To change the status of a server:
The High Availability Status window opens.
The servers synchronize before a failover occurs to the new active server.
If the primary management server becomes permanently unavailable:
Note: This is not supported for environments with Endpoint Security.
IMPORTANT: Check Point product licenses are linked to IP addresses. At the end of the disaster recovery you must make sure that licenses are correctly assigned to your servers.
(Create the active server as an object in the new primary, establish SIC and synchronize the databases).
The original Secondary server returns to Standby.
The first management server installed is the Primary Server and all servers installed afterwards are Secondary servers. The Primary server acts as the synchronization master. When the Primary server is down, secondary servers cannot synchronize their databases until a Secondary is promoted to Primary and the initial syncs completes.
To promote a Secondary server to become the Primary server:
#$FWDIR/bin/promote_util
#cpstop
$FWDIR/conf/mgha*
files. They contain information about the current Secondary settings. These files will be recreated when you start the Check Point services.mgmtha
license on the newly promoted server.Note - All licenses must have the IP address of the promoted Security Management Server.
cpstart
on the promoted server.Note - When you remove the old Primary server, all previous licenses are revoked.