- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- VSX migration
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VSX migration
Hi all,
This is my first post on this community which I like alot!
So to my issue, I'm going to migrate a Check Point cluster (appliances) to a VSX enviroment.
It's running on R80.10 the managment and on the gateways.
I guess the biggest challange will be the VPN tunnels (also it has to 3rd party VPN).
So my question now do you guys have any experience with this kind of migration, how I can prepare in the best possible way? Also I want the best way to possible solution for less impact.
Thanks in advance!
Best Regards
Philip
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is the cluster currently managed by the same management as the VSX cluster?
Will there be a 1 on 1 Cluster to VS migration? So all interfaces and VIP's will be reused on the VS?
If so that simplifies things, there are number of ways to do things, what I would do in that case:
- make sure the vlan's used on the physical cluster members are not allowed on the ports to the VSX cluster.
- add a new VS that takes over a part of the cluster and give it the correct interfaces and IP's
- add the VS to the VPN community in the same place as where the old cluster was, in a star the center gateway
At the moment of migration
- just disable the switch ports of the old cluster and allow the VLAN's to the new VS
- in the VPN community remove the old cluster from the gateways list - the PSK will remain and when your external IP is still the same (moved from cluster to VS) the VPN should restore on the VS.
- push Policy
Hope this gives you an idea on how to proceed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is the cluster currently managed by the same management as the VSX cluster?
The VSX cluster I haven't not configured yet, but yes it will be on the same managment.
Will there be a 1 on 1 Cluster to VS migration? So all interfaces and VIP's will be reused on the VS?
The cluster will be migrated to 2 VS, one for VPN tunnels and the other one for all other.
The external VIP IP will be the same for the VPN VS.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The only problem will then be to split functionality and IP's in the migration windows.
