CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Disaster Recovery
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-13
docstephano docstephano is offline
Junior Member
 
Join Date: 2007-09-05
Posts: 7
Rep Power: 0
docstephano has an average reputation (10+)
Default Splitting a SmartCenter in two

Hello,
I have a question regarding both disaster recovery and backup/restore procedures: but I do not want to crosspost in all directories... yet...

My point is: I have a distributed R65 installed on a GreenSmartCenter with two (DarkGreen and LighGreen) fw modules connected to it.
I have another bright new empty R65 RedSmartCenter, with a different IP and different name, without any fw module managed yet.

I'd like to split the modules on both gateways => get DarkGreen managed by RedSmartCenter... without the need to recreate greens objects and policies: that's the challenge.

(Possibly, I wouldn't like to have to re-SIC the modules but it is optionnal since when migrated, the module won't go back to its original GreenSmartCenter again).


What should I use to import objects and rulebase from GreenSC to RedSC efficiently ?

I tried cp_merge with object...5.C and DarkGreenPolicy.W files: all NAT configuration get screwed...

What else should I try: upgrade_export and then import ? But what about the certificates, the new IP address, the SIC... anything else for future ?


odumper/ofiler ? Not officially supported nor maintained since a long time ...


Any advice appreciated.
Cheers.
Reply With Quote
  #2 (permalink)  
Old 2007-11-13
Acidio Acidio is offline
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 2
Acidio has an average reputation (10+)
Default Re: Splitting a SmartCenter in two

Have done a similar thing. All I used was cp_merge and everything worked fine. Didn't have any problems.

It was a while ago when I did the migration, but from memory I think this was the procedure I used...

1) copy over objects_5_0.C file to new smart centre server
2) export the policy from the old smart centre server using cp_merge
3) export user accounts from old smart centre using dbexport
4) import objects into new smart centre using cp_merge
5) manually created user groups on new smart centre
6) imported users into new smart centre using dbimport
7) imported policy onto new smart centre using cp_merge
8) made appropriate adjustments to the policy as required
9) installed policy

everything was OK after doing this.

The only other preparation work I did was to ensure the policy didn't state which gateway the rules were to be installed on.


Hope this helps.
Reply With Quote
  #3 (permalink)  
Old 2007-11-14
docstephano docstephano is offline
Junior Member
 
Join Date: 2007-09-05
Posts: 7
Rep Power: 0
docstephano has an average reputation (10+)
Default Re: Splitting a SmartCenter in two

Thanks for your detailed answer Acidio,
what you described here looks very similar to what I did but without the same success.
Currently, the policy states for almost each rule on which firewall it applies but I'm almost sure the firewalls are known firewalls.

I'll try to redo it with your "preparation trick" first.

Thanks again for your answer.
Reply With Quote
  #4 (permalink)  
Old 2007-11-27
docstephano docstephano is offline
Junior Member
 
Join Date: 2007-09-05
Posts: 7
Rep Power: 0
docstephano has an average reputation (10+)
Default Re: Splitting a SmartCenter in two

Well,
cp_merge is not my friend...
upgrade_export/import + piece of CKPT doc dealing with migration of IP address of SmartCenter + regeneration of CA certificate +... and finaly get it working...
Lot of sweat...
Reply With Quote
  #5 (permalink)  
Old 2007-11-27
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Splitting a SmartCenter in two

You used the DarkGreen.W If you have exported the policy with cp_merge then you end up with a .pol file. The .W is not an exported file.

The release notes / user guide say use the .W file if you have too, but isn't recommended, you should export and use the exported DarkGreen.pol file and then import that .pol file instead.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:40.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0