<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Cluster Upgrade: VPN question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121472#M17294</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;My experience with Zero Downtime upgrades were that firewall session are kept with a light packet loss (1 or 2 packets).&lt;/P&gt;&lt;P&gt;S2S tunnel will disconnect and need to reconnect, which will cause an outage for the tunnel.&lt;/P&gt;&lt;P&gt;Remote Access connections will also disconnect and need to reconnect.&lt;/P&gt;&lt;P&gt;I've done those upgrades from R77.30 to R80.20 and R80.20 to R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jun 2021 14:45:53 GMT</pubDate>
    <dc:creator>Markus_Genser</dc:creator>
    <dc:date>2021-06-17T14:45:53Z</dc:date>
    <item>
      <title>Checkpoint Cluster Upgrade: VPN question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121394#M17270</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am Planning to upgrade checkpoint cluster from R80.10 to R80.30 with "ZeroDown time" process.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;we have a few site to site VPN from this cluster. During upgrade process, we have to failover primary firewall via applying #cpstop command. I want to know how VPN tunnels will be effected while upgrade process ? do i need to consider specific steps for VPN and/or mobile access blade configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 21:11:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121394#M17270</guid>
      <dc:creator>ashah</dc:creator>
      <dc:date>2021-06-16T21:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Cluster Upgrade: VPN question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121467#M17292</link>
      <description>&lt;P&gt;I suggest that you read the relevant sections of this guide completely, as answers to your questions are there (including much more).&lt;/P&gt;
&lt;P&gt;You said you will use Zero Downtime approach. This is not non-disruptive at all. The name is somehow misleading - technically correct, but most people will assume more than meant here.&lt;/P&gt;
&lt;P&gt;There are two other relevant upgrade modes (Connectivity Upgrade and Optimal Service Upgrade) which are better and can be non-disruptive for certain use cases. But you mentioned VPN and mobile access and here the guide clearly says: not supported.&lt;/P&gt;
&lt;P&gt;The guide also gives special hints regarding custom Mobile Access configuration, which you have to take special care of, because it would not survive upgrade.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 14:02:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121467#M17292</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-06-17T14:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Cluster Upgrade: VPN question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121470#M17293</link>
      <description>&lt;P&gt;Thank you very much for your response,&amp;nbsp;&lt;/P&gt;&lt;P&gt;this was the biggest confusion on that which method i should go for, customer do not want any downtime at all but checkpoint TAC support suggested "zero downtime" method.&amp;nbsp;&lt;/P&gt;&lt;P&gt;when it says, VPN and mobile access are not supported, should i expect that VPN will go totally down and/or i will have to re-build them after the upgrade?&amp;nbsp;&lt;/P&gt;&lt;P&gt;again, TAC told me that, VPN should survive as at least one cluster member will always be UP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;a lot of confusion on TAC's advice vs user guide.&amp;nbsp;&lt;/P&gt;&lt;P&gt;please suggest.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 14:23:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121470#M17293</guid>
      <dc:creator>ashah</dc:creator>
      <dc:date>2021-06-17T14:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Cluster Upgrade: VPN question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121472#M17294</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;My experience with Zero Downtime upgrades were that firewall session are kept with a light packet loss (1 or 2 packets).&lt;/P&gt;&lt;P&gt;S2S tunnel will disconnect and need to reconnect, which will cause an outage for the tunnel.&lt;/P&gt;&lt;P&gt;Remote Access connections will also disconnect and need to reconnect.&lt;/P&gt;&lt;P&gt;I've done those upgrades from R77.30 to R80.20 and R80.20 to R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 14:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121472#M17294</guid>
      <dc:creator>Markus_Genser</dc:creator>
      <dc:date>2021-06-17T14:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Cluster Upgrade: VPN question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121473#M17295</link>
      <description>&lt;P&gt;thanks a lot Markus for your input,&amp;nbsp;&lt;/P&gt;&lt;P&gt;after i saw comment from Tobias, i was thinking to go with connectivity upgrade method. if zero down time method wont be able to keep connectivity UP all the time, what do you think ? please suggest.&lt;/P&gt;&lt;P&gt;zero down time process says to apply #cpstop command on older active cluster version, is this the correct approach you applied?&lt;/P&gt;&lt;P&gt;How long your upgrade took?&lt;/P&gt;&lt;P&gt;when you say i will have to reconnect VPN, can you elaborate this please? do i have to re-configure VPNs?&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the help !!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 14:52:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121473#M17295</guid>
      <dc:creator>ashah</dc:creator>
      <dc:date>2021-06-17T14:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Cluster Upgrade: VPN question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121474#M17296</link>
      <description>&lt;P&gt;From what the guide says, what sk107042 says and my own experience, I would say TAC advise is wrong.&lt;/P&gt;
&lt;P&gt;Site to Site VPNs should recover automatically after a while, if they fail. Regarding RAS VPNs, I think it depends on the client and configuration. A manual reconnect may be needed.&lt;/P&gt;
&lt;P&gt;I suggest using Connectivity Upgrade (MVC is a R80.40 feature) and live with the RAS-VPN and Mobile Access problems (and the other limitations). Non-traditional Site to Site VPNs should survive this upgrade method.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 14:53:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121474#M17296</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-06-17T14:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Cluster Upgrade: VPN question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121476#M17298</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23009"&gt;@Markus_Genser&lt;/a&gt; : The guide and the sk clearly say for Zero Downtime upgrade method:&lt;/P&gt;
&lt;P&gt;Connections are not synchronized between cluster members running different Check Point software versions.&lt;BR /&gt;Connections that were initiated on a cluster members running the previous version are dropped when the cluster member is upgraded to a new version.&lt;BR /&gt;&lt;STRONG&gt;Requires a relatively short maintenance window for old connections to be dropped&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;I cannot believe, that in your case "firewall session are kept with a light packet loss (1 or 2 packets)". How can this be possible, when connections are not synced?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 14:57:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121476#M17298</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-06-17T14:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Cluster Upgrade: VPN question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121521#M17309</link>
      <description>&lt;P&gt;Well experience from the field is always a bit different than the sk or user guide.&lt;/P&gt;&lt;P&gt;Yes, the sessions persist, but there is still a short window during the failover, that the whole switching needs to recalculate that&amp;nbsp; the frames now leave on a different switch and port and this results in lost packets.&lt;/P&gt;&lt;P&gt;As the firewall still has the session, TCP control mechanism kicks in and resends the lost packet and ICMP &amp;amp; UDP simply don't care.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2021 06:11:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-Cluster-Upgrade-VPN-question/m-p/121521#M17309</guid>
      <dc:creator>Markus_Genser</dc:creator>
      <dc:date>2021-06-18T06:11:35Z</dc:date>
    </item>
  </channel>
</rss>

