<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues with throughput after VSX upgrade from R80.40 T102 to T118 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120791#M17153</link>
    <description>&lt;P&gt;Just wondering if anyone else seen any weird issues with total throughput being capped at 2Gbps after upgrade to current T118?&lt;/P&gt;
&lt;P&gt;That's on CP appliance 23800&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 528px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12092i9329DC609D0BD6D1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I did not observe any other issues apart from reduced throughput. After restoring T102 snapshot we were back to normal levels way above 2Gbps&lt;/P&gt;
&lt;P&gt;We have 3 bonds, all 2x10Gbps, so it feels like somehow they were running at 2x1Gbps for whatever reason.&lt;/P&gt;
&lt;P&gt;I didn't do long investigation but basic interface check shows that it should have run 20Gbps on bonds&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 417px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12091i2C956DAA7ACE87BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jun 2021 21:24:46 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2021-06-09T21:24:46Z</dc:date>
    <item>
      <title>Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120791#M17153</link>
      <description>&lt;P&gt;Just wondering if anyone else seen any weird issues with total throughput being capped at 2Gbps after upgrade to current T118?&lt;/P&gt;
&lt;P&gt;That's on CP appliance 23800&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 528px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12092i9329DC609D0BD6D1/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I did not observe any other issues apart from reduced throughput. After restoring T102 snapshot we were back to normal levels way above 2Gbps&lt;/P&gt;
&lt;P&gt;We have 3 bonds, all 2x10Gbps, so it feels like somehow they were running at 2x1Gbps for whatever reason.&lt;/P&gt;
&lt;P&gt;I didn't do long investigation but basic interface check shows that it should have run 20Gbps on bonds&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 417px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12091i2C956DAA7ACE87BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 21:24:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120791#M17153</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-06-09T21:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120905#M17177</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;we have latency issues with browsing the web on T118. At the moment workaround is to disable SecureXL on the VS.&lt;BR /&gt;Case is open.&lt;/P&gt;&lt;P&gt;Edit: We can limit it to Clients where HTTPS inspection is happening.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jan&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 12:01:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120905#M17177</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2021-06-14T12:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120907#M17178</link>
      <description>&lt;P&gt;Hehe, VS running over 10Gbps, turning off SXL would be a suicide &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 06:40:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120907#M17178</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-06-11T06:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120909#M17179</link>
      <description>&lt;P&gt;Running at 2GBit/s with same CPU load as with SecureXL turned on doing URLF and IPS. Very funny.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 06:51:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120909#M17179</guid>
      <dc:creator>Jan_Kleinhans</dc:creator>
      <dc:date>2021-06-11T06:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120933#M17185</link>
      <description>&lt;P&gt;We went from t91 -&amp;gt; t118 and experience an increased load on several VS fwk threads. In effect many of our VSs have doubled in cpu usage or more. Case open. no blades except firewalling enabled btw.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vs.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12119i853D56F89B6F75FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="vs.PNG" alt="vs.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Henrik&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 09:56:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120933#M17185</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2021-06-11T09:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120954#M17190</link>
      <description>&lt;P&gt;Hope this is not another bad Jumbo release!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 14:15:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120954#M17190</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-06-11T14:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120963#M17193</link>
      <description>&lt;P&gt;Take 100 that you upgraded through was supposed to have a fix that may be related to what you are seeing:&lt;/P&gt;
&lt;TABLE class="footnote" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;PRJ-15447,&lt;BR /&gt;PMTR-55887&lt;/TD&gt;
&lt;TD&gt;VSX&lt;/TD&gt;
&lt;TD&gt;In some scenarios, there may be high CPU utilization in a VSX environment with several instances.&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Might be interesting to ask TAC to look specifically at this fix and whether it is working as intended in your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 14:45:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120963#M17193</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-06-11T14:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120967#M17194</link>
      <description>&lt;P&gt;Problem for us wasn't CPU I'm afraid but heavily reduced throughput. 2x1G instead of 2x10G I would say.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 15:05:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120967#M17194</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-06-11T15:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120969#M17195</link>
      <description>&lt;P&gt;Kaspars my response about CPU was to Henrik, but that is strange that you seem to be capping right at 2Gbps like that.&amp;nbsp; Are you able to determine what is going on when traffic is bumping that limit?&amp;nbsp; Packet loss?&amp;nbsp; Latency? Jitter?&amp;nbsp; I assume you don't have any CPUs hitting 100% utilization during this capping, and network interface statistics look clean?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 15:27:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120969#M17195</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-06-11T15:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120970#M17196</link>
      <description>&lt;P&gt;I'm afraid I didn't get much time to investigate. As soon as I realized that we have a problem, I reverted snapshot on standby and went back in space of 15mins as it was fairly important production firewall. Interestingly no one complained so I assume we only "slowed" down traffic roughly for an hour. So no major noticeable impact. CPU was usual on VSes. But virtual switches showed increased CPU. Apart from that I have no info to go on &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; which is a shame&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 15:34:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/120970#M17196</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-06-11T15:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121115#M17217</link>
      <description>&lt;P&gt;Hello Kaspars,&lt;/P&gt;
&lt;P&gt;If you have opened SR for this issue, please share with my the number privately.&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;Eitan, VP Technical Services&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 07:56:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121115#M17217</guid>
      <dc:creator>Eitan_Gilad-Lug</dc:creator>
      <dc:date>2021-06-14T07:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121171#M17227</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the detailed information.&lt;BR /&gt;I am looking into the diff between T102 and T118 trying to identify if there is a possibility for a degredation.&lt;/P&gt;
&lt;P&gt;This may take few days, I will keep you updated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Jafar Atili&lt;BR /&gt;VSX Core Team leader&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 15:37:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121171#M17227</guid>
      <dc:creator>jafara</dc:creator>
      <dc:date>2021-06-14T15:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121340#M17261</link>
      <description>&lt;P&gt;So the load went back to normal after 48 hours. Apparently it was connections that was not accelerated after the upgrade, but was again after several hours, I guess because new connections were established.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 09:59:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121340#M17261</guid>
      <dc:creator>Henrik_Noerr1</dc:creator>
      <dc:date>2021-06-16T09:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121611#M17348</link>
      <description>&lt;P&gt;Jafara,&lt;/P&gt;
&lt;P&gt;Do you have any update for us?&amp;nbsp; &amp;nbsp;I'm pretty sure we all want these issues resolved, and in fact the QA on the jumbos to be especially scrutinized.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jun 2021 16:04:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121611#M17348</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-06-19T16:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121616#M17349</link>
      <description>&lt;P&gt;Hi! I did a new attempt with T118 installation, this time with a small twist: I added extra step after JHF install and node reboot I pushed all topologies and policies. And seem to have done the trick - no more strange 2x1G throughput limitations.&lt;/P&gt;
&lt;P&gt;In nutshell:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;use CLI CPUSE to install T118 on standby node with reboot at the end&lt;/LI&gt;
&lt;LI&gt;after node has recovered, push all VS (including VS0) topologies and policies from SmartConsole&lt;/LI&gt;
&lt;LI&gt;Failover nodes and repeat the same steps&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I will need to observe actual T118 behaviour for couple of days but bandwidth looks OK now.&lt;/P&gt;
&lt;P&gt;Rings a beel as there was a similar issue with one of the takes back in R80.30 if I remember correctly when you had to push policy during JHF installations else nothing worked&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 07:00:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121616#M17349</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-06-20T07:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121617#M17350</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thank you for your update,&lt;BR /&gt;I think it is always good to push policy after installing a newer code in the system.&lt;/P&gt;
&lt;P&gt;regarding the VSX configuration push, I can't think of how it could be related to limiting the firewall throughput.&lt;/P&gt;
&lt;P&gt;Are we sure the issue we experienced (throughput limit) is 100% a Firewall issue?&amp;nbsp; can't it be related to a 3rd party system?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Jafar&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 06:34:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121617#M17350</guid>
      <dc:creator>jafara</dc:creator>
      <dc:date>2021-06-20T06:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121618#M17351</link>
      <description>&lt;P&gt;Yes, I'm 99% sure as it was only FW that changed and we tried both nodes in the cluster and they are located in different datacentres and connected to different physical switches.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for JHF installation procedure - could you pls confirm that it is CP recommendation to install policies after first node has been upgraded and before cutting over to upgrade other cluster member. That part normally works with JHF installations without need for policy install. It really needs to be documented somewhere then.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 07:05:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121618#M17351</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-06-20T07:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121619#M17352</link>
      <description>&lt;P&gt;As Check Point can be in some way not really friendly in regards of upgrade, here are steps we are doing while upgrading jumbo or major upgrade:&lt;/P&gt;
&lt;P&gt;1. Schedule maintanance window with potentional service outage in case of disaster&lt;/P&gt;
&lt;P&gt;2. snapshot of both nodes, backup of both nodes. In case of VSX also management backup, snapshot, export.&lt;/P&gt;
&lt;P&gt;3. transfer all backups outside of the box&lt;/P&gt;
&lt;P&gt;Steps on current standby member:&lt;/P&gt;
&lt;P&gt;4. upgrade CPUSE deployment agent to newest version&lt;/P&gt;
&lt;P&gt;5. import + verify + install (if verify passed) hotfix&lt;/P&gt;
&lt;P&gt;6. Let the standby member reboot automatically&lt;/P&gt;
&lt;P&gt;7. Once standby member is up and running as standby, do all needed healthchecks&lt;/P&gt;
&lt;P&gt;8. if all HCs are fine, policy install on both members. Check warnings after policy installation for any suspisous messages&lt;/P&gt;
&lt;P&gt;9. HC again&lt;/P&gt;
&lt;P&gt;10. Wait 10 minutes and perform failover&lt;/P&gt;
&lt;P&gt;11. Ask everyone to do all needed tests if all is running fine (latency, speed, ...)&lt;/P&gt;
&lt;P&gt;12. Grace period of 1 week in case some issue will pop-up after XY minutes/hours/days&lt;/P&gt;
&lt;P&gt;13. After all is fine with upgraded member, repeat steps 4 - 11 on second member&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have to be paranoid in these times and do as much as possible to avoid service disruptions. If there is some, you can easily failover back while still have possibility to investigate issue with TAC.&lt;/P&gt;
&lt;P&gt;Installing the policy should be mentioned in every jumbo SK...&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 07:13:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121619#M17352</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2021-06-20T07:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121622#M17353</link>
      <description>&lt;P&gt;I don't see why a policy installation is required.&amp;nbsp; When the VSX node reboots it will pick up the policy from the manager anyway.&lt;/P&gt;
&lt;P&gt;If this is required, in my option, this would be a flaw in the product; what if you have 30 VS's, surely the vendor should not expect a policy push to all 30 VS's everytime a jumbo or upgrade is done.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 10:09:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121622#M17353</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-06-20T10:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with throughput after VSX upgrade from R80.40 T102 to T118</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121629#M17356</link>
      <description>&lt;P&gt;In principle I agree with you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5933"&gt;@genisis__&lt;/a&gt;&amp;nbsp; - seems odd that manual policy install is required. If that's the case, then it should be included in CPUSE, not that hard to code to re-apply all policies after reboot. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In my case, we had only 4 VSes so it was worth the effort to try and it seem to have paid off.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Jun 2021 11:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-with-throughput-after-VSX-upgrade-from-R80-40-T102-to/m-p/121629#M17356</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-06-20T11:39:29Z</dc:date>
    </item>
  </channel>
</rss>

