<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cluster upgrade in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34217#M2778</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to&amp;nbsp;replace checkpoint 4800 cluster R 77.30&amp;nbsp;with checkpoint 5K R 80.10 with minimal down time. Please provide the steps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jun 2018 14:22:46 GMT</pubDate>
    <dc:creator>Brianpiraty_Ale</dc:creator>
    <dc:date>2018-06-26T14:22:46Z</dc:date>
    <item>
      <title>Cluster upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34217#M2778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to&amp;nbsp;replace checkpoint 4800 cluster R 77.30&amp;nbsp;with checkpoint 5K R 80.10 with minimal down time. Please provide the steps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 14:22:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34217#M2778</guid>
      <dc:creator>Brianpiraty_Ale</dc:creator>
      <dc:date>2018-06-26T14:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34218#M2779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a number of questions that come to mind before being able to answer this:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Local management or central?&lt;/LI&gt;&lt;LI&gt;If local, is it HA?&lt;/LI&gt;&lt;LI&gt;If local, are there plans to move to Central?&lt;/LI&gt;&lt;LI&gt;If central, is management upgrade already?&lt;/LI&gt;&lt;LI&gt;ClusterXL or VRRP?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;The above questions will help&amp;nbsp;build a plan that can be used in your situation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 17:51:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34218#M2779</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-06-26T17:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34219#M2780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;central management and Manager is already with R 80.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it is cluster XL&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 18:10:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34219#M2780</guid>
      <dc:creator>Brianpiraty_Ale</dc:creator>
      <dc:date>2018-06-26T18:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster upgrade</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34220#M2781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are the steps we take with a cluster replacement currently planned for next Saturday:&lt;/P&gt;&lt;P&gt;Preparations:&lt;/P&gt;&lt;P&gt;Prepare the full configuration of the new boxes, run the First Time Wizard, plus all the things you configure in Gaia, being:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;interfaces (all using the same IP as the current units , except for the 1 interface, see below)&lt;/LI&gt;&lt;LI&gt;routing&lt;/LI&gt;&lt;LI&gt;DNS&lt;/LI&gt;&lt;LI&gt;NTP&lt;/LI&gt;&lt;LI&gt;Users&lt;/LI&gt;&lt;LI&gt;passwords&lt;/LI&gt;&lt;LI&gt;SNMP&lt;/LI&gt;&lt;LI&gt;etc.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Now see if you have 2 spare IP's on the network that you manage you gateways on, if so apply these to the correct interface.&lt;/P&gt;&lt;P&gt;Prepare your switch(es) to connect all used ports of your new boxes to shutdown ports, except for the management network.&lt;/P&gt;&lt;P&gt;Before you establish SIC to management type &lt;EM&gt;cphastop&lt;/EM&gt; on both new boxes.&lt;/P&gt;&lt;P&gt;Now in SmartConsole in your cluster object you add the 2 new boxes as new members, so you end up with 4 members, make sure the new members have a lower priority..&lt;/P&gt;&lt;P&gt;Set the Clusterversion&lt;/P&gt;&lt;P&gt;Now establish SIC and you can install the policy if you want, with the option to install anyway if any member fails, as you will have 2 members failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you are ready for the actual change window&lt;/P&gt;&lt;P&gt;On the switch connected to Backup gateway shut down all ports connected to the 4800 backup GW.&lt;/P&gt;&lt;P&gt;On the switch connected to the 5K backup GW enable all ports connected to the 5K backup GW (the one with the same IP's as the 48800 backup GW)&lt;/P&gt;&lt;P&gt;Check connectivty with the new box and the rest of the network. Push policy again, to make sure you have the latest loaded.&lt;/P&gt;&lt;P&gt;On the 5K backup GW issue the command&amp;nbsp;&lt;EM&gt;cphastart&amp;nbsp; &lt;/EM&gt;and &amp;nbsp;on the 4800 Primary GW type &lt;EM&gt;cphastop&lt;/EM&gt; to disable clustering and flip to the new member.&lt;/P&gt;&lt;P&gt;Run tests before you continue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When all is ok, you go to the next step, move the 4800 Primary out of the way by shutting down it's switch ports and bring the&amp;nbsp;5K primary online by enabling it's switch ports.&lt;/P&gt;&lt;P&gt;After a connectivity check you can bring the 5K primary GW into play by issuing the&lt;EM&gt; cphastart&lt;/EM&gt; command.&lt;/P&gt;&lt;P&gt;Depending on the setting of the clusterXL setting in the SmartConsole it will either flip to the higher priority or it will remain on the current active one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cleanup is done by removing the 2 4800 members from the cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps and yes there are some extra things you need to take care of like setting the correct version to make sure you push the right cluster members.&lt;/P&gt;&lt;P&gt;Don't hesitate to ask when you have questions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 21:37:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-upgrade/m-p/34220#M2781</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-06-26T21:37:11Z</dc:date>
    </item>
  </channel>
</rss>

