- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I'm looking for a way to extract a policy from 77.30 and move it to 80.10 mgmt. There were some solutions posted on different occasions but none is correct.
- confwiz is for older versions
- python tool is for 80.10
Before opening a ticket with CheckPoint, I would like to know if somebody was successful.
Many thanks for your feedback.
Catalin
you can use upgrade tool for migrate a single cma and then import to r80.10 with cma migrate , this at least work 100% with mds non sure about smartcenter but it should work in the same way
It is also possible to simply upgrade the R77.30 to R80.10 keeping the policy...
Unfortunately upgrade is not an option.
I was thinking about 'upgrade export ' but hopping about something better, thanks.
"migrate export" is the correct tool for the job. What is it that you find difficult or problematic with it?
I'd suggest running a pre-upgrade verifier first to see if there are any issues with the process. If there are, migrate export to the same version, restore in VM environment, make necessary adjustments to remove issues mentioned by verifier and re-run the migrate export with the 80.10 version of tools.
The issue is that I have to export only one policy from 77.30 and migrate to 80.10. The others will stay on 77.30 for now. Taking only the relevant policy and the DB used by that policy, this is problematic. Maybe the manual way is a better option!? Recreating the objects and the rules, if there are not so many. Just asking if somebody had to do the same.
Thanks for the explanation.
Unfortunately, I do not believe that there is a way to do that in 77.30 to R80.XX moves without intermediate steps I have described above.
You'd have to create an intermediate VM, delete the rest of the Policy Packages on it and migrate export the one remaining.
Hi Vladimir,
indeed 'migrate export/import' was the tool. Then I cleaned the policy and DB and ran the migrations tools to 80.10 on 77.30 VM. After some time, importing was done on 80.10 VM. As you mentioned already, without intermediary steps, I don't see how else we can do it. Thanks!
You are w:)lcome!
There is no "simple" solution to this problem as the configuration databases and formats used are very different.
In addition to the other options mentioned here, you might be able to do something like:
No matter which approach you take, some assembly will be required.
It'd be nice to have an option to "export policy package" in SmartConsole in R80.XX, instead of relying on scripts with their own dependencies and possibilities of errors and omissions.
Interestingly enough, you can export the rules as a CSV file right from SmartConsole in R80.x:
However, there is no way to import this CSV file again, or all the objects it refers to, which would be required for the CSV file to be useful.
A useful policy package export would have to include not only the rules but the objects in it.
Agree this is an area for improvement.
BTW: the CSV export does cheesy job: the group members are not included in it.
Old Web visualization tool was actually much better, since we've could wrestle Excel to extract useful data from it.
Thank you Vladimir and Dameon for your input. CheckPoint doesn't support any solution to extract 77.30 policy and migrate it to 80.10. In the end I was able to import successfully only the objects (via script) and I was recreating the groups manually. Because that specific policy I had to migrate was small, in the end I did it manually.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY