Migrating a Domain Management Server between R82 Multi-Domain Servers
This procedure lets you export the entire management database from a Domain Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. on one R82 Multi-Domain Server
Dedicated Check Point server that runs Check Point software to host virtual Security Management Servers called Domain Management Servers. Synonym: Multi-Domain Security Management Server. Acronym: MDS. and import it on another R82 Multi-Domain Server.
For the list of known limitations, see sk156072.
Procedure:
-
On the source Multi-Domain Server, export the Domain Management Server
-
Run this API:
export-managementFor API documentation, see the Check Point Management API Reference - search for
export-management. -
Calculate the MD5 of the export file:
md5sum <Full Path to Export File>
-
-
Transfer the export file to the target Multi-Domain Server
-
Transfer the export file from the source Multi-Domain Server to the target Multi-Domain Server, to some directory.
Note - Make sure to transfer the file in the binary mode.
-
Make sure the transferred file is not corrupted.
Calculate the MD5 for the transferred file and compare it to the MD5 that you calculated on the source Multi-Domain Server:
md5sum <Full Path to Export File>
-
-
On the target Multi-Domain Server, import the Domain Management Server
-
Run this API:
import-managementFor API documentation, see the Check Point Management API Reference - search for
import-management. -
Make sure that all the required daemons (FWM, FWD, CPD, and CPCA) are in the state "
up" and show their PID (the "pnd" state is also acceptable):mdsstatIf some of the required daemons on a Domain Management Server
Virtual Security Management Server that manages Security Gateways for one Domain, as part of a Multi-Domain Security Management environment. Acronym: DMS. are in the state "down", then wait for 5-10 minutes, restart that Domain Management Server and check again. Run these three commands:mdsstop_customer <IP Address or Name of Domain Management Server>mdsstart_customer <IP Address or Name of Domain Management Server>mdsstat
-
-
Configure and assign the Administrators and GUI clients
You must again configure the Multi-Domain Server Administrators and GUI clients and assign them to the Domains.
-
Configure the Multi-Domain Server Administrators and GUI clients:
-
Run the
mdsconfigcommand -
Configure the Administrators
-
Configure the GUI clients
-
Exit the
mdsconfigmenu
-
-
Assign the Administrators and GUI clients to the Domains:
See Migrating a Domain Management Server between R82 Multi-Domain Servers and Migrating a Domain Management Server between R82 Multi-Domain Servers.
-
-
Install policy on all managed Security Gateways and Clusters
-
Connect with SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. to the Active Domain (to which this Domain Management Server belongs). -
Install the applicable policies on all managed Security Gateways and Clusters.
-