Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Khanh134752
Explorer
Jump to solution

SMS, Backup

Hi everybody
I want to transfer all my GW to another SMS, is there any way to keep the configuration, policies and objects intact through the new SMS?

2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

There are two ways to do this:

  • Using migrate_server which will take your existing SMS configuration and migrate to a NEWLY installed SMS (with no configuration) on different hardware/VM. This is by far the cleanest way to go since SIC will be re-established once policy is installed from the new SMS.
  • If you are importing to an existing SMS that already has configuration, you will need to use something like ExportImportPolicyPackage which will copy most of the rules/objects, but will require some manual steps, including re-establishing SIC.

 

View solution in original post

0 Kudos
the_rock
Legend
Legend

Migrate server is what you need, just use that as Phoneboy said. Related sk is https://support.checkpoint.com/results/sk/sk135172

I would simply use example shown, works just fine, just make sure to use right versions and obviously, file name can be anything you prefer.

Andy

View solution in original post

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

There are two ways to do this:

  • Using migrate_server which will take your existing SMS configuration and migrate to a NEWLY installed SMS (with no configuration) on different hardware/VM. This is by far the cleanest way to go since SIC will be re-established once policy is installed from the new SMS.
  • If you are importing to an existing SMS that already has configuration, you will need to use something like ExportImportPolicyPackage which will copy most of the rules/objects, but will require some manual steps, including re-establishing SIC.

 

0 Kudos
Nguyen134854
Explorer

Can this method be used in case I change the IP of SMS?

 

0 Kudos
Bob_Zimmerman
Authority
Authority

Sure. The IP of the management doesn't matter much. It's a little easier if you make a new secondary management object with the new address, and push policy to make all of the firewalls aware of it ahead of time.

Note that the new management MUST have the same hostname as the old management. Changing a management's hostname is pretty painful since it's tied to the management's certificate authority.

0 Kudos
the_rock
Legend
Legend

Migrate server is what you need, just use that as Phoneboy said. Related sk is https://support.checkpoint.com/results/sk/sk135172

I would simply use example shown, works just fine, just make sure to use right versions and obviously, file name can be anything you prefer.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events