- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi All,
I have been tasked with refreshing appliances in a standalone environment with 1 firewall and another in an HA environment.
Everything I'm seeing is to get a snapshot, Gaia backup and perform migrate_server export on the current appliances and a migrate_server import on the new. The single environment is running R81.20 and the HA is running R81.10 which will be upgraded to R81.20.
With that said I was speaking with my customer and they seem to say the Gaia backup is sufficient to do this migration to the new appliances. He set this up originally.
I don't think this is correct and there may be some confusion. I have a meeting next week with my customer so I want to be sure I'm correct as I've never performed these tasks.
Any input is appreciated.
Thanks,
Anthony
Hey Anthony,
So, just to make sure there is no confusion, is it standalone as it gw+mgmt as one appliance or there is separate mgmt? If its distributed (separate mgmt), then you can absolutely do migrate_server export, then import into new server with desired version.
Its all documented below:
https://support.checkpoint.com/results/sk/sk135172
Now, when it comes to firewalls, backup will never work on a different hardware, as interfaces would never match, plus, Im sure version would not be the same. What I always do is this. Generate clish config, say from expert mode -> clish -c "show configuration" > /vaqr/log/hostname_config_date.txt, (just change the name) and would generate txt file with the clish config in /var/log
Then, you can use that file to copy bits and pieces to new fws, as long as interface name matches correctly.
After all that id done and verified, I always use below process, never had the issue.
Solved: Replace/Upgrade Cluster - Check Point CheckMates
Hope that helps!
Hi Andy,
These are appliances running both Mgmt and firewall. I've done firewall migrations/upgrades but never when running Mgmt and firewall on the same box.
Thanks,
Anthony
O ok, then you can do migrate export as well, just follow the sk I mentioned, as its not version dependant. It would import all the objects, along with smart console services etc, so there would not be an issue. I had done this before in the lab, from R81.20 to R82.
Thanks Andy. I'm trying to practice in my lab so we'll see how it goes.
Good idea! btw, if say export fails for whatever reason, just run -h flag to see all the options, but I always found one with --ignore_warnings would take care of it.
Since I was doing some other lab, what I did was built R81.20 standalone and then followed migrate server to import to R82 standalone, worked like a charm.
Awesome Andy!!
It only had 4 rules, but I just wanted to have something more than clean up rule, as that would prove it worked.
Cool Andy, good to hear. I will continue testing!
I just did it last night, but had to delete it, so much space on eve-ng and Im the worst "suspect", since I try to do labs for whatever I can : - )
Anyway, point is, it did work!
Hi Anthony,
The Gaia back on a management server does do a database backup/migrate_server export but I would not recommend that for migrations.
Always worth checking the Installation and Upgrade Guide. That is something you can share with your customer because it has procedures listed.
The verify is important to do too.
Hi Don,
Thanks for this. I've read all the documentation until i'm blue the face so its nice to get some others input.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY