- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello!
I have a situation where on the primary SMS, that manages all the gateways, customer have also enabled Endpoint Management, now they want to split functions, I mean, they want the SMS just for managing the gateways and a dedicated Endpoint Management Server to manage the endpoints and policies.
I could not find any documentation that describes this scenario.
If I just take a migrate export from SMS and import on the new server, I'll have all the unused objects and policies imported too, that's what I would like to avoid.
Is there a way that I can split the endpoints database from the SMS and import on a new server?
Thanks.
Super valid question...maybe TAC would have process for it, but personally, Im not aware of any method to "split" the database.
Andy
Hi,
Not an EP expert, but have one question - do you want to move it to a completely different environment or just another machine?
I wonder if adding another Check Point Host to your environment and defining it as EP server might do the trick.
Hello, Amir, the perfect solution would be as you said, on a new machine attached to the same environment, but the documentation says that for a dedicated EPM Server, I need to follow the installation procedure for a "Primary SMS", if that's true, I don't see how I can add another primary SMS to the actual environment.
Thanks!
Suggest you consult with TAC for the correct procedure here.
As I recall, it depends on the client blades used.
Yes, I'm afraid I'll need to get in touch with TAC. I was avoiding it, because sometimes involving TAC requires much time. CheckMates would have been a faster solution.
Thanks anyway.
I totally get what @Amir_Senn mentioned. Now, here is the issue you may encounter, in my humble opinion...so in your current situation, I bet option to uncheck endpoint is probably greyed out and not sure there is an easy way to do it. If there was, then you could indeed create another CP host and check endpoint option on that host.
Andy
Hello @the_rock.
The problem here is that the "main" dedicated server needs to be a primary SMS, customer do have 2 more policy servers, but they can not be the main managers, and, of course, I can not have a second primary SMS on this environment.
Best Regards.
I get it now. Not sure best process in that case...I would definitely check with TAC.
I can only find SKs about migrating from SMS + EPSS to Harmony Cloud EPS using a special migration script downloaded from Infinity EPS portal. I would assume that involving TAC will not delay this much, as we do not have an issue here but only need a supported procedure for this task that should be available. I remember that this is possible, but not the migration steps used. You could also ask your local CP SE for help.
Hello @G_W_Albrecht, if could share the sk you mentioned, that may be helpful.
I have also engaged TAC on this (case 6-0004184653), but I don't think there is an available procedure for this task, because the engineer asked for a migrate export and said he would replicate it in lab (as an exception, I understood) and he will try to do it for me, but he told that these kind of things are usually done by Professional Services.
I did ask for help to my local SE, but he didn't help me either.
This TAC case is my last hope.
Thank you!
I do not think they might be, but: https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/...
https://support.checkpoint.com/results/sk/sk179687
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 15 | |
| 13 | |
| 10 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY