- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Guys,
I am task to migrate a security gateway purposely for VPN to a new 5600 NGTP with R80.20 OS. I would like to know how to migrate a security gateway, do I still need to do the migrate export and migrate import?
Thanks
OK so the Security Policy is held on the Managment Server so that doesn't migrate.
What looking at is extracting the Gaia OS config and importing onto the new Box
You can use the show configuration command to display the current Gaia OS configuration from the unit.
You can take that output and place into a text file
Then edit the configuration to reflect the new Appliances Interface Names. Don't know your current model so may not use the same interface names
You can then paste the file contents into the 5600 after running through the initial config wizard. This should get your interfaces and routes into the box,
Obviously this only takes the Gaia Config so will need to look at other files that may have been modified
$FWDIR/boot/modules/fwkern.conf - kernel paramaters
$FWDIR/conf/trac_client_1.ttm - remote access client
Are the ones that I usually find the need to look at, again, probably worth checking the contents of all of these. They may or may not exist in your environment. Certainly the last 4 which are for RSA SecurID for instance.
Other people may be able to add other files to look at,
Can then establish SIC, license and push policy
migrate export/import is a management level tool
When you say migrate do you mean migrate to be
a) new hardware - ie box replacement
b) move vpn in policy to new termination point
Hi @mdjmcnally
What I mean is to move all configuration from old hardware (r77.x) to new hardware (r80.20).
Thanks
OK so the Security Policy is held on the Managment Server so that doesn't migrate.
What looking at is extracting the Gaia OS config and importing onto the new Box
You can use the show configuration command to display the current Gaia OS configuration from the unit.
You can take that output and place into a text file
Then edit the configuration to reflect the new Appliances Interface Names. Don't know your current model so may not use the same interface names
You can then paste the file contents into the 5600 after running through the initial config wizard. This should get your interfaces and routes into the box,
Obviously this only takes the Gaia Config so will need to look at other files that may have been modified
$FWDIR/boot/modules/fwkern.conf - kernel paramaters
$FWDIR/conf/trac_client_1.ttm - remote access client
Are the ones that I usually find the need to look at, again, probably worth checking the contents of all of these. They may or may not exist in your environment. Certainly the last 4 which are for RSA SecurID for instance.
Other people may be able to add other files to look at,
Can then establish SIC, license and push policy
Hi @mdjmcnally ,
Even if I will not import the following files, it will still work right? By the way, I am using MEP for my remote access VPN, where is the configuration of that?
FILES:
Thank you so much for the help.
So, building the new box with the existing configs from the old box then pushing the policy with the VPN configs should bring everything over for remote access configs?
Yes
Thanks dude for the reply! i had a couple more questions that i replied via email to the community.
@PhoneBoy
About the license? We need open a ticket with CP to move? From a Appliance to another?
Unless you're dealing with Open Server, you're not usually moving licenses.
If IP addresses are changing, you will need Account Services to issue you new license(s).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 42 | |
| 18 | |
| 11 | |
| 10 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY