- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Advice needed: Migrate or upgrade SMS HA?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Advice needed: Migrate or upgrade SMS HA?
Hi,
We have a physical Smart-1 server running R80.20 currently managing a cluster of two Checkpoint firewalls.
We are planning on 1. upgrading the management server to the latest version 2. build another virtual SMS server to form a management HA cluster.
Two options here:
1. Build a new virtual SMS running the latest firmware. Migrate policy to the new virtual server. Upgrade the physical one. Finally, form HA between the two.
2. Build a new virtual SMS running R80.20. Form HA between physical and virtual. Upgrade to the latest version.
In my view, option 2 is better as it does not require policy migration. however, I am not sure if there is any restriction or limitation to convert a standalone to HA with virtual SMS. Any advice, steps would be highly appreciated.
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Afaik there is no restriction using management ha with physical and virtual device. It is tested and supported.
To your question: option 3: upgrade smart-1, deploy vm, build ha 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Jm2c
I would prefer option 3.
Upgrade current hardware appliance to R80.40. (in-place upgrade).
(Ensure that you have backup/snapshot and configure gateways to send logs after the SMS is back.)
After that, create a virtual SMS. Attach it as standby SMS.
Option 4 would be to take the same type: either both as hardware or both as virtual
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Question: Why do you need to do Management HA ? With SMS installed as VM you will not need the HA capabilities at all, as you can snapshot, clone and change the running image in short time !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I assume, the hardware is not old enough to get rid of it, therefore i did not post this reply on my own 🙂
