CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-03
hi_there hi_there is offline
Junior Member
 
Join Date: 2006-08-03
Posts: 10
Rep Power: 0
hi_there has an average reputation (10+)
Default How to Migrate to another Management Server?

Hi

What are the steps required to change the management server? The new management server will be having a different IP Address from the exisiting.

The old/new management OS is W2K and using Nokia box with VRRP active.

Thanks
Reply With Quote
  #2 (permalink)  
Old 2006-08-04
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: How to Migrate to another Management Server?

Use the upgrade_export/upgrade_import tools. Read about them in the Upgrade Guide.

Even though you're not changing versions, it doesn't matter, the export/import tools seem to do the trick.
Reply With Quote
  #3 (permalink)  
Old 2006-08-07
hi_there hi_there is offline
Junior Member
 
Join Date: 2006-08-03
Posts: 10
Rep Power: 0
hi_there has an average reputation (10+)
Default Re: How to Migrate to another Management Server?

Quote:
Originally Posted by northlandboy
Use the upgrade_export/upgrade_import tools. Read about them in the Upgrade Guide.

Even though you're not changing versions, it doesn't matter, the export/import tools seem to do the trick.
Did use the tool for the importing of the database to the new server, change the management object IP address to reflect the new address by using dbedit.

Establish SIC with the secondary Nokia box than push the rules down.

BUT.... when the change the VRRP prority to high value to take over from primary it does not take over as master. Reason for doing one Nokia box at time is not to have any drop packets.

Is there a method to change to the another management server with different IP Address and without any downtime?

Thanks
Reply With Quote
  #4 (permalink)  
Old 2006-08-07
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 786
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: How to Migrate to another Management Server?

You should be able to do what you want. If you're re-establishing SIC, then state sync will probably be broken, and you might drop established connections when you switch VRRP priorities. If that's a major issue, you could always temporarily allow out of state connections.

But anyway, your process seems OK. When you raised the VRRP priorities of the secondary, what happened? Did the primary stay master, even with a lower priority? And did the secondary stay in backup? Look at the detailed VRRP view, which shows things like the effective priority, and who the firewall thinks the master is.

You may even want to check things on the wire with tcpdump, to look at the VRRP traffic.

You haven't mentioned what version of IPSO you're running, but if it's 3.7+, then IPSO monitors the firewall state, for VRRP. If certain things aren't right (fwd, cphad not running, sync not working, no policy), then the firewall won't go into VRRP master.

Check to see if sync is working or not - cphaprob state. It might not work, it's hard to say for certain. You may even need to do another cpstop;cpstart after pushing the policy out, to get things working happily, so that VRRP will think all is well, and let that node go master.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 12:38.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0