Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mitesh
Participant

Checkpoint Gateway Migration

Hello Team,

In our current setup we running 5600x2 appliances in cluster (ClusterXL), company has bought 9100x2 appliances. We want to perform Cluster Migration. We having below question relating to migration.

1. Can we add new 9100 appliances into existing cluster ? if yes than what will be steps or We create completely fresh cluster & push the policies to new cluster.

2. During migration what kind of challenges or issue we can face ?

 

0 Kudos
7 Replies
G_W_Albrecht
Legend Legend
Legend

1, Is not possible - clusters have to use the same hardware. You have to create a new cluster, replace the old by the new one in the rules and vpn config, install policy and delete old cluster from dashboard.

2. Depends - e.g. cluster VIP can be an issue

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Mitesh
Participant

@G_W_Albrecht Thanks for the reply....

We want to keep the same Cluster VIP.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

So you will need a maintenance window.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

I believe below link can be helpful.

I used it few times with customers and never had an issue. You just have to make sure 100% that topology reflects the new hardware.

Andy

https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/157228#M27268

0 Kudos
Mitesh
Participant

@the_rock @G_W_Albrecht  thanks for your reply....

What I understood is for Gateway migration on different hardware (new hardware) need to create new clusterXL, on same Cluster will not work.

Correct me if I'm wrong. 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Same cluster is not possible - clusters have to use the same hardware. ClusterXL will not start. I wrote that on 27. already....

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

No, you dont. Process I sent you, the solution Heiko Ankerbrand gave works 100% for different hardware, specially if you wish to keep same IP addresses. Actually, even if they are different, it would still work, as long as they match on OS level and in topology. 

I did that 7 times so far, 6 times IPs were same, 7th were little different and worked every time and EVERY time, hardware was totally different...couple times from 4000 to 6000 series and last few times from 5000 to 9000 series, so that absolutely would tell you that different hardware works, as long as you ensure the other things I mentioned are right.

You can replace the cluster if you want and do it "clean" way, but it will take you very long time. Btw, I never had any complaints from customers after doing that process below.

https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/157228#M27268

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events