Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
M_Soler
Contributor
Jump to solution

Error in the export when we want to migrate from on-premise SMS to Smart-1 cloud

Hello ,

We want to migrate our SMS from on-premise to Smart-1 Cloud, I download the script from the checkpoint portal,

I run it in our SMS but in 17% we have an error:

Failed to run export or export file (export_file.tgz) not found. Exit code: 1

I tried the migrate export and it works well, but not the script from the portal.
our SMS (Vmware) is in R81.20 take 10 in it is not an MDS server
I checked this limitiations but we are not in it :

https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Check-Point-SmartCloud-Admin-...

find the outputs of the df -h in my screenshot

 

I'm open for any idea

Thank you .

 

 

0 Kudos
2 Solutions

Accepted Solutions
M_Soler
Contributor

For us the implied_rules.def was blocking the migration so what we do we take an implied_rules.def without any modification and we change it with our implied_rules.def, don't forget to save your original implied_rules.def to put it again after the migration

View solution in original post

0 Kudos
Stas_M
Employee
Employee

Sure. Anyway, if you see that you got "hanged" with this issue drop us an email to above address and we will take care of it.
Regarding .def files. The .def files are not transferred during migration. If you changed them in on-prem and then attempted migration to Smart-1 Cloud you will get warnings. And if for some reason you can't skip them I suggest to replace all .def files with their defaults and then to attempt migration. Then to open SR for TAC to make changes in .def files.

View solution in original post

33 Replies
G_W_Albrecht
Legend
Legend

Let TAC look into the upgrade logs !

CCSE CCTE CCSM SMB Specialist
0 Kudos
M_Soler
Contributor

Thank you @G_W_Albrecht for your answer, I have already a case with TAC but it take a lot of time.

Do you know where I can found the logs related to the migration ?

Thank you again

0 Kudos
G_W_Albrecht
Legend
Legend

No - you could look into the script itself.

CCSE CCTE CCSM SMB Specialist
0 Kudos
Ian_Cresswell
Contributor

did you have any success with TAC, I am having the exact same problem.

0 Kudos
M_Soler
Contributor

For us the implied_rules.def was blocking the migration so what we do we take an implied_rules.def without any modification and we change it with our implied_rules.def, don't forget to save your original implied_rules.def to put it again after the migration

0 Kudos
Ian_Cresswell
Contributor

We have a problem with both tables.def and implied_rules.def.

I built a new Management server in Azure and replaced these two files, that fixed the error for tables.def but we still have the same problem with implied_rules.def.

I have downloaded the install .tgz from checkpoint so will extract the file from there and see if that lets me get past this error.

It seem the --ignore_warnings flag needs to be inside the script as if you append it to the end of command it is simply ignored.

0 Kudos
Stas_M
Employee
Employee

Hi @M_Soler and @Ian_Cresswell , 
I'm Smart-1 Cloud Customer Success engineer. 
Please send details and your Service ID to  MANAGEMENT_AS_A_SERVICE@checkpoint.com  and I will take a look on logs.
Or alternatively you can ask TAC to open a task for Smart-1 Cloud team.
Regards,
Stas

0 Kudos
Ian_Cresswell
Contributor

I do have a TAC case open under our management server for this error but as it is a migration and not a break fix I am having difficulty getting help from TAC, I am also waiting for the paperwork to go through for our support on Smart-1 cloud which is further complicating the issue.

 

0 Kudos
Stas_M
Employee
Employee

Sure. Anyway, if you see that you got "hanged" with this issue drop us an email to above address and we will take care of it.
Regarding .def files. The .def files are not transferred during migration. If you changed them in on-prem and then attempted migration to Smart-1 Cloud you will get warnings. And if for some reason you can't skip them I suggest to replace all .def files with their defaults and then to attempt migration. Then to open SR for TAC to make changes in .def files.

Ian_Cresswell
Contributor

Thanks

I add the line:

echo "--ignore_warnings" > migrate_flags

towards the end of the script after echo: "-force-upgrade-flow" > migrate flags

This allowed the script to complete, not sure if this is a recommended method?

I will try import the file to the Infinity Portal and see if everything works that side.

0 Kudos
M_Soler
Contributor

I think you don't have an other solution, and you will not have an issue to ignore the .def files because after the migration you open a case to remplace the default .def with yours , and all will be ok.

0 Kudos
Stas_M
Employee
Employee

@Ian_Cresswell Well, you can use "--ignore_warnings" but the issue is that it will ignore all warnings and not only warnings about .def files. 
So if you want to use it I recommend first to run it without this flag and see if you getting warnings about .def only and then to run it with "--ignore_warnings". However, personally I prefer the @M_Soler solution i.e. to replace .def files with the default .def files. This way migration will not hang on .def and you will still get other warnings.

