- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi Guys,
I am task to migrate a security gateway purposely for VPN to a new 5600 NGTP with R80.20 OS. I would like to know how to migrate a security gateway, do I still need to do the migrate export and migrate import?
Thanks
OK so the Security Policy is held on the Managment Server so that doesn't migrate.
What looking at is extracting the Gaia OS config and importing onto the new Box
You can use the show configuration command to display the current Gaia OS configuration from the unit.
You can take that output and place into a text file
Then edit the configuration to reflect the new Appliances Interface Names. Don't know your current model so may not use the same interface names
You can then paste the file contents into the 5600 after running through the initial config wizard. This should get your interfaces and routes into the box,
Obviously this only takes the Gaia Config so will need to look at other files that may have been modified
$FWDIR/boot/modules/fwkern.conf - kernel paramaters
$FWDIR/conf/trac_client_1.ttm - remote access client
Are the ones that I usually find the need to look at, again, probably worth checking the contents of all of these. They may or may not exist in your environment. Certainly the last 4 which are for RSA SecurID for instance.
Other people may be able to add other files to look at,
Can then establish SIC, license and push policy
migrate export/import is a management level tool
When you say migrate do you mean migrate to be
a) new hardware - ie box replacement
b) move vpn in policy to new termination point
Hi @mdjmcnally
What I mean is to move all configuration from old hardware (r77.x) to new hardware (r80.20).
Thanks
OK so the Security Policy is held on the Managment Server so that doesn't migrate.
What looking at is extracting the Gaia OS config and importing onto the new Box
You can use the show configuration command to display the current Gaia OS configuration from the unit.
You can take that output and place into a text file
Then edit the configuration to reflect the new Appliances Interface Names. Don't know your current model so may not use the same interface names
You can then paste the file contents into the 5600 after running through the initial config wizard. This should get your interfaces and routes into the box,
Obviously this only takes the Gaia Config so will need to look at other files that may have been modified
$FWDIR/boot/modules/fwkern.conf - kernel paramaters
$FWDIR/conf/trac_client_1.ttm - remote access client
Are the ones that I usually find the need to look at, again, probably worth checking the contents of all of these. They may or may not exist in your environment. Certainly the last 4 which are for RSA SecurID for instance.
Other people may be able to add other files to look at,
Can then establish SIC, license and push policy
Hi @mdjmcnally ,
Even if I will not import the following files, it will still work right? By the way, I am using MEP for my remote access VPN, where is the configuration of that?
FILES:
Thank you so much for the help.
So, building the new box with the existing configs from the old box then pushing the policy with the VPN configs should bring everything over for remote access configs?
Yes
Thanks dude for the reply! i had a couple more questions that i replied via email to the community.
@PhoneBoy
About the license? We need open a ticket with CP to move? From a Appliance to another?
Unless you're dealing with Open Server, you're not usually moving licenses.
If IP addresses are changing, you will need Account Services to issue you new license(s).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
12 | |
10 | |
7 | |
7 | |
5 | |
5 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY