CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-26
benny benny is offline
Junior Member
 
Join Date: 2006-07-26
Posts: 7
Rep Power: 0
benny has an average reputation (10+)
Default NG R55 migration

Hi Everyone

I am preparing to migrate my SmartCenter Management Station to a new hardware, IP Address and from win 2000 to 2003.

Could you look at the below step by step and let me know if there is anything i have missed. There are also a couple of questions in there.

.................................................. ..............................................
Migrating NG R55 SmartCenter to another hardware and IP address.

On current SmartCenter server

Add new SmartCenter Server to the firewall using the old smartcenter server

SmartDashboard

Manage > Network Objects > New… > Checkpoint… > gateway

Tick SVN foundation & Log Server & Secondary Management Station

Create a rule on the SmartCenter Server which allows Firewall-1 and CPD services from the above object to go to all gateways.

Does this include the following services:
CPD
CPD_Amon
FW1
And any other service that has FW1_* (As there are quite a few)


Push the rule to the managed gateways.

Run command

upgrade_export c:\Exportedconfig

copy exportedconfig.tgz to new SmartCenter Server

Run Setup on new SmartCenter Server
(Installing same components; SmartCenter Express & SmartConsole)

Run command

Upgrade_import c:\exportedconfig.tgz

reboot

Log into Checkpoint Web Site and generate the new certificates.

Import the new certificates. Where is the import utility for the new certificates.

Start and log in to the smartcenter console change the primary SmartCenter Object to the new IP Address.

Remove the secondary smartcenter management station created earlier.

Additional Queries…

Under… Policy > Global properties
Do I need to change the ‘Authenticate internal users with this suffix only:’

OU=users, O=SmartCenterSvr.domain.com.i3qdzi

Or does this get automatically changed.
Reply With Quote
  #2 (permalink)  
Old 2006-07-26
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,626
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: NG R55 migration

Unless you are changing the system name and you want the SIC to match, you can make this a lot easier.

SIC communications happen as part of "Rule 0" by default (in global properties) so unless you changed it there you don't have to worry about the rulebase so:

1. upgrade_export current SC and copy the file to a TFTP server
2. build your w2k3 box (Think about using SPLAT instead)
3. Run through the install, it will ask about doing an "advanced upgrade" chose that.
4. It should ask about upgrading your licenses as part of the advanced upgrade, let it (the SC will need internet access and your UC login)
5. connect to the SC with SmartDashboard and change the IP address of the SC object
6. push policy.

That should take care of you.
Reply With Quote
  #3 (permalink)  
Old 2006-07-27
benny benny is offline
Junior Member
 
Join Date: 2006-07-26
Posts: 7
Rep Power: 0
benny has an average reputation (10+)
Default Re: NG R55 migration

The new machine for smartConsole, will have a different name.
Reply With Quote
  #4 (permalink)  
Old 2006-07-28
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,626
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: NG R55 migration

Host name won't matter as long as you can deal with the old name in the object. If not it involves using dbedit and/or editing the objects_5_0.c file by hand. There is an SK on this but I can't find it right now.

Also search the board this was recently discussed (changing the name)
Reply With Quote
  #5 (permalink)  
Old 2006-07-31
benny benny is offline
Junior Member
 
Join Date: 2006-07-26
Posts: 7
Rep Power: 0
benny has an average reputation (10+)
Default Re: NG R55 migration

ok thanks. Just to check, HOw do i load the newly generated certificates into the new smartcenter svr?
Reply With Quote
  #6 (permalink)  
Old 2006-08-08
benny benny is offline
Junior Member
 
Join Date: 2006-07-26
Posts: 7
Rep Power: 0
benny has an average reputation (10+)
Default Re: NG R55 migration

I tried to run through the steps of adding the second Management Station but this was greyed out so i couldnt go any further.

Any Ideas?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:43.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0