sk180631 - How to clone a Domain on a Multi-Domain Security Management Server
How to clone a Domain on a Multi-Domain Security Management Server
Solution
Overview
It is possible to clone an existing Domain on the same Multi-Domain Security Management Server.
Requirements
| Version | Requirement |
| R82 and higher | The feature is integrated |
| R81.20 | Upgrade Tools build 997000670 or higher from sk135172. |
| R81.10 | Upgrade Tools build 996000503 or higher from sk135172. |
Important Notes
When you use the API v2 call "clone domain" (on R82 or higher versions), you can specify an optional parameter
omit-sensitive-infoto remove sensitive information from the management database on the new cloned Domain (such as internal passwords, shared secrets, and private keys).The cloning operation copies the entire management database (with all configured objects) of an existing Active Domain Server to the new Domain, except for the Internal CA database. On the new cloned Domain, the ICA database is "clean".
In the new Domain, all managed objects from the source Domain appear without an IP address and without SIC.
The cloning operation adds the suffix " _
" to each object it copies from the source Domain to the cloned Domain. After you clone a Domain, you must perform a full synchronization between all involved Multi-Domain Security Management Servers and Multi-Domain Log Servers in the environment.
Procedure
| Version | SmartConsole | Management API Calls |
| R82 and higher | 1. Connect with SmartConsole to the Multi-Domain Security Management Server. 2. Select the MDS context. 3. From the left navigation panel, click the Multi Domain view. 4. In the top middle section, click Domains. 5. In the left column Domains, right-click the existing Domain > in the menu, click Clone. 6. In the informational popup, click Continue. 7. Configure the new Domain, including the Trusted Clients. 8. Click OK. 9. The cloning progress appears in the bottom left corner of SmartConsole. |
Use this Management API call v2:mgmt_cli clone domain name "<Name-of-Existing-Domain-to-Clone>" new-domain-name "<Name-of-New-Domain>" new-domain-server-name "<Name-of-New-Domain-Server>" new-domain-server-ip "<IP-Address-of-New-Domain-Server>" --domain 'System Data' |
| R81.20 | Not Available | Use these Management API calls v1.9: 1. Export the database from an existing Domain: mgmt_cli export-management domain-name "<Name-of-Existing-Domain-to-Clone>" file-path "<File-Path>" --domain 'System Data'2. Import the database on a new Domain: mgmt_cli import-management file-path <File-Path> domain-name "<Name-of-New-Domain>" domain-ip-address "<IP-Address-of-New-Domain-Server>" domain-server-name "<Name-of-New-Domain-Server>" --domain 'System Data'3. Add trusted clients: mgmt_cli add trusted-client <parameters> |
| R81.10 | Not Available | Use these Management API calls v1.8 / v1.8.1: 1. Export the database from an existing Domain: mgmt_cli export-management domain-name "<Name-of-Existing-Domain-to-Clone>" file-path "<File-Path>" --domain 'System Data'2. Import the database on a new Domain: mgmt_cli import-management file-path <File-Path> domain-name "<Name-of-New-Domain>" domain-ip-address "<IP-Address-of-New-Domain-Server>" domain-server-name "<Name-of-New-Domain-Server>" --domain 'System Data'3. Add trusted clients: mgmt_cli add trusted-client <parameters> |
Known Limitations
- After cloning a Domain, in the new Domain all managed objects from the source Domain appear without an IP address and without SIC. As a result, when you connect with SmartConsole to the cloned Domain Management Server, the " Validations" panel shows this error about the cloned objects:
One of the following must be defined:
IP Address
IPv6 Address
On the cloned Domain, you must:
- Open the object.
- Enter the applicable IP address.
- In the applicable object (Security Gateway / Cluster Member / Check Point Host), establish the SIC Trust.
Note - In SmartConsole, the Check Point object does not show the green "V" icon until you restart the Domain with the commands "mdsstop_customer <IP Address of Domain> ; mdsstart_customer <IP Address of Domain>". This is only a cosmetic issue.
4. In the Security Gateway / Cluster objects:
1. Get interfaces.
2. Enable the applicable Software Blades.
3. Configure all other applicable settings.
5. Install the applicable policy.
- After cloning a Domain, you must manually add Administrators and Trusted Clients on the new cloned Domain Server to give them access to the new Domain Server.
- In a Management High Availability configuration, you can create and export a Domain for cloning only on a Multi-Domain Security Management Server, on which the Domain Management Server of the Domain is Primary and Active.
- In a Management High Availability configuration, you must perform the import of a cloning operation on the Multi-Domain Security Management Server, on which the Global Domain is Active. In case the cloned domain should have the Primary and Active Domain Management Server on another Multi-Domain Security Management Server, refer to sk184637.
- The cloning of a Domain is blocked if the Domain contains objects related to VSX.
- The Hit Count data is not cloned.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.