<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tips for upgrading HA clusters in GCP in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154227#M944</link>
    <description>&lt;P&gt;We have some older R80.30 HA BYOL clusters deployed in Google Cloud and I need to start planning how to upgrade to R80.40 or R81.10 while preserving external IP addresses.&amp;nbsp; I know this can be done by going to deployment manager, deleting the deployment, and selecting the "Keep resources created by it" option, and finally launching a new cluster with the same name.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem though is in Smart Console.&amp;nbsp; It seems that just changing the management IP addresses and resetting SIC doesn't work.&amp;nbsp; Instead, I have to&amp;nbsp;completely remove the cluster from SmartConsole, set it up as if it were a new cluster, then re-install policy.&amp;nbsp; This is fairly time consuming since any "Install on" rules need to be set to "Policy Targets" and then re-entered after the new cluster is up and running.&amp;nbsp; The cluster also needs to be removed from any VPN communities and inspection rules, which takes additional time.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there an easier way to do this?&amp;nbsp; I'm currently estimating 3-4 hours downtime per cluster and would really like to get that to under an hour if possible.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 30 Jul 2022 23:37:07 GMT</pubDate>
    <dc:creator>johnnyringo</dc:creator>
    <dc:date>2022-07-30T23:37:07Z</dc:date>
    <item>
      <title>Tips for upgrading HA clusters in GCP</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154227#M944</link>
      <description>&lt;P&gt;We have some older R80.30 HA BYOL clusters deployed in Google Cloud and I need to start planning how to upgrade to R80.40 or R81.10 while preserving external IP addresses.&amp;nbsp; I know this can be done by going to deployment manager, deleting the deployment, and selecting the "Keep resources created by it" option, and finally launching a new cluster with the same name.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem though is in Smart Console.&amp;nbsp; It seems that just changing the management IP addresses and resetting SIC doesn't work.&amp;nbsp; Instead, I have to&amp;nbsp;completely remove the cluster from SmartConsole, set it up as if it were a new cluster, then re-install policy.&amp;nbsp; This is fairly time consuming since any "Install on" rules need to be set to "Policy Targets" and then re-entered after the new cluster is up and running.&amp;nbsp; The cluster also needs to be removed from any VPN communities and inspection rules, which takes additional time.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there an easier way to do this?&amp;nbsp; I'm currently estimating 3-4 hours downtime per cluster and would really like to get that to under an hour if possible.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2022 23:37:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154227#M944</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2022-07-30T23:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Tips for upgrading HA clusters in GCP</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154231#M945</link>
      <description>&lt;P&gt;Are you following the process outlined here or something else?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailabilty_for_GCP/Content/Topics-GCP-HA/Additional-Information.htm?TocPath=Additional%20Information%7C_____3#Upgrading_a_Check_Point_CloudGuard_IaaS_High_Availability_Solution_to_a_Newer.." target="_blank" rel="noopener"&gt;CloudGuard Network High Availability for Google Cloud Platform R80.30 and Higher Deployment Guide &amp;gt; Additional Information &amp;gt; Upgrading a Check Point CloudGuard IaaS High Availability Solution to a Newer Version&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 02:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154231#M945</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-31T02:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Tips for upgrading HA clusters in GCP</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154237#M946</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;are you sure you can't just RESET SIC and ReSic the new GWs ? this is usually what I do in any Cluster upgrade in any cloud vendor .&lt;/P&gt;
&lt;P&gt;do you get any errors or issues doing this process ?&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 09:57:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154237#M946</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-07-31T09:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Tips for upgrading HA clusters in GCP</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154491#M947</link>
      <description>&lt;P&gt;I'd have to re-lab it, but the problem with just resetting SIC and changing the management IPs is the cluster never forms.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 04:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154491#M947</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2022-08-04T04:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Tips for upgrading HA clusters in GCP</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154492#M948</link>
      <description>&lt;P&gt;Thanks, I had not noticed this section.&amp;nbsp; It will be a couple weeks before I have time to try this out, but it makes sense.&amp;nbsp; The only caveat I can see is GCP doesn't allow instances in the same zone to have the same name, but I'd imagine this can be worked around by just selecting different zones for the old and new cluster members.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 04:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Tips-for-upgrading-HA-clusters-in-GCP/m-p/154492#M948</guid>
      <dc:creator>johnnyringo</dc:creator>
      <dc:date>2022-08-04T04:48:43Z</dc:date>
    </item>
  </channel>
</rss>