0 Kudos
the_rock
Legend
Legend

Thats 100% true, I used it myself few times and it does work with that flag on, but definitely does not address the real issue as to why it fails in the first place.

Best regards,

Andy

0 Kudos
(1)
Ian_Cresswell
Contributor

I did try that, I replaced the implied_rules.def with the file I extracted from Check_Point_R81.10_T335_Fresh_Install_and_Upgrade.tar but still got the same error regarding this file.

I had a similar problem with table.def but that was resolved once I replaced that file.

Not sure what else to do, do you have a suggestion where else I could get a copy of implied_rules.def?

I did not see any other errors or warnings in the Upgrade Report

0 Kudos
the_rock
Legend
Legend

I can get you clean file from that version if you like, but no clue if it would work.

Let me know.

Andy

0 Kudos
Ian_Cresswell
Contributor

Yes please Andy, would appreciate that.

 

I am on R81.10 with the latest hotfix applied.

0 Kudos
the_rock
Legend
Legend

OF COURSE mate, happy to try help you! Can you please message me directly with your email and I can send you the file securely?

Andy

0 Kudos
the_rock
Legend
Legend

K, just sent it, its encrypted email, not sure if it may ask you to create an account, but if it gets too complicated, I gave you my direct email as well, so shoot me a message and we can connect offline. Im sure it wont take more than 2 IT dudes to send a file 🤣🤣

Andy

0 Kudos
Ian_Cresswell
Contributor

I got it , thanks Andy.

Will try with this file and let you know how it goes.

the_rock
Legend
Legend

Lets do remote later if you are allowed to.Im very persistent guy, I dont give up easily on things, so Im fairly confident we can figure it out...this is in case file I gave you does not work.

Cheers mate.

Andy

0 Kudos
Ian_Cresswell
Contributor

Hi Andy

Unfortunately I got the same error Inspect files have been modified:/opt/CPsuite-R81.10/fw1/lib/implied_rules.def

I first simply replaced the file and when that didn't work I did a cpstop, replaced the file, ran cpstart and then ran the script again, same error.

I can do a remote session, just let me know when you are available, I am free the rest of the day today.

0 Kudos
the_rock
Legend
Legend

Dont worry, we will figure this out...I have some Fortinet stuff to do, but should be good any time between 12 and 2.30 pm. Im in EST, what about you? If its same time zone, we can do say 1-2 pm est?

Andy

0 Kudos
Ian_Cresswell
Contributor

I am in the GMT time zone, I am available up until 2pm EST, if you can make it earlier that be easier for me but I can make myself available until 2pm EST, you are helping me after all....

0 Kudos
the_rock
Legend
Legend

Just sent you direct email, Im fairly sure I can do it earlier.

Andy

0 Kudos
the_rock
Legend
Legend

Ok, my Fortinet thing was delayed till later this week, so Im free now. Please send the invite or I can create zoom meeting.

Andy

0 Kudos
Ian_Cresswell
Contributor

Thanks for your time earlier Andy, as you can see no matter what we do it always complains about the implied_rules.def file, even after I replaced it with a clean file from the checkpoint install files.

With the [echo "-force-upgrade-flow" "--ignore_warnings" >> migrate_flags] it does allow the migration tool to complete and creates the import file.

I have imported this to the infinity portal and everything looks fine, except, CME.

CME is enabled but there is nothing listed under the CME Management Name and when I try add an account under the Accounts (Controllers) section, it allows me to enter the details but when I click on Add it has a little think and then reverts to a blank page and never adds the account.

Does anyone have any idea on how to configure CME in the Infinity Portal?

0 Kudos
the_rock
Legend
Legend

Im very glad we spoke Ian, as it also got me thinking about CME part you showed me. As I mentioned to you over zoom, I also checked portal of a customer we support, as they have whole CP suite and in S1C portal, I dont see anything under CME tab, same as what you have.

I could be totally mistaken about this, but I was under impression that CME was only relevant in Azure vmss environment.

 

https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/Overview.htm

By the way, did you see screenshot I emailed you about those custom inspect files?

Best,

Andy

0 Kudos
Ian_Cresswell
Contributor

Hi Andy

The gateways I am trying to link up with CME are vmss gateways in Azure, they are in our database on the on Prem Management server.

I saw your attachment about the custom inspect files, at the moment my Infinity Portal looks the same, my worry is if any changes were made to my environment that affected the implied_rules.def file they would not be present in the infinity portal. Not sure if Checkpoint is able to import my implied_rules.def file to ensure it matches what I have on Prem?

0 Kudos
the_rock
Legend
Legend

I know some folks in TAC have backend access to S1C environments, so if you give them tenant ID, they can log in and check, for sure. I see what you mean about vmss gateways, totally makes sense in that case.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events