- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
This community helped me a lot in previous times but now I'm faced with an issue that I didn't find an answer.
I have a pair of CP15400 running in a clusterXL in front of a data center. That DC was supposed to be for a single client which has a huge server/storage resources
Now, the client decided to rent a part of that computer power 🙂
From the moment they expressed their willingness to rent a part of their environment we noticed a design flaw in CheckPoint deployment - we don't have any means for segregation network.
My question is - did anybody experienced the scenario where they migrated fully operational cluster to VSX? They don't have new boxes for this, rather they want to use current ones (and they already bought licenses for it). They are prepared for downtime but the question is how to do it with minimal impact?
Any suggestion/idea is greatly appreciated!
Cheers,
Travis
Travis,
There are a number of things that you need to to be aware of:
Hope this helps you on your way?
Hi Maarten,
Yeah, it helps!
Unfortunately - multidomain is not an option right now. Maybe in Q3.
Either way - management of that VSX will be done by one external person/company - end-users will not have access to it (DC owner is gonna become something like managed provider).
Idea is to have end-users separated on the Nexus side each in their own vrf and gateway for that vrf would be VS on the CP's.
One thing that I'm struggling with is this - how can I migrate current configuration from the running cluster (policies/objects/ip configuration/routes etc) onto a newly created VS?
Something like - export database and then import it to the new VS.
Once again - thanks a lot for your ideas!
Cheers,
Travis
Noup, we have a separate management server (VM).
As a potential solution, I was thinking of building temporary two new VMs (Gateways) and creating a new cluster under SMS.
Apply all the rules to those new VMs and basically divert aka free traffic from physical boxes.
That way, potentially I'll minimize downtime and have a few days to build VSX.
Does this make sense?
Cheers,
Travis
Hi Travis
Just wondering what approach you took in the end with this?
We're after coming across a similar situation with an existing clusterXL being split (also with a seperate management server) and we're trying to figure out the best approach to take.
Did you or anyone else figure a solution?
Thanks!
Eoin
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 20 | |
| 19 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY