Migrating an On-premises Security Management Server to Endpoint Security

With Endpoint Security, you can migrate from an on-premises Security Management Server to a Endpoint Security cloud tenant in the Check Point Portal.

Use Case

With Endpoint Security, you can migrate from an on-premises Security Management Server to a Endpoint Security cloud tenant in the Check Point Portal.

You are using the on-premises Security Management Server to manage Endpoint Security clients installed on the endpoints. You wish to use the Endpoint Security cloud service on the Check Point Portal for management.

Prerequisites for Migration

Before migrating an on-premises Endpoint Security Management Server to Endpoint Security (EPMaaS), verify that the major versions of the EPMaaS service and the on-premises Security Management Server are identical. Migration is supported only when the major versions match.

To find the Endpoint Security service version:

  1. Sign in to the Check Point Portal.

  2. Go to Service Management.

  3. Note the Endpoint Security service version.

To find the on-premises Security Management Server version:

  1. Connect to the Security Management Server using SSH.

  2. Run the following command.

    cpinfo -y all

  3. In the output, locate the Product Version (for example, R82.10, R82 and so on).

Note:
  • Migration of Security Management Server from an environment with High Availability and Secondary server to Endpoint Security is not supported. For assistance, contact Check Point Support.

  • During the migration, the Endpoint Security Administrator Portal is temporarily locked and unavailable for use.

Known Limitations

  • Endpoint Security Cloud/EPMaaS supports Endpoint Security Client E88.50 and later. Upgrade any older clients before migration.

  • Migration to Endpoint Security Cloud/EPMaaS is supported only from an R81.20 On-Premises Management Server. Servers running R82 or later cannot be migrated, and there are no plans to support R82 and later on EPMaaS. For these versions, migrate clients by using the Reconnect Tool generated from the target EPMaaS server.

  • The Legacy URL Filtering blade is not supported. Remove it from all Endpoint Security clients before migration. The new URL Filtering capability is part of the Anti-Bot blade and requires the Forensics, Anti-Bot, and Threat Emulation blades.

  • The Capsule Docs blade is not supported. Decrypt all Capsule Docs-encrypted documents and uninstall the blade before migration.

  • Endpoint Policy Servers are not supported. After migration, all Endpoint Security clients connect directly to the Endpoint Security Cloud/EPMaaS server.

  • File emulation through On-Premises Threat Emulation appliances is not supported. Change the policy to use cloud emulation. To request appliance support, open an RFE.

  • Anti-Malware updates are supported only from external (Internet) update servers.

  • High Availability/Secondary Management Servers are not supported. If High Availability is used, set the primary server to active, remove the secondary server object, and install the database through SmartConsole before exporting it (as described in the Infinity Portal instructions).

  • If network or gateway objects are assigned to other network/gateway objects and also to network/firewall policies, their deletion fails. Delete these objects before migration. If you cannot do this in production and only want to test migration, open a Service Request with Check Point Support.

  • If any third-party authentication (for example, RADIUS) is configured for SmartConsole or Gaia login, migration fails. Set all authentication methods to Check Point Password before migration. If you cannot do this in production and only want to test migration, open a Service Request with Check Point Support.

  • Network Authorized Preboot Bypass (formerly UOL / Unlock on LAN) is not supported on Cloud EPMaaS servers. This On-Premises feature relies on IPv4 and trust of the local network, which no longer applies when the server is accessible from anywhere.

  • During migration of a workgroup client, a machine copy is created in the server database. If FDE is installed and pre-boot is activated, associated pre-boot accounts may be deleted. One pre-boot account is always kept (order not specified) so the machine can be unlocked.

    To avoid issues:

    • Add FDE and pre-boot-protected computers to Active Directory before migration.

    • Temporarily disable FDE pre-boot during migration.

    • Ensure migrating workgroup computers have only one active pre-boot account.

Migrating to Endpoint Security

  1. Log in to Check Point Portal and access the Endpoint Security Administrator Portal.

  2. Go to Endpoint Settings > Migration Tool.

  3. Click Download.

    The system downloads the migration script.

  4. In the Endpoint Security Administrator Portal, copy the commands from the Migration Tool page Export Data.

  5. Transfer the downloaded migration script to a directory on the Security Management Server.

  6. On the Security Management Server, open the command line and run the commands you copied.

    The system generates encrypted_export.tgz file.

  7. Transfer the encrypted_export.tgz file to the local computer.

  8. In the Migration Tool page Import Data, click Browse and select the encrypted_export.tgz file.

  9. Click Upload & Start.

    Note:

    Check Point Portal supports the upload of files up to 5 GB. If the export file size exceeds 5 GB, contact Check Point Support.

    You will receive a confirmation mail when the import is complete.

  10. Continue with the post-migration steps. For more information, see sk179687.

  11. Run the Reconnect tool on all the endpoints to reconnect to the Endpoint Security on the Check Point Portal. For more information, see Reconnect Tool.