- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello gentlemen,
We've lost our SMS Virtual Machine and have no backups and no way to recover it. We have 2 Security Gateways in ClusterXL. Gateways are working fine but we are unable to change anything in policy because of the lack of SMS.
1. Is there any way to recover policy (access rules, objects, exceptions etc.) from gateways and import it to SMS?
2. If first option is impossible what is the safest method of reinstalling SMS in our situation ? By safest I mean anything which allows us to save as much as possible from working configuration and has minimal impact on our production environment?
Thank you for all your answers, I hope there is a solution other then creating everything from scratch.
Step1: Backup your gateways now
Step2: Install ccc on your gateways to check what IP your SMS had and what the security policy‘s name was, VPN gateways IP addresses, VPN topology, interface topology and much more
Step3: Set up a new SMS VM with the same IP it had before
Step4: Create a cluster object with the two cluster nodes that you have
Step5: Establish SIC to the new SMS using this procedure.
Step6: Read in the entire cluster topology
Step7: Recreate the rules using the $FWDIR/state/local/FW1/local.rule file on your gateways.
Step8: Install the new security policy
Step9: Check if everything is fine. In case it‘s not, restore the backup from Step1 and rework your security policy before trying again from Step5
Depending on the version, the answer might be different. Best is to request Check Point Professional Services to help you out.
Version is 80.30.
Step1: Backup your gateways now
Step2: Install ccc on your gateways to check what IP your SMS had and what the security policy‘s name was, VPN gateways IP addresses, VPN topology, interface topology and much more
Step3: Set up a new SMS VM with the same IP it had before
Step4: Create a cluster object with the two cluster nodes that you have
Step5: Establish SIC to the new SMS using this procedure.
Step6: Read in the entire cluster topology
Step7: Recreate the rules using the $FWDIR/state/local/FW1/local.rule file on your gateways.
Step8: Install the new security policy
Step9: Check if everything is fine. In case it‘s not, restore the backup from Step1 and rework your security policy before trying again from Step5
Unfortunately such tool hasn't been created yet. I'm planning to do this later this year and add it to ccc.
Did you, by any chance, opened a support request and sent CPINFO file from your management to Check Point TAC in the past?
First of all, thank you for all the answers.
Unfortunately we have never sent CPINFO to CheckPoint TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 15 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY