| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I have a single SPLAT box running VPN1 and Smartcentre. I would like to move the Smartcentre installation to a seperate box and end up with a distributed installation. I've run the export but end up back where I started. Can anyone tell me the steps I should be following? |
| |||
| As you have already done the export. Install CP on the new management station appliance that you want to build and do an import. I believe it has to be the same IP addresses and hostname for the time being. Once you know that you have connectivity to the dashboard, reinstall Check Point on the enforcement module. If the enforcement module needs to keep the same IP addresses then you will have to change the IP address and hostname of the management station. I don't know of any prettier way to do this. Someone else may have another solution. |
| |||
| As you, I tryed to separate the management from the filtering module using upgrade_export tool. It was a dead end. If you restore files from this backup, the script restores the firewall the way it was. That is to say, a standalone installation with SmartCenter and firewall module on the same host. The best way I found was using cp_merge utility. Export objects and rules using this tool, install your SmartCenter from scratch, import policy and objects, check results by connecting to the SmarCenter. At this stage, I see 2 solutions. Or reinstall the module and create SIC properly from both points, or try to convert the standalone installation to module only by applying #sk26320. As noted in this SK, "WARNING: Check Point recommends reinstalling the products properly." |
| |||
| What the problem is? 1. Upgrade export to the new hardware 2. Reconfigure IPs 3. Change HostName 4. Add a trial license for new IP 5. Run SmartDashborad 6. Unselect unneeded FW component 7. Fresh install you enforcement (old FW). Choose distributed install 8. Add new object, initialize SIC Done. P.S. It is better to do a backup before (the best is to hide one of the SCSI mirror disks to the safe place while server not running) |
![]() |
| Thread Tools | |
| Display Modes | |
| |