- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello fellow members.
Would really appreciate your expert opinions on this matter.
Currently I'm tasked w/ converting an on-premise standalone R80.40 setup to a distributed management and Cluster-XL setup.
Let's call the current setup old-mgmt-gateway-01.
This also manages an Azure R80.10 CloudGuard IaaS instance, let's call this azure-cg-01.
There's a site to site VPN between old-mgmt-gateway-01 and azure-cg-01.
Remote VPN clients also connect to old-mgmt-gateway-01.
I'm proposing the following as per sk154033:
I've already achieved successful management HA sync.
Moving forward, I'm seeking clarity on the following:
If there are any other dependencies that you think I missed, do let me know.
Thank you,
Calvin.
Right-click on one of the instances it is used in the policy and select Where Used.
You can see all the uses of the old object and replace specific instances of it with the new object.
You're creating a new gateway which means a new certificate will be created.
Clients will get prompted on first connection with the new fingerprint but after that, you should be ok.
For Site-to-Site VPN, you should be fine since the CA won’t change and what matters is the endpoints being able to validate the certificate and access the CRL.
Unless you want to regenerate the ICA with the new management server name.
For HTTPS Inspection, what matters is the CA key used for signing the certificates (different from the ICA).
Not sure where that’s stored offhand.
Thank you sir!
I don't think I'll go down the ICA regeneration road unless necessary.
One more thing that I realized is that with a security policy of just over 320 rules, the 'Install On' column has old-mgmt-gateway-01 and adding the gateway new-clusterxl means that I'll need to add it to those rules as well.
SK108538 looks like it will do the trick if I wanted replace, but I want to make it an addition.
Any tips?
Thanks
Right-click on one of the instances it is used in the policy and select Where Used.
You can see all the uses of the old object and replace specific instances of it with the new object.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY