CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-19
Junior Member
 
Join Date: 2007-02-19
Posts: 6
Rep Power: 0
MorfiusX has an average reputation (10+)
Default Moving SmartCenter

Here's some background:

I have a Nokia IP350 running NGX R61. All of the components are currently running on this machine. I have a second IP350. What we are trying to do is move the SmartCenter services to a central dedicated box, and have a single IP350 running as a gateway only.

I was able to use cp_merge to export the current policy, objects, and users into the new SmartCenter. When I imported the policy, a few pieces did not get imported. None of my VPN tunnel shared secrets imported. Also, neither did the global properties. So, I manually inserted the shared secrets.

When we attempted to switch over to the new IP350, about half of my site to site VPNs wouldn't route traffic. I saw a few IKE errors in the log, but for the most part, ping traffic was leaving the gateway via the tunnel, just not returning.

So, my question is this:

Is there a way or something I missed in importing shared secrets and the global properties? Is there a recommended approach for moving SmartCenter to a second machine?

TIA
Reply With Quote
  #2 (permalink)  
Old 2007-02-20
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 464
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Moving SmartCenter

run a simple upgrade_export and then upgrade_import if this is clean new smartcenter you are building up. Psk always follow with it. Use cp_merge (actually never used it personaly) if you are gonna add it to the already existing policy on the new smartcenter.
Reply With Quote
  #3 (permalink)  
Old 2007-02-21
Junior Member
 
Join Date: 2007-02-19
Posts: 6
Rep Power: 0
MorfiusX has an average reputation (10+)
Default Re: Moving SmartCenter

Maybe I am confused... By running the upgrade_export/import, I am making a backup of the whole system. When I imported this into the new standalone SmartCenter, it now looks like the old box. I don't want this. I am trying to get SmartCenter on one machine, and the Gateway on a separate machine.
Reply With Quote
  #4 (permalink)  
Old 2007-02-21
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Moving SmartCenter

Instructions are posted here:

http://www.cpug.org/check_point_reso...Deployment.htm
Reply With Quote
  #5 (permalink)  
Old 2007-02-21
Junior Member
 
Join Date: 2007-02-19
Posts: 6
Rep Power: 0
MorfiusX has an average reputation (10+)
Default Re: Moving SmartCenter

Thanks for the link. I will give it a shot.
Reply With Quote
  #6 (permalink)  
Old 2007-02-22
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 464
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Moving SmartCenter

Quote:
Originally Posted by MorfiusX View Post
Maybe I am confused... By running the upgrade_export/import, I am making a backup of the whole system. When I imported this into the new standalone SmartCenter, it now looks like the old box. I don't want this. I am trying to get SmartCenter on one machine, and the Gateway on a separate machine.
Yepp ur confused ;)
If u have standalone system today with fw/smartcenter on same machine u can still do upgrade_export and import it into your NEW distributed enviroment (smartcenter). You will get rules,objects,certs,psk's etc from the old smartcenter. Distributed vs standalone installation choice is something you make when you install software itself. Upgrade export/import is not aware of this setup.

Ofc when u open ur policy first time u will see only old fw/smartcenter object. You convert that object into your new smartcenter (so it matches ip wise etc) and create new Fw object for ur firewall module, establish sic etc etc
Reply With Quote
  #7 (permalink)  
Old 2007-02-22
Junior Member
 
Join Date: 2007-02-19
Posts: 6
Rep Power: 0
MorfiusX has an average reputation (10+)
Default Re: Moving SmartCenter

So I followed the guide posted above. Everything went as it stated. But, none of my site to site VPN tunnels will establish. All of them are using shared secrets. Any particular reason why this would happen? Everything works just fine.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0