> Source: [sk163372](https://support.checkpoint.com/results/sk/sk163372)

# sk163372 - How to consolidate Endpoint Management into an existing Security Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk163372 |
| Date Created | 2019-11-03 |
| Last Modified | 2020-06-30 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |

## Solution

This article describes how to convert a customer environment that has one management server dedicated to manage only Endpoints and one management server dedicated to manage only Gateways, to one management server that manages both.

**In this management consolidation process the target unified management server is the one that is used to manage the Security Gateways.**

**Customers who are interested in converting their environments as described above may [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/).**

Include the following information:

* Check Point Management versions in use
* Endpoint Security components in use
* Number of Endpoint Security Clients deployed
* Details on policy servers and secondary management server, if used
* Details on the hardware used in each management server

**Important notes:**

* Both management servers must be aligned to the same management server version. **The minimum supported version is R80.20**
* Cpinfo and full DB export is required by Check Point for simulation purposes.
* Security Management Server hardware might require an upgrade to fit sizing requirements of the consolidated environment.
* The Endpoint Management data will be moved using a dedicated consolidation export/import tool.
* Policy Servers and secondary server will be connected manually to the new environment, as part of the process.
* Endpoint Security Clients should be reconnected to the new management by running the *reconnect utility.*

Alternative of manual consolidation procedure
---------------------------------------------

Endpoint Management environments that involve a deployment with low complexity may consider environment consolidation by reconfiguring the Endpoint policy of the Security Management server, and reconnecting the Endpoint Security Clients.

**Notes and limitations:**

1. This procedure cannot be used if the MEPP or Capsule Docs blades are in use.
2. This procedure cannot be used if the FDE blade is in use with one of the following features - SmartCard preboot authentication, WebRH Token authentication, Offline Groups, Self Help Portal.
3. **Make sure you know the client uninstall password.** If you don't know it - configure it in the policy and make sure all clients receive the new policy.
4. Limitation for workgroup users/devices - as part of the below procedure the client reconnects to the new server. **Workgroup entities are being re-created in the new system as new entities, so policy assignments for such entities must be re-configured.**

**Phase 0: Backup**

Take a snapshot of the target server.

**Phase 1: Users and Computers**

1. On the target server, configure directory scanner the same way it is configured on the source server (SmartEndpoint \> Deployment \> Organization Scanners).
2. On the target server, create the virtual groups that are used in the policies on the source server.
   1. Find the current Virtual Groups on the source server - SmartEndpint \> Users and Computes \> Entire Organization \> Virtual Groups.
   2. Create the same groups on the target server.
   3. Populate the virtual groups - you may do it manually for smaller groups. For larger groups, you may use the option to export the group's members to Excel (right-click on the virtual group), and then use the *epmCommands* tool on the target server that allows populating virtual groups from a file.

**Phase 2: Upload client packages**

On the target server, upload client MSI packages that are used in the policies on the source server: In SmartEndpoint \> Deployment, check the client versions that are in use in the organization. Get the same versions from Support Center and upload them to the target server.

**Phase 3: Configure policies**

1. On the target server, configure the blades policy and software deployment policy. Re-configure all the actions that are on the source server and assign them to the same entities.
2. **Pay special attention to configure the same uninstall password on the target server and the same deployment policy including the blades that are installed.**
3. If FDE is used, also make sure to:
   1. Enable in the policy, in all rules, the option "Continue to acquire users after pre-boot has been enforced"
   2. Create a local user in SmartEndpoint under the "Users and Computers" tab, and assign it as preboot user for the entire organization (this is a precaution in case PB users are lost during the transition)

**Phase 4: Test one client**

Connect one **new**test device to the new server and verify that is it working correctly and gets correct policies.

**Phase 5: Connect policy servers (if used)**

1. On the target server, create the policy servers objects and establish SIC with the existing policy servers (use the same IPs, as they are already known by the clients).
2. Check in SmartEndpoint Reporting that they are communicating with the target management.

**Phase 6: Reconnect one client**

1. Generate a reconnect tool from the SmartConsole of the target server by running the command \<*Path to SmartConsole\>\\PROGRAM\\data\\RepWorkFolder\\INVOKE\\maketool.bat \<path to new config.dat\> \<client uninstall password\>* (get *config.dat* file from *$FWDIR/conf/SMC-Files/uepm/DA/config.dat* on the target server. **It is created after exporting a client package**)
2. Run the tool on an existing client:
   1. Make sure it gets correct policies from the new server.
   2. If FDE is used, make sure that the user is able to login with preboot and that remote help (one time logon) works.

**Phase 7: Reconnect the rest of the clients**

Using 3rd party tools, run reconnect tool on the other clients. You should see all clients connecting to the new server.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
