- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Migrate Policy Package from Management to Standalo...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Migrate Policy Package from Management to Standalone Firewall
Hi Checkmates,
As per the subject, is there any possibility of exporting the policy package "Branch-Policy" from Open Server Management to a Standalone (3800) Firewall?
Context :
- My cust has several branches; some branches outside the region will be managed locally, not via Management.
- We plan to scratch the FW and import the policy from management.
Is it a good process? Does anyone have any previous experience with it and how to solve it?
I know this is not the best practice, but sometimes we can't follow the best practice because business is business 🙂
Thanks!
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please look at the following options:
Script to Export and Import Policy Package:
https://github.com/CheckPointSW/ExportImportPolicyPackage
Option to convert Management to Standalone (if possible in your case. Perhaps first Export/Import the machine as a whole and then make the conversion):
sk118033 https://support.checkpoint.com/results/sk/sk118033
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please look at the following options:
Script to Export and Import Policy Package:
https://github.com/CheckPointSW/ExportImportPolicyPackage
Option to convert Management to Standalone (if possible in your case. Perhaps first Export/Import the machine as a whole and then make the conversion):
sk118033 https://support.checkpoint.com/results/sk/sk118033
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A StandAlone Firewall is not best practice as you do not have HA clustering available and a defective on GW will also mean a damaged SMS. I would suggest to evaluate Smart-1 Cloud Management as an alternative.
