> Source: [sk154033](https://support.checkpoint.com/results/sk/sk154033)

# sk154033 - How to migrate R80.10, R80.40 or R81 StandAlone environment to a distributed environment R80.10, R80.40 or R81

| Property | Value |
|----------|-------|
| Solution ID | sk154033 |
| Date Created | 2019-06-06 |
| Last Modified | 2024-11-30 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R81 (EOS) |
| OS | Gaia |
| Platform | Smart-1, Open Server |

## Solution

**Important Note:**   

* This article applies only to specific versions R80.10, R80.40, and R81.
* For versions R81.10 and higher, follow [sk179444](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk179444).

The below procedure allows you to migrate a standalone management environment to a distributed environment by creating a new secondary management server that is installed as a security management server only and promote that management server to become the primary.

This procedure does not work for R80.20 and R80.30 versions, because the ISO and kernel versions are different between the standalone server (gateway ISO) and distributed secondary Management server (Management ISO with New Kernel), which will fail the synchronization.

In R80.40, the ISO is once again unified with Gaia 3.10 on both Security gateway and Management. Therefore, the procedure of migrating standalone Management environment to a distributed environment management environment will work in R80.40 and higher versions.

**Notes:**

* Make sure to perform a full backup of your Security Management Server configuration prior to performing this procedure.
* If the installation of Threat Prevention policy fails on the Security Gateways, this could be due to IPS version mismatch between the Management Server and the Security Gateways. To solve this, update IPS in SmartConsole to the latest version and install the Threat Prevention policy.

<!-- -->

**Procedure**:

1. Install a new Secondary Security Management Server with the same version, and the same Jumbo Hotfix (and ad-hoc hotfixes) as the Primary Security Management Server.
2. In SmartConsole, configure a Secondary Security Management Server object.  
   Following the instructions in the [Security Management Administration Guide](https://support.checkpoint.com/product/184#f-commonsource=C.%20Documentation) for your version \> Chapter "Configuring a Secondary Server in SmartConsole"
3. Make sure that the two Security Management Servers are synchronized.
4. Install a new Security Gateway with the same version, and the same Jumbo Hotfix (and ad-hoc hotfixes) as the old Standalone server.
5. Configure the new Security Gateway object in the same way as the Gateway part on the old Standalone server.
6. Configure Install the same security policy that is used on the Gateway part of the old Standalone server.  
   This allows the new Security Gateway to take over the responsibilities of the Gateway part of the old Standalone server.
7. Move all traffic that was handled by the Gateway part on the old Standalone server to the newly installed Security Gateway and verify that the traffic and VPN access are working as expected.
8. Install the security policy on all Security Gateways in the environment to make them aware of the new Secondary Security Management Server object.
9. Install the database on all servers in the environment to make them aware of the new Secondary Security Management Server object.
10. Disconnect and power off the old Primary Security Management Server that is currently acting as a Standalone server.
11. Promote the newly installed Secondary Security Management Server to become Primary.  
    Follow the instructions in the [Security Management Administration Guide](https://support.checkpoint.com/product/184#f-commonsource=C.%20Documentation) for your version \> Chapter "Promoting a Secondary Server to Primary".
12. Make sure you can successfully install the security policy on all Security Gateways in the environment.
    * **Note:** To be able to revert, we recommend to create a rule allowing the old Standalone server's IP address to communicate will all Security Gateways. This allows you a fallback method to push the policy from the old Standalone server to the security Gateways if anything would go wrong.
13. Make sure you can successfully install the database on all servers in the environment.
14. Make sure that traffic and VPN access is working as expected.
15. Make sure that all Security Gateways are sending logs to the new Primary Security Management Server and their configured Log Servers.

**If any of the steps fails in this procedure, you can easily revert:**

1. Disconnect the new Security Management Server.
2. Disconnect the new Security Gateway.
3. Reconnect and power on the old Standalone server.

[](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk179444)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
