- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi ,
there is any step by step procedure o best practice to replace a gateway with a new model?
old gateway is 6600 with R80.40 and the plan is to replace it with 6900 with R80.40 / R81.10
the target is to preserve all the current states and configurations from the old firewall to the new firewall. the SMS is on other VM.
my plan is this procedure:
1. Backup old firewall and restore the backup on the new firewall.
2. Manually backup DHCP configuration file and IP Assignments file.
3. Upgrade new firewall to R81.10
4. Move the cables from the old firewall to the new firewall
5. Re-Establish SIC and edit gateway object propertie
6. Install Policy
what do you think about this plan? i missed any step?
Thank you in advance,
Yossi
By the way, below link could be helpful to you, though its cluster related, but same method applies.
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216
Also, make sure to NOT backup/restore, as its different hardware. Do clish -c "show confirguration" /var/log/configfile.txt on current fw, make necessary changes to reflect interfaces/routes on new fw and then on the new fw, from clich, run load configuration /var/log/configfile.txt (just make sure its in /var/log dir or wherever you move it to).
Hope that helps.
Andy
For the backup restoration you should also consider the JHF version to be safe, similar with the version upgrade don't just deploy it with the base image rather also apply the latest recommended JHF.
Chris is right, consider latest recommended jumbo as well.
Between step 1 and 2 you will have to perform FTW on appliance for basic config. Not sure if you need to remake SIC though...
Thank you very much for the insights. sure i forgot about the first time configuration wizard and the JHF version.
By the way, below link could be helpful to you, though its cluster related, but same method applies.
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216
Also, make sure to NOT backup/restore, as its different hardware. Do clish -c "show confirguration" /var/log/configfile.txt on current fw, make necessary changes to reflect interfaces/routes on new fw and then on the new fw, from clich, run load configuration /var/log/configfile.txt (just make sure its in /var/log dir or wherever you move it to).
Hope that helps.
Andy
For the Also part:
A Gaia backup, unlike a Gaia snapshot, can be restored on the same or a different appliance running the same Check Point Gaia OS version and hotfixes.
But:
So you are partly right with a very good point indeed !
Let us know if any issues. I had done this few times successfully, so can definitely help you out if need be.
Good luck!!
Thank you all very much for the help.
i will update on the results
Yossi
Any time. Here comes my corny joke everyone is sick off..."For you, no charge, except iphone charge" ; - )
Andy
SIC is needed there, for sure.
thank you everybody,
the replacement was smooth and everything works as planned.
only issue was after the first install policy DHCP and Office Mode was not working, resolved with a reboot.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
12 | |
8 | |
7 | |
7 | |
6 | |
5 | |
5 | |
4 | |
4 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY