Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
antsvett3
Participant

Standalone backups and appliance refresh

Hi All,

I have been tasked with refreshing appliances in a standalone environment with 1 firewall and another in an HA environment.

Everything I'm seeing is to get a snapshot, Gaia backup and perform migrate_server export on the current appliances and a migrate_server import on the new. The single environment is running R81.20 and the HA is running R81.10 which will be upgraded to R81.20.

With that said I was speaking with my customer and they seem to say the Gaia backup is sufficient to do this migration to the new appliances. He set this up originally.

I don't think this is correct and there may be some confusion. I have a meeting next week with my customer so I want to be sure I'm correct as I've never performed these tasks.

Any input is appreciated.

 

Thanks,

Anthony

 

 

 

0 Kudos
12 Replies
the_rock
MVP Platinum
MVP Platinum

Hey Anthony,

So, just to make sure there is no confusion, is it standalone as it gw+mgmt as one appliance or there is separate mgmt? If its distributed (separate mgmt), then you can absolutely do migrate_server export, then import into new server with desired version.

Its all documented below:

https://support.checkpoint.com/results/sk/sk135172

Now, when it comes to firewalls, backup will never work on a different hardware, as interfaces would never match, plus, Im sure version would not be the same. What I always do is this. Generate clish config, say from expert mode -> clish -c "show configuration" > /vaqr/log/hostname_config_date.txt, (just change the name) and would generate txt file with the clish config in /var/log

Then, you can use that file to copy bits and pieces to new fws, as long as interface name matches correctly.

After all that id done and verified, I always use below process, never had the issue.

Solved: Replace/Upgrade Cluster - Check Point CheckMates

Hope that helps!

Best,
Andy
antsvett3
Participant

Hi Andy,

These are appliances running both Mgmt and firewall. I've done firewall migrations/upgrades but never when running Mgmt and firewall on the same box.

Thanks,

Anthony

0 Kudos
the_rock
MVP Platinum
MVP Platinum

O ok, then you can do migrate export as well, just follow the sk I mentioned, as its not version dependant. It would import all the objects, along with smart console services etc, so there would not be an issue. I had done this before in the lab, from R81.20 to R82.

Best,
Andy
0 Kudos
antsvett3
Participant

Thanks Andy. I'm trying to practice in my lab so we'll see how it goes.

the_rock
MVP Platinum
MVP Platinum

Good idea! btw, if say export fails for whatever reason, just run -h flag to see all the options, but I always found one with --ignore_warnings would take care of it.

Best,
Andy
the_rock
MVP Platinum
MVP Platinum

Since I was doing some other lab, what I did was built R81.20 standalone and then followed migrate server to import to R82 standalone, worked like a charm.

Best,
Andy
antsvett3
Participant

Awesome Andy!!

0 Kudos
the_rock
MVP Platinum
MVP Platinum

It only had 4 rules, but I just wanted to have something more than clean up rule, as that would prove it worked.

Best,
Andy
0 Kudos
antsvett3
Participant

Cool Andy, good to hear. I will continue testing!

0 Kudos
the_rock
MVP Platinum
MVP Platinum

I just did it last night, but had to delete it, so much space on eve-ng and Im the worst "suspect", since I try to do labs for whatever I can : - )

Anyway, point is, it did work!

Best,
Andy
0 Kudos
Don_Paterson
MVP Gold
MVP Gold

Hi Anthony,

The Gaia back on a management server does do a database backup/migrate_server export but I would not recommend that for migrations. 

Always worth checking the Installation and Upgrade Guide. That is something you can share with your customer because it has procedures listed. 

The verify is important to do too. 

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Gui...

 

 

 

antsvett3
Participant

Hi Don,

Thanks for this. I've read all the documentation until i'm blue the face so its nice to get some others input.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events