- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
We recently upgraded MDM to R81 which has a dedicated Smart Events server attached to the Global domain. We experienced problems with the Advanced Upgrade (migrate_server) tool on the secondary MDM management server and MDM log server and decided to simply redeploy these as part of the upgrade process.
ie: We deleted each domain's standby management server and log server and then re-created them.
Running log doctor also complains about duplicate servers being defined, herewith the view when editing the Correlation Unit in SmartEvent:
We're running R81 JHA take 23 on primary and standby MDM management servers, MDM log server and dedicated SmartEvent server.
Domain view:
PS: SmartEvent server status shows all objects being in sync:
Regards
David Herselman
Hi,
I'm Kobi Ohayon from R&D, responsible for SmartEvent.
It is hard to know exactly what led to this situation, since there is missing information.
What do you mean by re-deploy, fresh install? what was on the partitions while installing?
What went wrong with the upgrade itself that you decided to re-deploy the server?
If the only problematic issue is the duplicate of objects, you just need to resync DBSync using the clean_dbsync_tables.sh script (sk116335)
Pay attention that this script causes cpstop/cpstart.
Thanks.
Hi,
I'm Kobi Ohayon from R&D, responsible for SmartEvent.
It is hard to know exactly what led to this situation, since there is missing information.
What do you mean by re-deploy, fresh install? what was on the partitions while installing?
What went wrong with the upgrade itself that you decided to re-deploy the server?
If the only problematic issue is the duplicate of objects, you just need to resync DBSync using the clean_dbsync_tables.sh script (sk116335)
Pay attention that this script causes cpstop/cpstart.
Thanks.
Hi Kobi,
That certainly did. Many thanks for the tip, running the script provided in sk116335 allowed us to reconfigure SmartEvents and removed all duplicates.
To answer your earlier questions though:
We ran migrate_server to generate the advanced upgrade TGZ archive on all systems successfully (MDS primary, MDS standby, MDS log and Smart Event server). Stopped those VMs and installed R81 on new VMs with the same network settings, then ran the first time wizard as the appropriate role (MDS primary, MDS standby, MDS log and finally dedicated Smart Event server for the global domain). We then created a snapshot before installing licenses and running '$MDS_FWDIR/scripts/migrate_server verify -v R81', validating 'cpprod_util CPPROD_GetValue CPupgrade-tools-R81 BuildNumber 1' returned the then current '995000486'. We would then try to run migrate_server to restore the TGZ which worked for the MDS primary and Smart Event servers but failed thrice for the MDS standby and MDS log servers.
We subsequently reverted to snapshot, connected to MDS primary and removed each domain's standby management server instance and log instance, after which we removed the MDS servers. Then established SIC with the new MDS standby and MDS log server and re-created all domain server instances, connecting to each domain to update logging on the security gateways and installing policy on each one.
The problem was logged as 6-0002724907, should someone at Check Point wish to reproduce the problem in a lab to aid others pursuing an R81 upgrade in future.
Regards
David Herselman
Hi David,
Please let us know if the suggested solution by Kobi helped you.
Thanks,
Ido
Hi,
Yes, the clean_dbsync_tables.sh script provided in sk116335 removed the duplicate server objects.
Again, many thanks!
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY