Looking to see if I'm thinking about this properly but we're collapsing two HA clusters into a single HA cluster with a new management. The two existing clusters have been upgraded from R77 (or older) over the years and are now running R81.20. Also going from Open Servers to Check Point appliances.
We're trying to keep the new cluster as clean as possible without bringing over a lot of the garbage from the old ones so I setup the new HA cluster and management server and now am trying to get just the objects imported into the cluster and then we're going to build out the rules by hand, etc.
I'm trying to use this script and following what Danny did at the end and for the most part it seems to be working but none of my service or network groups have members so trying to figure that out. https://community.checkpoint.com/t5/API-CLI-Discussion/CLI-API-Example-for-exporting-importing-and-d...
Besides any advice on the group membership issue, any gotchas I should be looking for when migrating to a new management/cluster? IPS rules is another place I'll want to review and found this script and am going to run it to compare the defaults to what we're using in production: https://support.checkpoint.com/results/sk/sk178646
We have over 3,000 additional objects so trying to limit the heavy lifting of object creation but still keeping the new policy clean by building out the rules manually. Is there a checklist or things to check that Check Point has which would assist in determining all the areas I need to review? ACL Policy, NAT, IPS, HTTPS Inspection, LDAP Object, Global Properties, Identity Awareness, etc.
Thank you!