- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Checkpoint Gateway Migration
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint Gateway Migration
Hello Team,
In our current setup we running 5600x2 appliances in cluster (ClusterXL), company has bought 9100x2 appliances. We want to perform Cluster Migration. We having below question relating to migration.
1. Can we add new 9100 appliances into existing cluster ? if yes than what will be steps or We create completely fresh cluster & push the policies to new cluster.
2. During migration what kind of challenges or issue we can face ?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, you dont. Process I sent you, the solution Heiko Ankerbrand gave works 100% for different hardware, specially if you wish to keep same IP addresses. Actually, even if they are different, it would still work, as long as they match on OS level and in topology.
I did that 7 times so far, 6 times IPs were same, 7th were little different and worked every time and EVERY time, hardware was totally different...couple times from 4000 to 6000 series and last few times from 5000 to 9000 series, so that absolutely would tell you that different hardware works, as long as you ensure the other things I mentioned are right.
You can replace the cluster if you want and do it "clean" way, but it will take you very long time. Btw, I never had any complaints from customers after doing that process below.
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/157228#M27268
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1, Is not possible - clusters have to use the same hardware. You have to create a new cluster, replace the old by the new one in the rules and vpn config, install policy and delete old cluster from dashboard.
2. Depends - e.g. cluster VIP can be an issue
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@G_W_Albrecht Thanks for the reply....
We want to keep the same Cluster VIP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So you will need a maintenance window.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe below link can be helpful.
I used it few times with customers and never had an issue. You just have to make sure 100% that topology reflects the new hardware.
Andy
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/157228#M27268
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@the_rock @G_W_Albrecht thanks for your reply....
What I understood is for Gateway migration on different hardware (new hardware) need to create new clusterXL, on same Cluster will not work.
Correct me if I'm wrong.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Same cluster is not possible - clusters have to use the same hardware. ClusterXL will not start. I wrote that on 27. already....
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, you dont. Process I sent you, the solution Heiko Ankerbrand gave works 100% for different hardware, specially if you wish to keep same IP addresses. Actually, even if they are different, it would still work, as long as they match on OS level and in topology.
I did that 7 times so far, 6 times IPs were same, 7th were little different and worked every time and EVERY time, hardware was totally different...couple times from 4000 to 6000 series and last few times from 5000 to 9000 series, so that absolutely would tell you that different hardware works, as long as you ensure the other things I mentioned are right.
You can replace the cluster if you want and do it "clean" way, but it will take you very long time. Btw, I never had any complaints from customers after doing that process below.
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/157228#M27268
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks....
Last Sunday we completed Security Gateway Migration activity successfully.
Steps which you mentioned we followed that & seamlessly completed activity. During activity while installing policy we got updatable object error due which policy installation got failed, using SK131852 (scenario 1) we resolved the error message.
once again thanks for the solution.
