CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Management High Availability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-19
Testing-123 Testing-123 is offline
Member
 
Join Date: 2007-07-27
Posts: 86
Rep Power: 2
Testing-123 has an average reputation (10+)
Default Mgmt HA Hostname Change

Hello All,

I have a HA pair of R65 Check Point smart centres on Windows 2003. The active is called alpha-1 and the passive is called alpha-2. There is a requirement to rename them to alpha-active and alpha-standby respectively. No VPN's are defined in any of the policies and administrators access to smart dashboard is via Check Point passwords.

Has anyone done this in a HA environment? Any advice on how to go about it to minimise disruption to firewall admins/NOC who will be using tracker during the upgrade for BAU....

Regards
Testing-123
Reply With Quote
  #2 (permalink)  
Old 2008-03-19
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 130
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Mgmt HA Hostname Change

on the active

The first thing you need to do is make sure all of the firewall objects managed have the vpn option unchecked. This will revoke any certs issued.

Then you need to go to the command line and type in fwm sic_reset. This will destroy the ica. You can change the hostname at this point and reboot.


Once the box is up click on Start >Run and type cpconfig. You will see an option for the cert/ica. Just click OK to Create the ICA with the new hostname.


Reset sic on the backup mgmt via cpconfig and change the hostname on the box.


Login to the Active Smart Dashboard and delete and recreate the backup mgmt object with the new sic key and hostname


Click on Policy > HA and force a sync from the Primary to the backup.
Reply With Quote
  #3 (permalink)  
Old 2008-03-19
Testing-123 Testing-123 is offline
Member
 
Join Date: 2007-07-27
Posts: 86
Rep Power: 2
Testing-123 has an average reputation (10+)
Default Re: Mgmt HA Hostname Change

Hi Routerkid1,

Thank you for your reply. I'm comfortable with the process you've described as i built the HA pair using an exported config so i'm familiar with the possible issues i may encounter.

But as always, i use this forum as a santiy check and a knowledge base and have just realised i will have to resic the modules to the SC after the host name change as the ICA would have changed and i cannot remember the SIC key on the modules! But i'm running VRRP clusters so this should not be a major issue but something (important) that slipped my mind (*duhn*)

Thanks once again.

Regards
Testing-123
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:40.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0