> Source: [sk156072](https://support.checkpoint.com/results/sk/sk156072)

# sk156072 - Domain Migration

| Property | Value |
|----------|-------|
| Solution ID | sk156072 |
| Date Created | 2019-06-20 |
| Last Modified | 2026-07-14 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Solution

**Table of Contents**

1. Migration of Domain Server between Multi-Domain Management Servers
   1. Migrating a Global Domain
   2. Exporting a non-Global Domain from a Multi-Domain Management Server
   3. Importing a non-Global Domain into a Multi-Domain Management Server
2. Backing up / Restoring a Domain
   1. Backing up a Domain
   2. Restoring a Domain
3. Domain migration between Security Management and Multi-Domain Management servers
   1. Before the migration
   2. Migrating from a Security Management Server to a Domain Management Server
   3. Migrating from a Domain Management Server to a Security Management Server
4. Known Limitations
5. Troubleshooting

**Support for Domain Migration between different versions (if you migrate to a higher version, then you must also perform an upgrade):**

* From versions R81.10, R81.20, and higher
* To versions R81.20 and higher

**Important Notes:**

* Before you export a database, you must:

  1. Update the Application Control signatures

  2. Update Anti-Virus, Anti-Bot, and IPS signatures

  3. Discard or publish all sessions
* **You must use the latest Upgrade Tools package in all types of Domain migrations from [sk135172](https://support.checkpoint.com/results/sk/sk135172).**

  The Domain migration feature is self-updatable. It allows faster release of features and fixes related to upgrade and migration.

  Security Management Servers / Multi-Domain Management Servers that have online access to `checkpoint.com`, will get the latest available Upgrade Tools automatically.
* In the syntax below, the parameter "`file-path`" requires a path to the management database file (relative or absolute).  
  Just for convenience, the syntax below always uses the directory "`/var/log/`".

### (1) Migration of Domain Server between Multi-Domain Management Servers {#1}

**(1-A) Migrating a Global Domain:**{#1-A}

You must migrate the Global Domain to the target Multi-Domain Management Server before you migrate a local Domain that is assigned to the Global Domain.

Local domain migration will be blocked in the import phase if the Global Domain version that the domain is assigned to is missing from the target server. Reassign the Global Domain to all Domains that should be exported before the export of the Global Domain and the local domains.

**Note:** When a Global Domain is migrated - the previous one is deleted. Thus, if there are domains assigned to the previous Global Domain - the migration will be blocked. A new Global Domain should not be migrated if the previous one is in use.

**(1-B) Exporting a Domain from a Multi-Domain Management Server:**{#1-B}

See the [Management API Reference](https://sc1.checkpoint.com/documents/latest/APIs/#api_versions) for your Management Server version. On the Management Server, run:

`mgmt_cli export-management [version "<TARGET_VERSION>"] domain-name "<NAME_of_DOMAIN>" file-path "/var/log/<NAME_of_DOMAIN>_exported.tgz" --domain 'System Data' --format json`  

**Note:** The parameter '`version`' is required if the versions of the source server and the target server are different.

**(1-C) Importing a Domain into a Multi-Domain Management Server:**{#1-C}

See the [Management API Reference](https://sc1.checkpoint.com/documents/latest/APIs/#api_versions) for your Management Server version. On the CLI of the Management Server, run:

`mgmt_cli import-management file-path "/var/log/<NAME_of_DOMAIN>_exported.tgz" --domain 'System Data' --format json`

Notes:

* After the Domain import, you must connect with SmartConsole to this Domain and install the Security Policy on each managed Security Gateway / Cluster / Virtual System / Virtual Router to receive logs from it.

* If the Domain contains Security Gateway / Clusters you managed with the Provisioning Software Blade:

  * You must install the Security Policy on each SmartLSM Security Profile.

