Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
praveen0312
Explorer

Migrating Checkpoint Management Server from Hyper-V to AHV

Hello Checkmates,

We have a Checkpoint Security Management Server (Gaia R81.10 JHF 150) managing two 5400 Gateways (Gaia R81.10 JHF 150) in a high availability cluster. The current SMS is an open server in Hyper-V.  Our customer asked us to migrate all the servers we have in Hyper-V to Nutanix AHV. For this migration, Checkpoint TAC suggested me to build a new server in AHV and import the existing management database with migrate_server command to the new SMS in AHV.

I wanted to have your opinion on the below method. 

Instead of importing management database with migrate_server command can I use the snapshot of the existing SMS in Hyper-V to build the new SMS in AHV?  

0 Kudos
5 Replies
Chris_Atkinson
Employee Employee
Employee

A limitation of GAiA snapshots is that the source and destination hardware/appliance must be the same, so this would likely fall into unsupported territory.

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

migrate_server is the best way to do this, yes.
I would also install the "new" VM on R81.20 which has a more up-to-date installer that should improve disk I/O (only occurs on fresh installs). 

0 Kudos
praveen0312
Explorer

Thank You @PhoneBoy  and @Chris_Atkinson 

Are there any prerequisites that I need to take care on the newly built server, before I import the database with migrate_server command?

I can keep the same IP address and Hostname as the old server. Does this impact the Licensing and SIC between the gateways and the new SMS? Or do I need to regenerate the license again and reestablish the SIC between the gateways and new SMS? 

0 Kudos
emmap
Employee
Employee

If you keep the same IP and hostname you will not have to reset SIC. The licenses will also be transferred over with the migrate. 

0 Kudos
PhoneBoy
Admin
Admin

migrate_server brings the licenses and SIC certificates across, so you don't lose anything there.
Even if you change the management IP address, simply pushing policy to the gateways from the new management will re-establish connectivity.
Depending on your policy configuration, you may need to perform an fw unloadlocal first (unloads security policy, so should be done in an outage window).

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events