Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
an_technical
Explorer

migrating from standalone to distributed model

Hi Team,

 

we have following architecture in our organization.

2 standalone firewalls in cluster

1 in distributed setup

 

we got new mgmt server and want to manage all firewalls through new mgmt server.

I can do database export import for distributed setup but how can i move policies from standalone firewall to new mgmt server. I used export_import_package and its throwing lot of errors. 

0 Kudos
10 Replies
Tal_Paz-Fridman
Employee
Employee

Please make sure to follow the instructions in https://support.checkpoint.com/results/sk/sk179444

Migration from a Standalone environment to a Distributed environment to versions R81.10 and higher versions

0 Kudos
an_technical
Explorer

Thanks @Tal_Paz-Fridman : I will test this.

I also wanted to know how to migrate the distributed env mgmt server to the new mgmt server. Will migrate_server will solve the problem?

0 Kudos
Tal_Paz-Fridman
Employee
Employee

As noted in the SK, migrate_server is part of the flow 

0 Kudos
an_technical
Explorer

Okay. One more question I have. migrate_server from standalone and distributed can be imported into new mgmt server?

 

0 Kudos
Tal_Paz-Fridman
Employee
Employee

migrate_server is the utility used for the export and import. It can be run from any machine that has a database. 

Just follow the instructions closely and it will work.

0 Kudos
an_technical
Explorer

Hi @Tal_Paz-Fridman :

I tried replicating sk179444. It failed with error: Migration between full HA and non full HA machine is not supported. The standalone devices are in HA.

Any suggestions. How to resolve this?

0 Kudos
an_technical
Explorer

Hi @Tal_Paz-Fridman : I tried following this article:
https://community.checkpoint.com/t5/Management/Moving-from-Full-HA-to-Distributed-on-R80-x/m-p/13068

I can only see the configuration2 file not the configuration file.

When I export export_standalone file. I get below content:

 

drwxr-xr-x 8 admin root 4.0K Jan 19 11:27 .
drwx------ 16 admin root 4.0K Jan 19 21:54 ..
drwxr-xr-x 3 admin root 164 Jan 19 11:27 31ab94da-4ab1-5da9-a03d-ddddddaaaaaa
drwxr-xr-x 3 admin root 164 Jan 19 11:27 41e821a0-3720-11e3-aa6e-0800200c9fde
drwxr-xr-x 3 admin root 164 Jan 19 11:27 8bf4ac51-2df7-40e1-9bce-bedbedbedbed
drwxr-xr-x 4 admin root 4.0K Jan 19 11:27 a0bbbc99-adef-4ef8-bb6d-cebcebcebceb
drwxr-xr-x 3 admin root 164 Jan 19 11:27 a0eebc99-afed-4ef8-bb6d-fedfedfedfed
-rw-r--r-- 1 admin root 57M Jan 19 11:27 a0eebc99-afed-4ef8-bb6d-fedfedfedfed.tgz
-rw-r--r-- 1 admin root 23K Jan 19 11:27 com.checkpoint.management.mgmt_blade.objects.DomainBase.data
-rw-r--r-- 1 admin root 7.3K Jan 19 11:27 com.checkpoint.management.upgrade.objects.UpgradeRuleData.data
-rw-rw---- 1 admin root 60M Jan 19 21:54 export_standalone
drwxr-xr-x 4 admin root 4.0K Jan 19 11:28 extra_data

This don't have configuration file.

If I extract a0eebc99-afed-4ef8-bb6d-fedfedfedfed.tgz
This has configuration2 file. After making the changes. I run below command 

tar -cvzPf export_standalone * and import the file. Import fails. I tried with .tgz extension as well.

Please suggest.

@_Val_ : Can you also please guide.

Thank You

 

 

0 Kudos
Tal_Paz-Fridman
Employee
Employee

The SK states clearly:

 

Limitations

These migration procedures do not support Full High Availability clusters (Full HA).

 

This might require contacting TAC or PS or use tools just to export and import the policy:

https://github.com/CheckPointSW/ExportObjects

https://github.com/CheckPointSW/ExportImportPolicyPackage

 

_Val_
Admin
Admin

As Tal already mentioned, Full HA migration is not supported. Open a TAC ticket to see if they can help you. Otherwise, you will need to engage with Check Point PS or re-create policy manually or through APIs

0 Kudos
_Val_
Admin
Admin

Also, the article is for a much older SW version, the suggested case will not work for you anymore.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events