  * If after the migration, the Domain's IP address differs from the IP address before the migration, then after you install the Security Policy on each SmartLSM Security Profile, you must connect to the command line on each managed device and manually fetch the Security Policy with this command:

    `fw fetch <IP Address of Domain After Migration>`

### (2) Backing up / Restoring a Domain {#2}

**(2-A) Backing up a Domain:**{#2-A}

See the [Management API Reference](https://sc1.checkpoint.com/documents/latest/APIs/#api_versions) for your Management Server version. On the CLI of the Management Server, run:

`mgmt_cli export-management domain-name "<NAME_of_DOMAIN>" file-path "/var/log/<NAME_of_DOMAIN>_backup.tgz" is-domain-backup true --domain 'System Data' --format json`

**(2-B) Restoring a Domain:**{#2-B}

See the [Management API Reference](https://sc1.checkpoint.com/documents/latest/APIs/#api_versions) for your Management Server version.

1. Verify the Domain database. On the CLI of the Management Server, run:

   `mgmt_cli import-management verify-domain-restore "true" file-path "/var/log/<NAME_of_DOMAIN>_backup.tgz" --domain 'System Data' --format json`
2. Restore the Domain:

   `mgmt_cli import-management file-path "/var/log/<NAME_of_DOMAIN>_backup.tgz" --domain 'System Data' --format json`
3. Restore the Standby Domain servers and Domain Log servers (they must be created with the same name and IP address):

   1. For each Standby Domain server, run:

      `mgmt_cli set-domain name "<NAME_of_DOMAIN> or <UID_of_DOMAIN>" servers.add.ip-address "<IP Address of Domain Server>" servers.add.name "<Name of Domain Server>" servers.add.multi-domain-server "<Name of Multi-Domain Server>" servers.add.backup-file-path "<Full Path>" --format json`
   2. For each Log Server, run:

      `mgmt_cli set-domain name "<NAME_of_DOMAIN> or <UID_of_DOMAIN>" servers.add.ip-address "<IP Address of Domain Server>" servers.add.name "<Name of Domain Server>" servers.add.multi-domain-server :<Name of Multi-Domain Server>" servers.add.backup-file-path "<Full Path>" --format json servers.add.type "log server"`
   3. If there is a Management High Availability between the Domain and a dedicated Security Management Server:

      1. Re-install the Security Management Server.

      2. Reset SIC with the Security Management Server from the Active Domain server.

4. Add GUI clients and administrators to the Domain.

5. Install the Security Policy on each managed Security Gateway / Cluster / Virtual System / Virtual Router, to receive all logs from it.

### (3) Domain migration between a Security Management Server and Multi-Domain Management servers {#3}

#### (3-A) Before the migration: {#3-A}

1. On the target server, make sure the free disk space in the **/var/log/** partition is at least 5 times the size of the exported database file.

2. Make sure to publish changes you wish to migrate, only published changes are exported.

#### (3-B) Migrating from a Security Management Server to a Domain Management Server {#3-B}

**(3-B-a) Export a Security Management Server:**

1. Make sure all processes are up and running, with the "`cpwd_admin list`" command.

2. Run the "`fw logswitch`" command to close the active log files. Only closed logs are migrated.

3. If the target server has a different IP address than the source server, you must prepare the source database before the export:

   * Create a new host object in SmartConsole with the IP address of the target Security Management Server.

   * Define an Access Policy rule to each installed policy, that lets the new host connect to Security Gateways:

     |------------|-------------|-----------------------------------------------------|
     | Source     | Destination | Service                                             |
     | New Server | Any         | FW1 (TCP 256) CPD (TCP 18191) FW1_CPRID (TCP 18208) |

   * For VSX, add a rule to VSX policy as well (see [sk167639](https://support.checkpoint.com/results/sk/sk167639) for specific instructions for migration with VSX).

   * Install the edited Security Policy on all Security Gateways and Clusters.

4. Log in with the API command to the "System Data" level and export the database:

   `mgmt_cli export-management [version "<TARGET_VERSION>"] file-path "/var/log/Mgmt_exported.tgz" is-smc-to-mds true --domain 'System Data' --format json`  

   **Note:** The parameter '`version`' is required if the versions of the source server and the target server are different.

