<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recommended patching process for private cloud images in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202502#M4529</link>
    <description>&lt;P&gt;Is the expectation then, that those of us doing Private Cloud infrastructure (VMWare or KVM) would have to figure out our own mechanism for keeping images current?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For private cloud deployments I just can see that as feasible.&lt;/P&gt;&lt;P&gt;As things are now,&amp;nbsp; private cloud using KVM would require a base image deployment followed immediately by an HFA installation taking the time to deliver a new cluster from less than 1 minutes to 10-20 minutes, with the added bagging of the disk bloat from the upgrade process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something or is private cloud automation/deployment that much behind the public cloud provider process?&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2024 18:38:38 GMT</pubDate>
    <dc:creator>AlJo</dc:creator>
    <dc:date>2024-01-08T18:38:38Z</dc:date>
    <item>
      <title>Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202395#M4520</link>
      <description>&lt;P&gt;Just started working with the KVM images for Check Point R81.20 gateway.&lt;/P&gt;&lt;P&gt;After chasing things down a bit and figuring out that R81.20 completely changed the cloud-init process I have a gateway up and running under KVM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used the latest KVM qcow2 image but being a good Check Point admin, I need the image to the latest HFA.&lt;/P&gt;&lt;P&gt;Is there a best practice/process for deploying images at the latest HFA?&amp;nbsp; The base qcow image deploys at about 5 gig, but after running cpuse to install the latest HFA, the image checks in at over 13G of committed disk consumption.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This isn't very cloud friendly and quite cumbersome.&amp;nbsp; Following this model up deploy, then patch,&amp;nbsp; it slows deployments considerably.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something?&amp;nbsp; Is there a better way to have a vetted patched version for direct deployment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jan 2024 18:24:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202395#M4520</guid>
      <dc:creator>AlJo</dc:creator>
      <dc:date>2024-01-06T18:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202416#M4521</link>
      <description>&lt;P&gt;I will ask one of my colleagues that did this, 13 GB does not sound logical to me at all.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 03:25:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202416#M4521</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T03:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202468#M4525</link>
      <description>&lt;P&gt;As far as I can remember, we will release updated images that include the recommended JHF.&lt;BR /&gt;We do not do this for every JHF, of course.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 13:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202468#M4525</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-08T13:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202488#M4527</link>
      <description>&lt;P&gt;Why wouldn't this be done for each HFA release?&amp;nbsp; As the steward of the source code, we're reliant on Check Point to provide the latest images unless Check Point provides a tool to custom bake the HFA's into a deployable image.&amp;nbsp; I'm not expecting Check Point to provide images for all patches, but I AM expecting to see images for each "Recommended" HFA.&lt;/P&gt;&lt;P&gt;And, from my lab, here are the **bleep** image sizes, the First being the image directly from Check Point, the second R81.20 Gateway only, not you managed by the multi-domain manager, all I did was update to the latest HFA (Take 41)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-rw-r----- 1 root kvm 4589092864 Jan 4 21:12 CheckPointR81-20-GW.qcow2&lt;BR /&gt;-rw-r----- 1 root kvm 15321792512 Jan 8 14:35 ncflabcpfw0002.qcow2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 14:38:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202488#M4527</guid>
      <dc:creator>AlJo</dc:creator>
      <dc:date>2024-01-08T14:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202494#M4528</link>
      <description>&lt;P&gt;I know we provide Blink images that include the most recent recommended release:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20_Downloads.htm?tocpath=_____3" target="_blank"&gt;https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20_Downloads.htm?tocpath=_____3&lt;/A&gt;&lt;BR /&gt;We also update the images in the public cloud providers (AWS, etc).&lt;BR /&gt;However, I believe we only distribute a qcow for the base version.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 15:44:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202494#M4528</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-08T15:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202502#M4529</link>
      <description>&lt;P&gt;Is the expectation then, that those of us doing Private Cloud infrastructure (VMWare or KVM) would have to figure out our own mechanism for keeping images current?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For private cloud deployments I just can see that as feasible.&lt;/P&gt;&lt;P&gt;As things are now,&amp;nbsp; private cloud using KVM would require a base image deployment followed immediately by an HFA installation taking the time to deliver a new cluster from less than 1 minutes to 10-20 minutes, with the added bagging of the disk bloat from the upgrade process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something or is private cloud automation/deployment that much behind the public cloud provider process?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:38:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202502#M4529</guid>
      <dc:creator>AlJo</dc:creator>
      <dc:date>2024-01-08T18:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202503#M4530</link>
      <description>&lt;P&gt;Personally, I noticed every image I deployed in the cloud ALWAYS contained whatever recommended jumbo was at the time of the installation...just my own experience.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:42:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202503#M4530</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T18:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202504#M4531</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;Are you deploying in Public Cloud or Private Cloud?&amp;nbsp; Based on my reading of this thread, the public cloud (AWS, Azure, GCP) get the HFAs rolled in, but not the private cloud (qcow2) images.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:49:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202504#M4531</guid>
      <dc:creator>AlJo</dc:creator>
      <dc:date>2024-01-08T18:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202505#M4532</link>
      <description>&lt;P&gt;Mostly public, but only once in private and it had updated jumbo (maybe just luck, no clue lol)&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:53:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202505#M4532</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-08T18:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202506#M4533</link>
      <description>&lt;P&gt;I haven't asked, but that appears to be the case at present.&lt;BR /&gt;I see two places where you might have an issue with this process:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Time to deploy. This, I believe, could be mitigated by creating your own image (take base image, apply JHF via CPUSE before you run First Time Wizard).&lt;/LI&gt;
&lt;LI&gt;Size of the resulting image. It's a bit bigger because it includes the CPUSE overhead, which wouldn't be there with a fresh install.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Will have to ask around and see if there's a better way to do this.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 18:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202506#M4533</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-08T18:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202543#M4534</link>
      <description>&lt;P&gt;If you try to install a jumbo before completing the first-time wizard, CPUSE definitely complains at you. I'm not sure how safe an option that is.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 21:29:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202543#M4534</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-01-08T21:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202551#M4535</link>
      <description>&lt;P&gt;Totally agree with that.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2024 00:03:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/202551#M4535</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-09T00:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/206718#M4613</link>
      <description>&lt;P&gt;Has there been any feedback from the Check Point team on how this might be addressed?&amp;nbsp; I've raised the issue with my account team and they are as perplexed as I regarding not having "current" private cloud images available.&lt;/P&gt;&lt;P&gt;I'd image the images are generated programmatically, just add one more output of KVM to make available via Check Point download site.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 16:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/206718#M4613</guid>
      <dc:creator>AlJo</dc:creator>
      <dc:date>2024-02-21T16:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Recommended patching process for private cloud images</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/206721#M4614</link>
      <description>&lt;P&gt;Hope there are some discussions about this at CPX.&lt;/P&gt;
&lt;P&gt;Definitely valid point you made&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6743"&gt;@AlJo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 21 Feb 2024 16:36:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Recommended-patching-process-for-private-cloud-images/m-p/206721#M4614</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-21T16:36:00Z</dc:date>
    </item>
  </channel>
</rss>

