- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Migrate VSX Gateway to New Management
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Migrate VSX Gateway to New Management
Hi all,
Hi have a enviroment with two 15600 running vsx in R80.10, we need to split the management server that also has the log/event role in two diferente servers, one for management and other for event/log. We already create the two server and migrate the management database to the new server and build the sic with the new event/log. Now we need to migrate the gateways but we are not sure what could be the steps to migrate only one gateway at a time to minimize the downtime. The new management as a diferent name and ip address. If anyone could give any ideias , will be welcome.
Thanks in adanced,
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You may try as follows, this is very brief to give an idea
- Create snapshots on both gateways in case you need to go back
- Disconnect all but Mgmt interface cables from standby node, lets call it FW2, to prevent uncontrolled traffic failover once you have connected to the new mgmt server and configured firewall
- Run reset_gw command on FW2 that will wipe out current VSX config. Ideally from console port, but Mgmt will work too
- Make sure that you can reach new management server IP from FW2. Do ping from firewall
- From your management server run vsx_util reconfigure command. If your management DB has been migrated correctly and nothing is corrupted regarding VSX objects, than command should complete and you will have full VSX config on FW2. If it fails, you will need to investigate
- Set 64 bit mode if it was set originally (check with vs_bits -stat )
- Reboot FW2
- Set affinities the same way as they are on FW1
- Check/Set MultiQueue
- Check/Set CCP broadcast/multicast
- Your gateway should be ready now. Check vsx stat -v and cphaprob stat
- Try pushing all topologies and policies from new management to FW2 (untick box to allow installation if one gateway in cluster fails)
- Cutover - you will not be able to synchronize connections tables as firewalls belong to different clusters. One option is to allow out of state connections before step 12 that will make cutover more seamless
- Note your statistics on FW1 (i.e. using cpview) so you know what to expect on FW2
- Unplug all interfaces from FW1 (except Mgmt) and plug in all on FW2
- Check statistics on FW2 i.e using cpview
- Do your testing to make sure everything is working
- repeat steps 3-12 with FW1
- plug in cables to FW1 and failover to it to check functionality
- Double-check licenses on gateway and mgmt
- Set out of state back to normal if your changed it and push all policies