**(3-B-b) Import into a Multi-Domain Management Server:**

1. Install the Multi-Domain Management Server on the target server.

   Note: For an existing Multi-Domain Management Server, create backup prior to importing a new Domain Management Server.
2. Copy the management database file that you exported from the source server to a directory of your choice on the target server. Use FTP, SCP or similar.

3. Log in via API command to the "System Data" level and import the database (for R80.20 Jumbo Hotfix Accumulator and R80.30 Jumbo Hotfix Accumulator, add the option "`exported-from-mds false`"). See the examples below.

   The command will create a new Domain and new Domain Management Server, and import the source database.

   **There is no need to create the Domain before the migration.**

   **Note:** Make sure the Domain name you wish to create does not conflict with the existing Domains.

   On the CLI of the Management Server, run:

   `mgmt_cli import-management domain-name "<NAME_of_DOMAIN>" domain-server-name "<NAME_of_DOMAIN_SERVER>" domain-ip-address "<IP_Address_of_DOMAIN>" file-path "/var/log/Mgmt_exported.tgz" --domain 'System Data' --format json`
4. Test the target deployment.

5. Disconnect the source server from the network.

6. Add GUI Clients.

7. With the GuiDBedit Tool, edit the value of the parameter **hosted_by** to see logs - see [sk123593](https://support.checkpoint.com/results/sk/sk123593).

8. Install the Security policy on all Security Gateways and Clusters.  
   For LSM environment, install the Security policy on all the LSM Security Profiles.

9. If after the migration, the Domain's IP address differs from the IP address before the migration, and the Domain contains LSM Gateways / Clusters, run this command one time on each of the LSM devices:

   `fw fetch <IP Address of Domain After Migration>`
10. If the target server has a different IP address than the source server - Delete the special Access Control rule you added before the migration:

    1. Connect with SmartConsole to the target Domain Management Server.

    2. In each Security Policy, delete the Access Control rule with the new Host object you added on the source Security Management Server before migration.

    3. Delete the Host object you added on the source Security Management Server before migration.

    4. Install the applicable policies on all managed Security Gateways and Clusters.

#### (3-C) Migrating from a Domain Management Server to a Security Management Server {#3-C}

**(3-C-a) Export a Domain Management Server:**

1. Make sure all processes are up and running, with the "`mdsstat -m`" command.

2. Run the "`fw logswitch`" command to close the active log files. Only closed logs are migrated.

   Note: Log switch should be executed for the Domain context by running the command "`mdsenv <IP Address or Name of Domain Server>`
3. If the target server has a different IP address than the source server, you must prepare the source database before the export.

   **Do NOT change the hostname in the import.**
   * Create a new host object in SmartConsole with the IP address of the target Security Management Server.

   * Define an Access Policy rule to each installed policy, that lets the new host connect to Security Gateways.

     |------------|-------------|-----------------------------------------------------|
     | Source     | Destination | Service                                             |
     | New Server | Any         | FW1 (TCP 256) CPD (TCP 18191) FW1_CPRID (TCP 18208) |

   * For VSX, add a rule to VSX policy as well (see [sk167639](https://support.checkpoint.com/results/sk/sk167639) for specific instructions for migration with VSX).

   * Install the edited Security policy on all Security Gateways and Clusters.

4. Log in with the API command to the "System Data" level and export the database.

   See the [Management API Reference](https://sc1.checkpoint.com/documents/latest/APIs/#api_versions) for your Management Server version.
   * On R81.10 and higher, run:

     `mgmt_cli export-management [version "<TARGET_VERSION."] domain-name "<NAME_of_DOMAIN>" file-path "/var/log/<NAME_of_DOMAIN>_exported.tgz" --domain 'System Data' --format json`  

     **Note:** The parameter 'version' is required if the versions of the source server and the target server are different.
   * On R81 and lower, run:

     `mgmt_cli -d "System Data" migrate-export-domain domain "<NAME_of_DOMAIN>" file-path "/var/log/<NAME_of_DOMAIN>_exported.tgz" include-logs {true | false}`

**(3-C-b) Import into a Security Management Server:**

1. Install the Security Management Server on the target server. If you change the IP address, make sure to use the same hostname and add license for Security Management Server.

