- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
sk61681 and sk85900 gives the solution which is quite different from each other. Does anyone has use these solution?
I need to migrate the policy from standalone to distributed. If so please suggest me the best way to do so.
Thank You
Sagar Manandhar
These SKs solve different problems:
Which approach you take will largely depend on what you want to use the current Standalone hardware for when it's all said and done.
you should use this : sk61681
Any specific reason?
If you only want the policy than i think you might be able to use the cpmerge util but i belive you want to keep all you managment server data ..( user db , internal ca...) The sk i pointed you to will provide it to you
I only need the object and policy. We don't need to restore the server data.
Than read about cpmerge utility you can export policy package and import it and the object.c for the object from the othe managment server
These SKs solve different problems:
Which approach you take will largely depend on what you want to use the current Standalone hardware for when it's all said and done.
i am importing the configuration between standalone machine and management only machine . Thanks.. i will follow this SK
What is the procedure for R80.10 version? Both the SKs say's it's not applicable to R80.xx version.
I think you should still be able to do a migrate export of the management piece, import into a new standalone management system, then do a clean install of the gateway.
You can easily test this without affecting your existing gateway (except for the cpstop required to take the migrate export).
Not clear with the answer. Let me reiterate the query:
I have R80.10 Standalone machine. Would like to migrate it to distributed setup(separate Mgmt server and GW).
Both sk61681 and sk85900 doesn't applicable to R80.xx
What do you suggest on this?
Tried this with a system that has VPN's configured. Seems the python script doesn't like Interoperable Devices and VPN communities as it failed to import;
Adding vpn-communities-star
Failed to import vpn-community-star with name [Corp_Carrollton_VPN]. Error: Invalid parameter for [shared-secrets]. Invalid value
Failed to import vpn-community-star with name [Corp_COLO_VPN]. Error: Invalid parameter for [shared-secrets]. Invalid value
👍
To describe what I said a little more verbosely:
Refer to the Installation and Upgrade Guide R80.10 for more details.
Are you sure that you can export a standalone configuration and import it to a mgmt only just like that on R80.30??
And if that succeeds, what about the gw object after the import? We ll need to "revert" this object to mgmt only in order to create a new gateway, is this possible??
Or should we just use the python method ??
Hello @PhoneBoy . while I appreciate the interest in doing it ourselves, I assume that support has ways to purge an "all-in-one" migrate export file of SIC and local gateway refernce(s)? I send them a "migrate export <>" from all-in-one export and they send back file without local gateway reference (and SIC reset)?
Because support has done numerous voodoo operations in past, I like this method instead of jumping through endless hoops that only burn time for everyone (customer, reseller, etc).
thoughts?
If TAC had such a tool, it'd most likely be formally documented in an SK, even internally.
I haven't seen that.
Hello -- I can confirm that SK154033 does work for Standalone migration to Distributed for R80.40. However, there are various clean-up aspects that are missing and we have SR open on topics.
In addition, the source standalone server was a CP-badged appliance running R77.30 with JHA. The R80.40-based standalone instance is temporary.
We used HyperV as virtual platform and took "snapshot/checkpoint" after initial GAIA install -- before wizard -- so we could clone into the other instances we needed (permanent and temporary).
Note: HyperV is supported for R80.40 in production with specific JHA/HFA take installed. See HCL for specifics (virtual machines tab).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
6 | |
5 | |
4 | |
4 | |
4 | |
2 | |
2 | |
2 | |
2 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY