<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.40 cluster blink upgrade gone wrong in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/115004#M16130</link>
    <description>&lt;P&gt;Thanks for the response Andy, I didn’t follow steps 1 or 2 in your referenced guide in either the lab or the production environments. However I have never followed these steps and I have never had this problem before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rest of the procedure looks pretty much spot on and is how I would normally so this. As soon as I did step 3 the experience was not what I believe should have been.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Mar 2021 07:26:09 GMT</pubDate>
    <dc:creator>adina</dc:creator>
    <dc:date>2021-03-31T07:26:09Z</dc:date>
    <item>
      <title>R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114802#M16085</link>
      <description>&lt;P&gt;I have performed an R80.40 upgrade on a R80.30 clusterXL the other day using a Blink Package as the Major Versions package wasn’t available for download. &amp;nbsp;I followed the steps in sk92449, however upon upgrading the first gateway I started noticing some issues. I started with the standby member and after the upgrade it came back as active and it was conflicting with the other gateway that was also active.&lt;BR /&gt;Is this standard behavior or have I missed something?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 13:14:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114802#M16085</guid>
      <dc:creator>adina</dc:creator>
      <dc:date>2021-03-28T13:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114806#M16086</link>
      <description>&lt;P&gt;If you just did the CPUSE upgrade and didn’t take any additional steps, I can see how you’d run into what you did.&lt;BR /&gt;There are a few different things you can do prior to the upgrade to ensure a much smoother transition, depending on the level of downtime that is acceptable.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107042&amp;amp;partition=Basic&amp;amp;product=ClusterXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107042&amp;amp;partition=Basic&amp;amp;product=ClusterXL&lt;/A&gt;,&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 17:36:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114806#M16086</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-28T17:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114818#M16092</link>
      <description>&lt;P&gt;Thank you for your quick response. This was one of the articles I referred to when planning my upgrade. I can't see anything in there that suggests I need to take any additional steps to prevent an ‘Active - Active’ state. I have also tested this in a lab environment both before and after the change and couldn’t replicate the issue.&amp;nbsp;&lt;BR /&gt;I’m trying to work out if I have made a mistake as I am struggling to understand where I’ve made it, based on the documentation I have read and the test results.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 20:01:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114818#M16092</guid>
      <dc:creator>adina</dc:creator>
      <dc:date>2021-03-28T20:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114822#M16093</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/60882"&gt;@adina&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Did you perform an upgrade or fresh install using Blink?&lt;/P&gt;&lt;P&gt;Did you enable MVC?&lt;/P&gt;&lt;P&gt;Did you push policy for the upgraded member to obtain the interfaces, topology, clusterXL, etc?&lt;/P&gt;&lt;P&gt;I typically would shutdown the upstream switch ports to prevent active/active, leave just the sync and management ports up, perform the upgrade/fresh install using the desired mode, establish SIC (if required), install license (if required), push policy, enable MVC (if supported for that particular upgrade path), check the Cluster status and re-enable the upstream switchports if all looks healthy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 23:21:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114822#M16093</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2021-03-28T23:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114867#M16102</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27193"&gt;@Alex_Shpilman&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I did an upgrade not a clean install. Normally I would have used the Major Versions package, however for the gateways it wasn’t available for download. I’ve considered downloading and manually importing it but in the end I decided to go for the Blink image.&lt;/P&gt;&lt;P&gt;These are the steps that I did:&lt;BR /&gt;- Snapshot the appliance and export the snapshots to a secure external location.&lt;BR /&gt;- Take a backup of the gaia configuration.&lt;BR /&gt;- Check for updates.&lt;BR /&gt;- Download the Blink image on the Standby gateway (which is also the gateway withe the lowest priority in the cluster).&lt;BR /&gt;- Verify the package.&lt;BR /&gt;- Start the upgrade.&lt;BR /&gt;- After the new version finished installing and the appliance rebooted it came back as active. I didn’t get the chance to push the policy or do anything else.&lt;/P&gt;&lt;P&gt;To fix it I just did a cphastop on the upgraded gateway, pushed the policy, enabled mvc and continued with the upgrade.&lt;/P&gt;&lt;P&gt;In my lab I followed the same steps, however after the reboot the firewall came back as ‘Ready’ every single time I’ve tried it.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 11:15:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114867#M16102</guid>
      <dc:creator>adina</dc:creator>
      <dc:date>2021-03-29T11:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114872#M16105</link>
      <description>&lt;P&gt;Hm...those steps do make sense, BUT...here is something I have problem with. If you follow below (specially section for zero downtime upgrade page 133, it outlines exact steps...I did this many times and it never failed)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dl3.checkpoint.com/paid/bf/bf5b38d9c193fca29b572bd4f77fa07e/CP_R80.10_Installation_and_Upgrade_Guide.pdf?HashKey=1617028761_ae12ff9ce35017f344cb45bff6fb11c5&amp;amp;xtn=.pdf" target="_blank"&gt;https://dl3.checkpoint.com/paid/bf/bf5b38d9c193fca29b572bd4f77fa07e/CP_R80.10_Installation_and_Upgrade_Guide.pdf?HashKey=1617028761_ae12ff9ce35017f344cb45bff6fb11c5&amp;amp;xtn=.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that what you followed in your lab?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Mar 2021 12:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114872#M16105</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-29T12:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114906#M16110</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/60882"&gt;@adina&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I believe your sequence was according to the outlined steps in the &lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Installation_and_Upgrade_Guide/Topics-IUG/MVC-Upgrade-of-ClusterXL-GW-mode.htm?tocpath=Upgrade%20of%20Security%20Gateways%20and%20Clusters%7CUpgrading%20ClusterXL%252C%20VSX%20Cluster%252C%20or%20VRRP%20Cluster%7CMulti-Version%20Cluster%20(MVC)%20Upgrade%7C_____4" target="_self"&gt;MVC&lt;/A&gt;, however, the official documentation is specifying upgrade/clean install as per &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92449" target="_self"&gt;sk92449&lt;/A&gt;&amp;nbsp;, which is not specifying Blink.&lt;/P&gt;&lt;P&gt;As a precaution, I usually shutdown the data interfaces to prevent active/active, in case the upgraded member comes up with no ClusterXL configuration.&lt;/P&gt;&lt;P&gt;The fact that stopping CluserXL and installing policy fixed the issue suggests that the Blink upgraded member came up with no ClusterXL settings, which restored after the policy installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 01:05:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114906#M16110</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2021-03-30T01:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114944#M16117</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I'd like to clarify two issues:&lt;/P&gt;
&lt;P&gt;1. SK92449 does not mention Blink because Blink is just another CPUSE package. No special treatment or specific installation instructions for Blink packages.&lt;/P&gt;
&lt;P&gt;2. CPUSE (DA - Deployment Agent) is installing a package on a local machine. Hence is does not have any awareness of the other cluster members state. SK92449 refers to local machine installation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 13:28:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114944#M16117</guid>
      <dc:creator>Boaz_Orshav</dc:creator>
      <dc:date>2021-03-30T13:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114953#M16121</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Would be good if you can share the following with timestamp of the occurrence so we can try to figure out what happen on this specific case.&lt;/P&gt;
&lt;P&gt;We need from both members:&lt;/P&gt;
&lt;P&gt;/var/log/messages&lt;/P&gt;
&lt;P&gt;$FWDIR/log/fwk.elg (in VSX or USFW case).&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 15:12:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114953#M16121</guid>
      <dc:creator>Yair_Shahar</dc:creator>
      <dc:date>2021-03-30T15:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114971#M16126</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19244"&gt;@Boaz_Orshav&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. True, unless Blink Utility is used, which is not clear in this case&lt;/P&gt;&lt;P&gt;2. True again but my point was that in most cases after an upgrade, the CluserXL membership is retained and the upgraded member comes up as "Ready".&lt;/P&gt;&lt;P&gt;Not in this case though, I had a few of these cases before and that's why suggested to shutdown the data ports until policy is installed and MVC is enabled on the upgraded member.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Mar 2021 19:55:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/114971#M16126</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2021-03-30T19:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/115004#M16130</link>
      <description>&lt;P&gt;Thanks for the response Andy, I didn’t follow steps 1 or 2 in your referenced guide in either the lab or the production environments. However I have never followed these steps and I have never had this problem before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rest of the procedure looks pretty much spot on and is how I would normally so this. As soon as I did step 3 the experience was not what I believe should have been.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:26:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/115004#M16130</guid>
      <dc:creator>adina</dc:creator>
      <dc:date>2021-03-31T07:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/115005#M16131</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27193"&gt;@Alex_Shpilman&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/19244"&gt;@Boaz_Orshav&lt;/a&gt;&amp;nbsp; for the responses. I can confirm this was an upgrade not using the blink utility.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;With regards to the second point the DA might be only aware of what is happening locally however this does not explain why when the firewall rebooted on it’s upgraded version that the CCP did not detect the counter part firewall and move to a ready state.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to confirm the experience:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;the upgrade was run from CPUSE&lt;/LI&gt;&lt;LI&gt;the firewall rebooted with an initial policy (expected and replicated in the lab)&lt;/LI&gt;&lt;LI&gt;the firewall went active as soon as it had rebooted ( not seen in the 4 other times i have tested this in the lab)&lt;/LI&gt;&lt;LI&gt;I then had to run cphastop to stop them fighting over the VIP.&lt;/LI&gt;&lt;LI&gt;I could then get back into the environment and push policy to the upgraded firewall.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 31 Mar 2021 07:43:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/115005#M16131</guid>
      <dc:creator>adina</dc:creator>
      <dc:date>2021-03-31T07:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 cluster blink upgrade gone wrong</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/130938#M19261</link>
      <description>&lt;P&gt;Did you figure out what happened here? I'm trying convince myself to use Blink images to upgrade clusters to R81 but your experience is not assuring.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2021 10:42:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-cluster-blink-upgrade-gone-wrong/m-p/130938#M19261</guid>
      <dc:creator>am</dc:creator>
      <dc:date>2021-10-04T10:42:26Z</dc:date>
    </item>
  </channel>
</rss>

