem is the vsx cluster. It will probably have to be completely reinstalled.
I know CP15400 is not really suitable for the project. Does anyone have experience with such a change?
Best regards
Stefan
Hey bro
Did you see here sk167639 ?
Many thanks for the tip. My problem is that I have no access to the previous MDS. It belongs to the previous service provider. Unfortunately, they only took over the firewall gateways. I was not involved in the project at the time.
Suitability of 15400 as a management platform aside, you basically need to import the gateways as new devices. It might be a good time for a clean re-install of the software on them, just to start fresh - for the regular cluster you can do it one member at a time, just clean install one, create a new gateway cluster with just that fresh gateway, then do the other one. Unfortunately for VSX you cannot create a single-node cluster, and you won't be able to just re-SIC it as is, you'll need to rebuild it and recreate it all from scratch. If you can possibly borrow a suitable extra gateway to temporarily use to build the VSX cluster on the new SMS you can leave one of the existing cluster members running while you do the build, then swap it out afterwards.
Many thanks for the tip. I had already suggested this procedure to the project manager as I don't see any other solution. A completely new setup during a change also takes far too long.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY