- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Team,
We would like to replace the existing Fortigate with a Checkpoint Quantum.
And we would like to add "configured Qunatum Gateway" on running smart-1.
Therefore, we have considered the migration process as follows. Please let us know if anything is incorrect.
1.We counfigure a temporaly Smart-1 environment because the configuration place and running place are in different network.
2.We get the existing Fortigate configuration, and we convert the configuration using the SmartMove tool by Checkpoint.
3.We configure the Quantum Gateway to connect to a temporary Smart-1 environment.
4.We import the configuration, including the policies and objects created by the SmartMove tool, into the temporary Smart-1 environment.
5.We check the policies and objects in the temporary environment.
6.After the check is completed, we export the configuration using the Checkpoint 'migrate export' command from a temporary Smart-1 environment.
7.We move the appliance from the temporary to the running environment, and Then we connect the moved Quantum to the running environment using SIC.
8.We import the configuration to the running Smart-1 environment using the 'migrate import' command.
9.We cut over from the existing Fortigate to the new Quantum and check using the running environment.
When you say 'running Smart-1 environment', you mean an existing management server that is already managing policies and gateways? If so, you can't 'migrate import' (the new command is migrate_server for this) from one server to merge into an existing one, this tool is for moving a complete management database from an existing server to a fresh one. If you try this you may end up losing all the existing configurations from the target server.
I suggest that after you test the procedure with your temporary management server, you will have to then re-run the same import from SmartMove into the existing management server. You don't need the gateway to do this, the objects and policy will import into the management server for review for you do check over before moving to the next step of building up the gateway and installing the policy over to it.
Dear emmap,
Thank you for the reply.
Yes, 'running Smart-1 environment' is "an existing management server that is already managing policies and gateways."
I understood that the migrate server command is used for restore or complete new setups, so I thought it might not be suitable for this migration, which is why I asked.
In this case, should we import into the running Smart-1 appliance using "(5) How to Complete the Migration" with "sk115416"?
Yes, after testing it in your temporary Smart-1 and taking a snapshot of the running Smart-1.
Thank you for the reply.
Does this mean using SmartMove to import the config extracted from the temporary Smart-1 after testing into the running Smart-1?
No it means testing the SmartMove import on your temporary Smart-1 and then when you have tested it and it's not causing any issues, run the same thing against the running Smart-1.
OK. I understood. thanks.
What I did last time I did this for customer was take their Cisco confir, use smart move to convert to CP, import that config into my CP mgmt lab and then use script from smart-1 portal to import lab mgmt config into smart-1 environment. Done 🙂
If you need help, message me directly, we can do remote.
Andy
Hi the_rock
Thanks you for the reply.
Yes. Which SK should we refer to for that script?
We also want to migrate from temporary Smart-1 to the running smart-1.
I dont believe there is script for it, its one from the portal itself once you log in.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 32 | |
| 18 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY