sk180631 - How to clone a Domain on a Multi-Domain Security Management Server

How to clone a Domain on a Multi-Domain Security Management Server

Solution

Overview

It is possible to clone an existing Domain on the same Multi-Domain Security Management Server.

Requirements

Version Requirement
R82 and higher The feature is integrated
R81.20 Upgrade Tools build 997000670 or higher from sk135172.
R81.10 Upgrade Tools build 996000503 or higher from sk135172.

Important Notes

In the new Domain, all managed objects from the source Domain appear without an IP address and without SIC.

Procedure

Version SmartConsole Management API Calls
R82 and higher 1. Connect with SmartConsole to the Multi-Domain Security Management Server.
2. Select the MDS context.
3. From the left navigation panel, click the Multi Domain view.
4. In the top middle section, click Domains.
5. In the left column Domains, right-click the existing Domain > in the menu, click Clone.
6. In the informational popup, click Continue.
7. Configure the new Domain, including the Trusted Clients.
8. Click OK.
9. The cloning progress appears in the bottom left corner of SmartConsole.
Use this Management API call v2:
mgmt_cli clone domain name "<Name-of-Existing-Domain-to-Clone>" new-domain-name "<Name-of-New-Domain>" new-domain-server-name "<Name-of-New-Domain-Server>" new-domain-server-ip "<IP-Address-of-New-Domain-Server>" --domain 'System Data'
R81.20 Not Available Use these Management API calls v1.9:
1. Export the database from an existing Domain:

mgmt_cli export-management domain-name "<Name-of-Existing-Domain-to-Clone>" file-path "<File-Path>" --domain 'System Data'
2. Import the database on a new Domain:

mgmt_cli import-management file-path <File-Path> domain-name "<Name-of-New-Domain>" domain-ip-address "<IP-Address-of-New-Domain-Server>" domain-server-name "<Name-of-New-Domain-Server>" --domain 'System Data'
3. Add trusted clients:

mgmt_cli add trusted-client <parameters>
R81.10 Not Available Use these Management API calls v1.8 / v1.8.1:
1. Export the database from an existing Domain:

mgmt_cli export-management domain-name "<Name-of-Existing-Domain-to-Clone>" file-path "<File-Path>" --domain 'System Data'
2. Import the database on a new Domain:

mgmt_cli import-management file-path <File-Path> domain-name "<Name-of-New-Domain>" domain-ip-address "<IP-Address-of-New-Domain-Server>" domain-server-name "<Name-of-New-Domain-Server>" --domain 'System Data'
3. Add trusted clients:

mgmt_cli add trusted-client <parameters>

Known Limitations

One of the following must be defined:
IP Address
IPv6 Address

On the cloned Domain, you must:

  1. Open the object.
  2. Enter the applicable IP address.
  3. In the applicable object (Security Gateway / Cluster Member / Check Point Host), establish the SIC Trust.

Note - In SmartConsole, the Check Point object does not show the green "V" icon until you restart the Domain with the commands "mdsstop_customer <IP Address of Domain> ; mdsstart_customer <IP Address of Domain>". This is only a cosmetic issue. 4. In the Security Gateway / Cluster objects: 1. Get interfaces. 2. Enable the applicable Software Blades. 3. Configure all other applicable settings. 5. Install the applicable policy.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.