<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Replace and migrate in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replace-and-migrate/m-p/110033#M15073</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have a little question.&lt;/P&gt;&lt;P&gt;I need to replace clusterxl with 2 5600 running on r77,30 in new 6600 with r80.40.&lt;/P&gt;&lt;P&gt;The problem is that is not possible to stop the firewall service.&lt;/P&gt;&lt;P&gt;The management run on vmware.&lt;/P&gt;&lt;P&gt;Which is the more easy procedure with minor impact on the gateway so that in case the rollback i need only an restart of old environment?&lt;/P&gt;&lt;P&gt;The interface ip is not possible to change&lt;/P&gt;&lt;P&gt;Thank a lot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 07 Feb 2021 12:55:41 GMT</pubDate>
    <dc:creator>Ginoogle</dc:creator>
    <dc:date>2021-02-07T12:55:41Z</dc:date>
    <item>
      <title>Replace and migrate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replace-and-migrate/m-p/110033#M15073</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;I have a little question.&lt;/P&gt;&lt;P&gt;I need to replace clusterxl with 2 5600 running on r77,30 in new 6600 with r80.40.&lt;/P&gt;&lt;P&gt;The problem is that is not possible to stop the firewall service.&lt;/P&gt;&lt;P&gt;The management run on vmware.&lt;/P&gt;&lt;P&gt;Which is the more easy procedure with minor impact on the gateway so that in case the rollback i need only an restart of old environment?&lt;/P&gt;&lt;P&gt;The interface ip is not possible to change&lt;/P&gt;&lt;P&gt;Thank a lot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 12:55:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replace-and-migrate/m-p/110033#M15073</guid>
      <dc:creator>Ginoogle</dc:creator>
      <dc:date>2021-02-07T12:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Replace and migrate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replace-and-migrate/m-p/110060#M15084</link>
      <description>&lt;P&gt;There’s really not a way to do this without some sort of minimal outage.&lt;BR /&gt;On the policy side, you can (temporarily) disable the “Drop out of state” properties to minimize some of the impact.&lt;BR /&gt;You can generally swap in/out the hardware (with the accompanying restart) easily enough.&lt;/P&gt;
&lt;P&gt;Where I see some possible complexity is in either defining a new cluster (with duplicate IPs to the previous) or updating the existing cluster object configuration to match the new hardware.&lt;BR /&gt;I’d recommend searching the community as I know others have had to perform similar types of upgrades.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 18:03:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replace-and-migrate/m-p/110060#M15084</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-07T18:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Replace and migrate</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replace-and-migrate/m-p/110183#M15132</link>
      <description>&lt;P&gt;I do it the following path:&lt;/P&gt;&lt;P&gt;1) replace the standby 5600 with a new 6600&lt;/P&gt;&lt;P&gt;2) initiate SIC to 6600 and change the version of the cluster to R80.40&lt;/P&gt;&lt;P&gt;3) Install a policy and remove the tick on install on all members - 6600 will become a part of the cluster but will be in ready, 5600 will proceed to be the active one&lt;/P&gt;&lt;P&gt;4) in the most unstressed time do a cpstop of the 5600. 6600 will start processing traffic&lt;/P&gt;&lt;P&gt;5) replace 5600 with the new 6600, initiate SIC and push the policy and mark&amp;nbsp;on install on all members&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 12:59:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replace-and-migrate/m-p/110183#M15132</guid>
      <dc:creator>MartinTzvetanov</dc:creator>
      <dc:date>2021-02-08T12:59:50Z</dc:date>
    </item>
  </channel>
</rss>

