Hello Everyone,
I have a Check Point VSX VSLS cluster running R81.20 (JHF 119). I also have a Check Point Security Management Server running R81.20 (JHF 119), deployed as an EC2 instance on AWS, which manages the VSX cluster members as well as virtual systems.
I am planning to upgrade the Security Management Server from R81.20 to R82. My approach is to deploy a new EC2 instance with Check Point SMS R82 (JHF 44) and import the output of migrate-server from the existing management server into this new instance. The hostname and IP address of the new management server will differ from those of the current one.
What I would like to understand is how SIC with the VSX cluster will be established after the migration. Specifically, I am unsure how the VSX gateways (and their virtual systems) will trust the new management server.
I am considering the following steps and would appreciate your feedback on whether this approach will work:
Set a new SIC password on the VSX cluster members using the cpconfig command.
Run vsx_util reconfigure from the new management server to establish SIC with the VSX cluster members and the corresponding virtual systems.
Install the security policy from the new management server.
Could you please confirm if this approach is valid, or suggest any recommended best practices or alternative steps for this scenario?
For safety, I have already taken snapshot backups of the Security Management Server and the VSX cluster members.
Regards,
Abdul Tayyeb R.