2. Copy the management database file that you exported from the source server to a directory of your choice on the target server. Use FTP, or SCP.

3. Import the database:

   See the [CLI Reference Guide](https://support.checkpoint.com/product/184#f-commonsource=C.%20Documentation) for your Management Server version.
   * On R81 and higher, run:

     `$MDS_FWDIR/scripts/migrate_server migrate_import_domain [-l | -x] /<Full Path>/<Name of Exported File>.tgz`
   * On R80.40 and lower, run:

     `$MDS_FWDIR/scripts/migrate_import_domain.sh -sn <Server Name> -dsi <Server IP Address> -o <Path to Export File>`
4. Test the target deployment.

5. Disconnect the source server from the network.

6. Add a SmartConsole Administrator with the "`cpconfig`" command.

7. Add GUI Client with the "`cpconfig`" command.

8. Install the Security policy on all Security Gateways and Clusters.  
   For LSM environment, install the Security policy on all of the LSM Security Profiles.

9. If the Security Management Server IP after migration differs from the exported Domain IP and it contains LSM gateways/clusters, run the following command once on each of the LSM devices:

   `fw fetch <IP Address of Management Server>`
10. If the target server has a different IP address than the source server- Delete the special Access Control rule you added before migration:

    1. Connect with SmartConsole to the target Security Management Server.

    2. In each Security Policy, delete the Access Control rule with the new Host object you added on the source Domain Management Server before migration.

    3. Delete the Host object you added on the source Domain Management Server before migration.

    4. Install the applicable policies on all managed Security Gateways and Clusters.

### (4) Known Limitations {#4}

**(4-A) Limitations for:**

* **Migration of Domain from one server to another**

* **Migration of Domain Server between Multi-Domain Management servers**

* **Domain Backup/Restore**

|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                                                                                                                                                                             |
| Backup/Restore of a Domain Server is supported only on the same Multi-Domain Security Management Server.                                                                                                                                                                                                |
| Migrating a Domain is possible only when the source and the destination have the same major version with the same base image take (ISO) installed.                                                                                                                                                      |
| Backup/Restore of a Domain is supported only with Management API calls (CLI and REST).                                                                                                                                                                                                                  |
| To clone a Domain, see [sk180631](https://support.checkpoint.com/results/sk/sk180631).                                                                                                                                                                                                                  |
| Restoring a Domain with Global Policy is supported only if the assigned Global Domain Revision (while taking the Domain Management Server backup) was not purged.                                                                                                                                       |
| You can take and restore multiple Domain backups at different times. But only the latest changes while taking the backup are restored. Older Revisions are not available.                                                                                                                               |
| After restoring a Domain Server, you must manually add Trusted Clients (administrators and GUI Clients) to give them access to the restored Domain Server.                                                                                                                                              |
| Hit Count data is not migrated.                                                                                                                                                                                                                                                                         |
| Migrating more than one Domain at a time is not supported.                                                                                                                                                                                                                                              |
| In a Management High Availability configuration, you must restore all the servers, Standby Domain Servers and Log Servers, before working on the restored Domain.                                                                                                                                       |
| The time it takes to migrate a Domain depends on the size of the Domain. It can take up to one hour. Migrating a very large Domain may take more time.                                                                                                                                                  |
| You can take a backup of a Domain only on the Multi-Domain Management where the Domain is Primary and Active.                                                                                                                                                                                           |
| A backup of a Domain is blocked if the domain contains objects related to VSX. Refer to [sk167639](https://support.checkpoint.com/results/sk/sk167639) for instructions.                                                                                                                                |
| Migration of the Global Domain is supported only if the Multi-Domain Security Management Server is **not** configured for Management High Availability.                                                                                                                                                 |
| Migration of the Global Domain is blocked in the import phase if there are Domains assigned to the Global Domain on the target server.                                                                                                                                                                  |
| Migration of a Local Domain is blocked in the import phase if the Global Domain version that is assigned to the Domain is missing from the target server. In such case, reassign the Global Domain to all Domains that should be exported before the export of the Global Domain and the local Domains. |
| R80.30 and lower: Migrating or restoring the same Domain with a new IP address on the same Multi-Domain Security Management Server is not supported.                                                                                                                                                    |
| Migration from a Security Management Server to a Security Management Server is not supported.                                                                                                                                                                                                           |
| While a Domain backup is running, the "Logs \& Monitor" view in SmartConsole might show "*Problems have occurred during search*".                                                                                                                                                                       |
| While a Domain backup is running, the "Sessions" view in SmartConsole might show "*Error retrieving results*".                                                                                                                                                                                          |

