Upgrading a Standalone from R80.10 and lower with Migration
In a migration and upgrade scenario, you perform the procedure on the source Standalone and the different target Standalone.
|
Notes:
|
|
Important - Before you upgrade a Standalone:
|
Procedure:
-
Get the R80.40 Management Server Migration Tool
Step
Instructions
1
Download the R80.40 Management Server Migration Tool from the R80.40 Home Page SK (see Management Server Migration Tool and Upgrade Tools).
2
Transfer the R80.40 Management Server Migration Tool package to the current server to some directory (for example,
/var/log/path_to_migration_tool/
).Note - Make sure to transfer the file in the binary mode.
-
On the current Standalone, run the Pre-Upgrade Verifier and export the entire management database
Step
Instructions
1
Connect to the command line on the current Standalone.
2
Log in to the Expert mode.
3
Go to the directory, where you put the R80.40 Management Server Migration Tool package:
cd /var/log/path_to_migration_tool/
4
Extract the R80.40 Management Server Migration Tool package:
tar zxvf <Name of Management Server Migration Tool Package>.tgz
5
Important - This step applies only when you upgrade from R77.30 or lower.
Run the Pre-Upgrade Verifier (PUV).
-
Run this command and use the applicable syntax based on the instructions on the screen:
./pre_upgrade_verifier -h
-
Read the Pre-Upgrade Verifier output.
If it is necessary to fix errors:
-
Follow the instructions in the report.
-
In a Management High Availability environment, if you made changes, synchronize the Management Servers immediately after these changes.
-
Run the Pre-Upgrade Verifier again.
-
6
Export the management database:
yes | nohup ./migrate export [-l | -x] [-n] /<Full Path>/<Name of Exported File> &
Notes:
-
yes | nohup ... & are mandatory parts of the syntax.
-
For details, see the R80.40 CLI Reference Guide - Chapter Security Management Server Commands - Section migrate.
7
Important - This step applies only when you upgrade from R80, R77.30 or lower.
If SmartEvent Software Blade is enabled on this Standalone, then export the Events database.
See sk110173.
8
Calculate the MD5 for the exported database files:
md5sum /<Full Path>/<Name of Database File>.tgz
9
Transfer the exported databases from the current Standalone to an external storage:
/<Full Path>/<Name of Database File>.tgz
Note - Make sure to transfer the file in the binary mode.
-
-
Install a new R80.40 Standalone
Perform a clean install of the R80.40 Standalone on another computer.
Do not perform initial configuration in SmartConsole.
See Installing a Security Management Server.
Important - The IP address of the source and target Standalone must be the same. If it is necessary to have a different IP address on the R80.40 Standalone, you can change it only after the upgrade procedure. Note that you have to issue licenses for the new IP address.
-
On the R80.40 Standalone, import the databases
Important - Before you import the management database, we strongly recommend to install the latest General Availability Take of the R80.40 Jumbo Hotfix Accumulator. This makes sure the R80.40 server has the latest improvements for reported import issues.
Step
Instructions
1
Connect to the command line on the R80.40 Standalone.
2
Log in to the Expert mode.
3
Make sure a valid license is installed:
cplic print
If it is not already installed, then install a valid license now.
4
Transfer the exported databases from an external storage to the R80.40 Standalone, to some directory.
Note - Make sure to transfer the files in the binary mode.
5
Make sure the transferred files are not corrupted.
Calculate the MD5 for the transferred files and compare them to the MD5 that you calculated on the original Standalone:
md5sum /<Full Path>/<Name of Database File>.tgz
6
Go to the
$FWDIR/bin/upgrade_tools/
directory:cd $FWDIR/bin/upgrade_tools/
7
Import the management database:
yes | nohup ./migrate import [-l | -x] [-n] /<Full Path>/<Name of Exported File>.tgz &
Notes:
-
yes | nohup ... & are mandatory parts of the syntax.
-
For details, see the R80.40 CLI Reference Guide - Chapter Security Management Server Commands - Section migrate.
Notes:
-
If you upgrade from R80 (or higher) version, and the IP addresses of the source and target Standalone are different:
-
Issue licenses for the new IP address in your Check Point User Center account.
-
Install the new licenses on the R80.40 Standalone.
-
-
If you upgrade from R77.30 (or lower) version to R80.40, then the IP addresses of the source and target Standalone must be the same.
-
If it is necessary to have a different IP address on the R80.40 Standalone, you can change it only after the upgrade procedure. Note that you have to issue licenses for the new IP address.
-
8
Important - This step applies only when you upgrade from R80, R77.30 or lower.
If SmartEvent Software Blade is enabled on this Standalone, then import the Events database.
See sk110173.
9
Restart the Check Point services:
cpstop
cpstart
-
-
Upgrade the dedicated Log Servers and dedicated SmartEvent Servers
This step is part of the upgrade procedure of a Standalone server. If you upgrade a dedicated Log Server or SmartEvent Server, then skip this step.
If your Standalone manages dedicated Log Servers or SmartEvent Servers, you must upgrade these dedicated servers to the same version as the Standalone:
-
Install the management database
Step
Instructions
1
Connect with SmartConsole to the R80.40 Standalone.
2
In the top left corner, click . > Install database
3
Select all objects.
4
Click Install.
5
Click OK.
-
Install the Event Policy
Important - This step applies only if the SmartEvent Correlation Unit Software Blade is enabled on the R80.40 Standalone.
Step
Instructions
1
Connect with the SmartConsole to the R80.40 Standalone.
2
In the SmartConsole, from the left navigation panel, click Logs & Monitor.
3
At the top, click + to open a new tab.
4
In the bottom left corner, in the External Apps section, click SmartEvent Settings & Policy.
The Legacy SmartEvent client opens.
5
In the top left corner, click . > Actions > Install Event Policy
6
Confirm.
7
Wait for these messages to appear:
SmartEvent Policy Installer installation complete
SmartEvent Policy Installer installation succeeded
8
Click Close.
9
Close the Legacy SmartEvent client.
-
Install the Security Policy
Step
Instructions
1
Connect with SmartConsole to the R80.40 Standalone.
2
Click Install Policy.
3
Install the Access Control Policy on the Standalone object.
4
Install the Threat Prevention Policy on the Standalone object.
-
Test the functionality on the R80.40 Standalone
Step
Instructions
1
Connect with SmartConsole to the R80.40 Standalone.
2
Make sure the management database and configuration were upgraded correctly.
-
Disconnect the old Standalone from the network
Disconnect cables from the old Standalone.
-
Connect the new Standalone to the network
Connect cables to the new Standalone.