> Source: [sk174186](https://support.checkpoint.com/results/sk/sk174186)

# sk174186 - Multi-Domain Management Deployment on Google Cloud Platform

| Property | Value |
|----------|-------|
| Solution ID | sk174186 |
| Date Created | 2021-06-23 |
| Last Modified | 2026-03-29 |
| Technical Level | General |
| Products | Cloud Firewall, Multi-Domain Security Management Server |
| Versions | R81 (EOS), R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R81.20, R82 |
| Platform | GCP |

## Solution

**Check Point Recommended version for all deployments is [R82](https://support.checkpoint.com/results/sk/sk181127#Installation) with its Recommended [Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) Take.**   
**To maintain the highest quality and security of our management solutions, Check Point recommends installing the Recommended Jumbo Hotfix, especially after the initial deployment.**

<br />

You can now deploy a Multi-Domain Security Management environment, including all features and functionalities on Google Cloud Platform.  
You can read more on Multi-Domain Security Management here: <https://www.checkpoint.com/products/multi-domain-security-management/>  

### Minimum Instance Size Requirements

`c2-standard-16` or any similar instance with minimum 16 cores and 64 GB RAM (and up).  

### Installation

To deploy a Multi-Domain Management Server in Google Cloud Platform:  

1. Go to the Google Cloud Platform Marketplace and search for Check Point products.
2. Deploy "Check Point CloudGuard IaaS Firewall \& Threat Prevention / (BYOL)" VM.
3. After choosing resource allocation, select the Manual configuration.
4. A VM with a private \& public IP will be deployed.
5. Wait for the installation to finish and run the First Time Wizard with Multi-Domain configuration.
6. Follow the regular First Time Wizard configuration, choose the primary and secondary Multi-Domain Log Server and the Multi-Log Server, and make sure you are using the same NTP servers for High Availability.

To check the Security Management Server's readiness:  

1. Log in to the machine in Expert mode and run this command: `mdsstat`
2. When the Multi-Domain Management Server is ready, the output of the command shows that all processes are up.

**Note:** The Automatic Provisioning Service will be enabled only on the Primary Multi-Domain Server.  

### Upgrade of a High Availability environment (More than one Multi-Domain Server)

<br />

To upgrade your High Availability environment:   

**Note:** The step order (sequence) is very important.  

1. Export the databases from both Multi-Domain High Availability members.
2. Transfer the databases to an external location.
3. Backup the Secondary Multi-Domain Server.
4. Delete the Secondary Multi-Domain Server (**The machine itself**) .
5. Shut down the Primary Multi-Domain Server.
6. Deploy a new Secondary Multi-Domain Server (**you must make sure that the new machine receives the same IP address as the old Secondary Multi-Domain Server**. Currently, there is no way to pick an IP address in our template (this will be fixed). The first available IP address is assigned automatically. Consequently, you need to manually assign the IP address.
7. Add all the IP addresses of the Domain Management Servers to the new Secondary Multi-Domain Server in the Azure portal.
8. Deploy the new Primary Multi-Domain Server.
9. Delete all the IP addresses of the Domain Management Servers from the old Primary Multi-Domain Server, and add them to the new Primary Multi-Domain Server in the Azure portal.
10. Make sure that the First Time Wizard of the Primary Multi-Domain Server completed, and that it is ready.
11. Transfer the previously exported databases to the new Secondary and Primary MDS (from step #2).
12. Run `mds_import.sh \[path to tgz\] `on both Multi-Domain Server members.
13. On the Primary Multi-Domain Server you will be asked to change the IP address, choose "Yes".

### Limitations

|--------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **ID** | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| 1      | The user must ensure connectivity between all Check Point objects across the Multi-Domain Management environment. For example: * Multi-Domain Servers and Multi-Domain Log Servers * Domain Management Servers and Domain Log Servers * Security Gateways and more. Lack of connectivity between the different objects might result in functional issues and failures.                                                                                                                                |
| 2      | The IP addresses of the Multi-Domain Management Server must be static (not Dynamic IP addresses).                                                                                                                                                                                                                                                                                                                                                                                                     |
| 3      | Communication method with the Check Point objects: * For communication with the private IP address, all the above must be installed in the same VPC or or be connected over VPN, Google Cloud Interconnect, or VPC Peering etc. * For communication with Public/Elastic IP addresses, see [sk181701](https://support.checkpoint.com/results/sk/sk181701).                                                                                                                                             |
| 4      | For on-premises objects and Windows machines (for SmartConsole usage), it is up to the user to establish connectivity with the Multi-Domain environment that is deployed in Google Cloud Platform.                                                                                                                                                                                                                                                                                                    |
| 5      | Before creating a new Domain Server, you must add a new IP address: go to the Network interface object related to your MDS machine \> click **Edit** \> **Network Interface** \> **Show Alias IP ranges** , and add the IP address of the Domain Server that you are about to create (private, static). **Note -** You are adding the IP address to the existing interface of the Multi-Domain Management Server in the Google Cloud Marketplace Portal Under **Compute Engine** \> **VM Instances**. |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