<br />

**(4-B) Limitations for a Domain migration between Security Management and Multi-Domain Management servers**

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Description                                                                                                                                                                                                                                           |
| Migration of the **same** Security Management Server **twice**into an Multi-Domain Security Management Server (or to two different Multi-Domain Security Management Servers in the same Management High Availability environment) is not supported.   |
| Migration of two different Security Management Servers into two **different Multi-Domain Security Management Servers** in a Management High Availability environment is not supported.                                                                |
| After migrating a Domain Server, you must manually add Trusted Clients (administrators and GUI Clients) to give them access to the new Domain Server.                                                                                                 |
| Hit Count data is not migrated.                                                                                                                                                                                                                       |
| Migrating more than one Domain at a time is not supported.                                                                                                                                                                                            |
| In a Management High Availability configuration, you can export and migrate only the Active Domain Management Server                                                                                                                                  |
| When migrating a Domain from a Multi-Domain Security Management Server to a Security Management Server (or vice versa), the Standby Domain Servers / Log Servers are not migrated. You must remove all references to these objects the Domain export. |
| The time it takes to migrate a Domain depends on the size of the Domain. It can take up to one hour. Migrating a very large Domain may take more time.                                                                                                |
| Domain migration is blocked if the Domain contains objects related to VSX. Refer to [sk167639](https://support.checkpoint.com/results/sk/sk167639) for instructions.                                                                                  |
| Migrating a Domain is possible only when the source and the destination has the same major version installed (can be with any Take of that major version).                                                                                            |
| Migration of a Domain from a Multi-Domain Security Management Server to a Security Management is not supported if the Domain is assigned to the Global Domain.                                                                                        |
| Exporting the database from a Security Management Server with the enabled "Endpoint Policy Management" Software Blade is not supported.                                                                                                               |
| You can export a Domain on the Multi-Domain Security Management Server only when the Domain is Primary and Active.                                                                                                                                    |
| R80.30 and lower: Renaming a Domain Server or changing a Domain Server's IP address during migration is not supported.                                                                                                                                |

### (5) Troubleshooting {#5}

|---------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Error**                                                                       | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| `Failed to import: Failed: Failed to get active machine for domain`             | The export files do not match the import command. Verify that you use the correct export file and the correct command (import / migrate_import_domain). Correct usages of the command: * Migrate of a Domain Management Server to a Security Management Server, in the SMC use: `migrate_server migrate-import-domain` * Migrate from a Multi-Domain Management Server to a Multi-Domain Management Server, on the target Multi-Domain Management Server use: `migrate_server import` * Migrate from a Security Management Server to a Security Management Server, on the target Security Management Server use: `migrate_server import` |
| `Failed: null` (during the import phase)                                        | Make sure the file we use for the import operation is the correct file, and that it was taken from a server running the same version                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| `Failed to import domain: Failed: Failed to find backup domain meta data file.` | Migration from a Security Management Server (SMS) to a Security Management Server (SMS) is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
