Migrating Database Between R80.30 Security Management Servers
This procedure lets you export the entire management database from one R80.30 Security Management Server and import it on another R80.30 Security Management Server.
Workflow:
- Back up the current R80.30 Security Management Server
- On the current R80.30 Security Management Server, export the entire management database
- Install a new R80.30 Security Management Server
- On the new R80.30 Security Management Server, import the database
- Test the functionality
- Disconnect the old Security Management Server from the network
Step 1 of 7: Back up the current R80.30 Security Management Server
See Back up your current configuration.
Step 2 of 7: On the current R80.30 Security Management Server, export the entire management database
| Step | Description | 
| 1 | Connect to the command line on the current R80.30 Security Management Server. | 
| 2 | Log in to the Expert mode. | 
| 5 | Go to the directory:$FWDIR/bin/upgrade_tools/ [Expert@MGMT:0]# cd $FWDIR/bin/Management Server Migration Tool/
 | 
| 6 | Export the management database: If  blade is disabled on this Security Management Server and:This Security Management Server is connected to the Internet, run:Full Path[Expert@MGMT:0]# ./migrate_server export -v R80.30 [-l | -x] /<Name of Exported File>/<>.tgz
This Security Management Server is not connected to the Internet, run:Full Path[Expert@MGMT:0]# ./migrate_server export -v R80.30 -skip_upgrade_tools_check [-l | -x] /<Name of Exported File>/<>.tgz
If  blade is enabled on this Security Management Server and:This Security Management Server is connected to the Internet, run:Full Path[Expert@MGMT:0]# ./migrate_server export -v R80.30 [-l | -x] [--include-uepm-msi-files] /<Name of Exported File>/<>.tgz
This Security Management Server is not connected to the Internet, run:Full Path[Expert@MGMT:0]# ./migrate_server export -v R80.30 -skip_upgrade_tools_check [-l | -x] [--include-uepm-msi-files] /<Name of Exported File>/<>.tgz
 Syntax options: - Specifies the version, to which you plan to upgrade.-v R80.30- Does not try to connect to Check Point Cloud to check for a more recent version of the Management Server Migration Tool.-skip_upgrade_tools_check- Exports the Check Point logs without log indexes in the-ldirectory. Note - The command can export only closed logs (to which the information is not currently written).$FWDIR/log/- Exports the Check Point logs with their log indexes in the-xdirectory. Note - The command can export only closed logs (to which the information is not currently written).$FWDIR/log/- Backs up the MSI files from the Endpoint Security Management Server during the export operation.--include-uepm-msi-files
 | 
| 7 | This step applies only to R7x and R80 versions. If  Software Blade is enabled, then export the  database. See sk110173. | 
| 8 | Calculate the MD5 for the exported database files: Full Path[Expert@MGMT:0]# md5sum /<Name of Database File>/<>.tgz
 | 
| 9 | Transfer the exported databases from the current Security Management Server to an external storage: Full Path/<Name of Database File>/<>.tgz
 Note - Make sure to transfer the file in the binary mode. | 
Step 3 of 7: Install a new R80.30 Security Management Server
Important:
The IP addresses of the source and target R80.30 Security Management Servers must be the same. If you need to have a different IP address on the R80.30 Security Management Server, you can change it only after the upgrade procedure. Note that you have to issue licenses for the new IP address. For applicable procedures, see sk40993 and sk65451.
Step 4 of 7: On the new R80.30 Security Management Server, import the database
| Step | Description | 
| 1 | Connect to the command line on the R80.30 Security Management Server. | 
| 2 | Log in to the Expert mode. | 
| 3 | Make sure a valid license is installed: cplic print
 If it is not already installed, then install a valid license now. | 
| 4 | Transfer the exported databases from an external storage to the R80.30 Security Management Server, to some directory. Note - Make sure to transfer the files in the binary mode. | 
| 5 | Make sure the transferred files are not corrupted. Calculate the MD5 for the transferred files and compare them to the MD5 that you calculated on the original Security Management Server: Full Path[Expert@MGMT:0]# md5sum /<Name of Database File>/<>.tgz
 | 
| 6 | Go to the directory:$FWDIR/scripts/ [Expert@MGMT:0]# cd $FWDIR/scripts/
 | 
| 7 | Import the management database: If  blade is disabled on this Security Management Server and:This Security Management Server is connected to the Internet, run:Full Path[Expert@MGMT:0]# ./migrate_server import -v R80.30 [-l | -x] /<Name of Exported File>/<>.tgz
This Security Management Server is not connected to the Internet, run:Full Path[Expert@MGMT:0]# ./migrate_server import -v R80.30 -skip_upgrade_tools_check [-l | -x] /<Name of Exported File>/<>.tgz
If  blade is enabled on this Security Management Server and:This Security Management Server is connected to the Internet, run:Full Path[Expert@MGMT:0]# ./migrate_server import -v R80.30 [-l | -x] [--include-uepm-msi-files] /<Name of Exported File>/<>.tgz
This Security Management Server is not connected to the Internet, run:Full Path[Expert@MGMT:0]# ./migrate_server import -v R80.30 -skip_upgrade_tools_check [-l | -x] [--include-uepm-msi-files] /<Name of Exported File>/<>.tgz
 Note - The command automatically restarts Check Point services (performsmigrate_server importandcpstop).cpstart Syntax options: - Specifies the version, to which you plan to upgrade.-v R80.30- Does not try to connect to Check Point Cloud to check for a more recent version of the Upgrade Tools.-skip_upgrade_tools_check- Imports the Check Point logs without log indexes in the-ldirectory.$FWDIR/log/- Imports the Check Point logs with their log indexes in the-xdirectory.$FWDIR/log/- Restores the MSI files from the Endpoint Security Management Server during the import operation.--include-uepm-msi-files
 | 
Step 5 of 7: Test the functionality
| Step | Description | 
| 1 | Connect with SmartConsole to the new R80.30 Security Management Server. | 
| 2 | Make sure the management database and configuration were imported correctly. | 
Step 6 of 7: Disconnect the old Security Management Server from the network
Step 7 of 7: Connect the new Security Management Server to the network