<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practise for installing Hotfixes on ClusterXL in HA mode in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28937#M2287</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is easy - look into&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106162&amp;amp;partition=Advanced&amp;amp;product=All&amp;quot;"&gt;sk106162: &lt;STRONG&gt;Jumbo&lt;/STRONG&gt; &lt;STRONG&gt;Hotfix&lt;/STRONG&gt; &lt;STRONG&gt;Accumulator&lt;/STRONG&gt; for R77.30 (R77_30_jumbo_hf)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In cluster environment:&lt;BR /&gt; Jumbo Hotfix Accumulator must be installed on all members of the cluster. To assure synchronization without losing connectivity, cluster administrator should use either &lt;A href="https://sc1.checkpoint.com/documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/129990" target="_blank"&gt;Optimal Service Upgrade&lt;/A&gt; (OSU) method, or &lt;A href="https://sc1.checkpoint.com/documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/129990" target="_blank"&gt;Connectivity Upgrade&lt;/A&gt; (CU) method. For additional information and limitations, refer to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107042" target="_blank"&gt;sk107042 - ClusterXL upgrade methods and paths&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Jan 2019 10:03:41 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-01-31T10:03:41Z</dc:date>
    <item>
      <title>Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28935#M2285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello colleagues,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any kind of best practice procedure for&amp;nbsp;installing Hotfixes on ClusterXL in HA mode without downtime?&lt;/P&gt;&lt;P&gt;I used to perform it in the following way:&lt;/P&gt;&lt;P&gt;1. Installing the HF on the Standby member&lt;/P&gt;&lt;P&gt;2. Performing the manual cluster switchover by issuing "clusterXL_admin down" on the Active cluster member&lt;/P&gt;&lt;P&gt;3. &lt;SPAN&gt;Installing the HF on the&amp;nbsp; current Standby member and issuing&amp;nbsp;"clusterXL_admin up" on it to push it back to the cluster&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This procedure leads to the small drop of traffic during the switchover.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, is there a better way to perform the installation on both member without, or with minimal, downtime?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I run into the following SK -&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107042"&gt;sk107042 - ClusterXL upgrade methods and paths&lt;/A&gt;, and&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Best_Practices/Cluster_Connectivity_Upgrade/html_frameset.htm"&gt;Connectivity Upgrade R77.x and R80.x Versions Best Practices&lt;/A&gt;&amp;nbsp;document, but I'm not sure whether they are applicable for&amp;nbsp;Hotfixes installation, or only for major/minor version upgrades.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2019 15:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28935#M2285</guid>
      <dc:creator>Oleg_Pekar1</dc:creator>
      <dc:date>2019-01-30T15:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28936#M2286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you elaborate on "This procedure leads to the small drop of traffic during the switchover"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cluster admin down should not cause any downtime if configured correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those SK are the best articles you can have, follow connectivity upgrade process.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2019 21:53:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28936#M2286</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2019-01-30T21:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28937#M2287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is easy - look into&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106162&amp;amp;partition=Advanced&amp;amp;product=All&amp;quot;"&gt;sk106162: &lt;STRONG&gt;Jumbo&lt;/STRONG&gt; &lt;STRONG&gt;Hotfix&lt;/STRONG&gt; &lt;STRONG&gt;Accumulator&lt;/STRONG&gt; for R77.30 (R77_30_jumbo_hf)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In cluster environment:&lt;BR /&gt; Jumbo Hotfix Accumulator must be installed on all members of the cluster. To assure synchronization without losing connectivity, cluster administrator should use either &lt;A href="https://sc1.checkpoint.com/documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/129990" target="_blank"&gt;Optimal Service Upgrade&lt;/A&gt; (OSU) method, or &lt;A href="https://sc1.checkpoint.com/documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/129990" target="_blank"&gt;Connectivity Upgrade&lt;/A&gt; (CU) method. For additional information and limitations, refer to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107042" target="_blank"&gt;sk107042 - ClusterXL upgrade methods and paths&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 10:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28937#M2287</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-01-31T10:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28938#M2288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The drop of traffic may be connected with our traffic pattern - lots of short HTTP session are in place. I believe default synchronisation settings have some delay configured - need to revise that, thanks for pointing out.&lt;/P&gt;&lt;P&gt;Do you use the&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;connectivity upgrade process during your upgrades? Is it smooth?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 12:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28938#M2288</guid>
      <dc:creator>Oleg_Pekar1</dc:creator>
      <dc:date>2019-01-31T12:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28939#M2289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice remark!&lt;/P&gt;&lt;P&gt;That's what I wanted to see in the docs - a clear indication of the recommended procedure.&lt;/P&gt;&lt;P&gt;But I only missed it due to the fact it is not mentioned for the newer versions of CheckPoint software:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116380"&gt;Jumbo Hotfix Accumulator for R80.10 (R80_10_jumbo_hf)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk137592"&gt;Jumbo Hotfix Accumulator for R80.20 (R80_20_jumbo_hf)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Do you think it's still a thing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 12:19:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28939#M2289</guid>
      <dc:creator>Oleg_Pekar1</dc:creator>
      <dc:date>2019-01-31T12:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28940#M2290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do know that - and you did cite the important documentation yourself &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; You can use the Comment field in Give us feedback at the end of the page to suggest changes to the sk, i just did that...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 12:30:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28940#M2290</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-01-31T12:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28941#M2291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AFAIK OSU and CU are methods to use when you are upgrading from a lower version, not for Jumbo Hotfix upgrade since your base version it's still the same. &lt;STRONG&gt;Maybe an error of documentation on sk106162???&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Here are the upgrade paths of CU showing only base versions and nothing related to Jumbo Hotfix upgrades.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="78065" class="image-1 jive-image" height="380" src="https://community.checkpoint.com/legacyfs/online/checkpoint/78065_pastedImage_1.png" width="547" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your cluster is configured as "Highest priority member is always active"??&lt;/P&gt;&lt;P&gt;Your approach of Standby first its correct, for this scenarios I prefer to check the option "Maintain current active member" to aviod failovers other than those manually executed through clusterXL_admin; always verifying that the state is Active/Standby before start any operation.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 15:41:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28941#M2291</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2019-01-31T15:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28942#M2292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is ClusterXL - if you install an update it follows the same procedure as a Jumbo HF, so you have to use&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;OSU&amp;nbsp;or CU or schedule a maintenance window...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 16:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28942#M2292</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-01-31T16:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practise for installing Hotfixes on ClusterXL in HA mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28943#M2293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah,&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;"Maintain current active member" option lets perform only one failover, so I use this mode.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;I lived happily following the procedure described in my opening post, until started preparing for CCSE exam and encountering the&amp;nbsp;&lt;SPAN&gt;OSU and CU ways of upgrade. Unfortunately, there's no info whether these procedures are acceptable for installing Jumbos, so I went here to clarify it with the community &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;I believe Gunther is right, and CheckPoint just needs to update the relevant SKs.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;If understand it correct, the CU procedure will just make an additional sync of the connections and routing tables between the members, which is no harm for cluster at all.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 11:50:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practise-for-installing-Hotfixes-on-ClusterXL-in-HA-mode/m-p/28943#M2293</guid>
      <dc:creator>Oleg_Pekar1</dc:creator>
      <dc:date>2019-02-01T11:50:25Z</dc:date>
    </item>
  </channel>
</rss>

