Good afternoon.
Now there is a full-mesh vpn network on CheckPoint, but the current main SMS is located in another country (let's call it A) and manages all Checkpoint gateways. Communication with SMS via MPLS and via the Internet.
The separation of a part of the gateways and their transfer to the control of another SMS (in another location, let's call it B) is being considered.
I have an idea.:
1) deploy Secondary SMS to location B and connect it to the current one located in another country A.
2) Synchronize everything.
3) Make Secondary SMS active in the location of the Bar.
4) then, in some way, break the connection with another SMS in country A, say, disable MPLS or restrict connection.
5) you will probably have to deploy another SMS in location B with the same name as the former main SMS in country A and upgrade it to Primary.
5) Reinitialize SIC on gateways that require SMS connection in country A and possibly reinitialize SIC on gateways that will be connected to SMS in location B.
But I'm not sure about the result and the possibilities.
Maybe someone has asked such a task? what is the best way to perform such a separation-transferring part of the gateways to the new SMS?