- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hey there, we just migrated one of our management server to a server with new hostanme and new ip. As the old management server is also still in use, we had to change ip and name of the new one.
Now we want to renew the sic of managemnt server (fwm sic_reset), thus we have also to renew the sic to the gateways. Now the question: Is there a recommended way to do that for vsx gateways and vsx cluster? I think resetting sic for vsx with cpconfig is not a good idea. Do I have to reset the sic per VS or can it be done for hole gw/cluster?
Any help is appreciated.
Hello PhoneBoy,
In my last post I forgot to write which releases we use:
Old management server: R77.30 (server still in use, will soon upgraded to R80.20)
New Management server: R80.20 (server has new hostname and ip)
Cluster/Gatewaysm: still on R77.30
Hi phoneboy,
thank you for your reply.
Yes you are right. Normally we should avoid to break the ICA. But the old management server is still online and used. What we have done, we splitted the manager into two. Means we now have two management server each of it serves some of the gateways/cluster, which were managed before by only one server.
I know, we could use all the old stuff (ICA and SIC certificates) on both servers, but we don‘t want to get into future trouble with that. That was the reason for the sic_reset on the new server.
Example: We use QRadar as SIEM system. When not creating a new ICA on the new server we will have two lea connection from our QRadar. One to each management server, but with the same credentials (hostname is the same, only IP is different). That works for now, but who knows if that is a recommended configuration. So we decided to create on one server the new ICA.
We figured out, to reconnect a vsx cluster from the old to the new management server, we have to do a fresh install on each of the both cluster gateways and then do a vsx_util reconfigure - that works. But that means we have an Outage.
Do you have a more comfortable idea, maybe without outage? Or only short outage?
Thank you in adavance,
Markus
Hello PhoneBoy,
In my last post I forgot to write which releases we use:
Old management server: R77.30 (server still in use, will soon upgraded to R80.20)
New Management server: R80.20 (server has new hostname and ip)
Cluster/Gatewaysm: still on R77.30
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY