- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Create a Domain without startup?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Create a Domain without startup?
In R80 how do you create a new domain but do not start it? So far the GUI and the API automatically starts the new Domain after creation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Michael,
Currently in R80 this is not supported. We do plan to support it on future releases.
May I ask what is your use-case in which you don't want to start the new Domain automatically?
Eran
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In all the past versions we can export a Domain/CMA and import into a new MDS. However the only way to do this is to build a new Domain on the new MDS and then do not start it. We would then take the export from the old Domain, then take this export and import it into the new domain and then start it afterwards. If you start the Domain before the import, the import will fail. So this feature is a must for migrating Domains on at a time. We also use this feature to move a Domain from one MDS to another. When you try and run a cma_migrate it will tell you in the output to not start the domain. Without this feature Check Point is going to make our migration to R80 impossible in the near future. I can't believe Check Point would even consider releasing R80 without this working. You will probably find we are not the only customer that uses this feature.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the current R77.x environments the process to import a CMA one at a time has improved so it is not necessary to create the domain without first starting it.
If you look at the windows carefully you should see at the bottom of one an "Import Options" section which allows you to enter the full path to an export file.
Doing this correctly will import your CMA without having to create it without starting it.
While I'm not 100% sure this feature will be in R80 I doubt they would have removed it in a future release.
How To Migrate from Security Management Server to Domain Management Server
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
To be more accurate -
It's not supported using the SmartConsole but it is supported using the APIs.
This is from the user manual -
Eran
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That helps out a lot. I did not see the option for "skip-start-domain-server". I was using the directions from the "CP_R80_Multi-DomainSecurityManagement_AdminGuide.pdf" and it did not show this part. I will give it a try.
Thank you!
From the "CP_R80_Multi-DomainSecurityManagement_AdminGuide.pdf"
To create a new Domain (add domain):
# mgmt_cli add domain name "<domain>" servers.ip-address "<ip_address>" servers.name "<domain_server>" servers.multi-domain-server "<multi_domain_server>"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The part this is missing is how to assign a license to the CMA, is there anyway to do this? I have amds that is using legacy licensing so would need to assign a license per CMA.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Go into topleft menu in Smartconsole and select Manage Licenses and Packages, which will start SmartUpdate.
In SmartUpdate go to the left pane Multi-Domain Licenses and select your CMA from the list right click on it and attach a license from repository.
When it will tell you there was a problem attaching the license try to make sure to attach the same license again, now it will give you the error that it is already attached.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there not a way to attach a license using the mgmt_cli command in that way the whole build can be scripted.
