<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practices to perform version UPGRADE in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161791#M28697</link>
    <description>&lt;P&gt;Regardless of the deployment, you should have some understanding of what upgrade method to use in your specific circumstances.&lt;BR /&gt;In general, either method will work, obviously, but the choice of which tool(s) you use will depend on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Source/target versions involved (for example, if upgrading R77.30 to R81.10, this will require a multi-stage upgrade)&lt;/LI&gt;
&lt;LI&gt;Hardware changes (if you are changing from one appliance to another)&lt;/LI&gt;
&lt;LI&gt;You need to leverage (or make) low-level changes that can't be implemented through an in-place upgrade (the filesystem/disk partitioning issues I mentioned previously)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I've explained why I recommend using the Advanced Upgrade process for your specific situation.&lt;BR /&gt;However, you can do an in-place upgrade, but will miss out on some of the performance benefits by doing that. (The filesystem changes improve performance)&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2022 17:08:39 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-11-10T17:08:39Z</dc:date>
    <item>
      <title>Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161440#M28569</link>
      <description>&lt;P&gt;Hello, team.&lt;/P&gt;&lt;P&gt;I am looking for a recommendation, regarding the "correct" way to perform a version UPGRADE for my GAIA R80.30 which is "working" on an OPEN SERVER, in the STANDALONE architecture (SMS+SG).&lt;BR /&gt;The intention is to take it to the R81.10 version.&lt;/P&gt;&lt;P&gt;These are the data of my operating system:&lt;/P&gt;&lt;P&gt;Product version Check Point Gaia R80.30&lt;BR /&gt;OS build 200&lt;BR /&gt;OS kernel version 2.6.18-92cpx86_64&lt;/P&gt;&lt;P&gt;Is it better to perform the UPGRADE process, using the CPUSE package?&lt;BR /&gt;Or is it better to do a FRESH INSTALL to perform the UPGRADE?&lt;/P&gt;&lt;P&gt;Which of both methods is the most advisable to do it in production?&lt;/P&gt;&lt;P&gt;Thanks for your comments and contributions.&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 13:53:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161440#M28569</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-07T13:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161442#M28571</link>
      <description>&lt;P&gt;In this specific case, I recommend using the “advanced upgrade” approach, which includes a fresh install booting from a USB ISO.&lt;BR /&gt;This is necessary to leverage the XFS file system, which will improve performance in a standalone configuration.&lt;/P&gt;
&lt;P&gt;Of course, with a standalone system, any upgrade involves unavoidable downtime.&lt;BR /&gt;A fresh install always takes longer than an in-place upgrade.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 13:57:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161442#M28571</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-07T13:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161445#M28573</link>
      <description>&lt;P&gt;Thank you for your contribution, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you comment me, in which cases nowadays, do you use the CPUSE package to do version upgrade?&lt;/P&gt;&lt;P&gt;Because I have seen in many videos and some documentation, that this method is also being "put" in practice a lot.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 14:21:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161445#M28573</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-07T14:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161457#M28575</link>
      <description>&lt;P&gt;I had done this few times and from my experience, its BEST to use whats called "blink package" for upgrades, if its available. Those are much faster, but be prepared to give it some time, as even if thats uses on mgmt server upgrade, depending on the HDD size and database, it can take some time after reboot of the box.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 15:09:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161457#M28575</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-07T15:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161465#M28576</link>
      <description>&lt;P&gt;Generally, using CPUSE is fine to do the upgrade.&lt;BR /&gt;The only time I don't suggest using CPUSE (personally) is to benefit from changes that cannot be implemented through an in-place upgrade:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In R80.40, we adopted the XFS filesystem as the default.&lt;/LI&gt;
&lt;LI&gt;In R81.20, the new installer changes how disks are partitioned&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Gaia-partition-misalignment/m-p/160677#M26928" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Gaia-partition-misalignment/m-p/160677#M26928&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In both cases, a fresh install from USB/ISO is the only way to implement these changes.&lt;BR /&gt;Management benefits greatly from these changes.&lt;BR /&gt;Gateways also benefit from these changes, albeit to a lesser degreee.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 15:49:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161465#M28576</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-07T15:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161470#M28578</link>
      <description>&lt;P&gt;Hello, my friend.&lt;/P&gt;&lt;P&gt;This method you just mentioned is totally new to me.&lt;BR /&gt;I had not heard of it until now.&lt;/P&gt;&lt;P&gt;Is this method very different from the other method, in which you only work with the CPUSE package?&lt;/P&gt;&lt;P&gt;What I want is to try to minimize the risks of affecting the box I have (Standalone, R80.30), and try to "make" the task more practical.&lt;/P&gt;&lt;P&gt;Do you recommend using the "Blink Package" method, over the method of just using the "CPUSE" package?&lt;/P&gt;&lt;P&gt;Thanks for your comment&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 16:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161470#M28578</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-07T16:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161474#M28580</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Your explanation is clear, but I have a problem "interpreting" a part of your comment.&lt;/P&gt;&lt;P&gt;The part of the comment is this:&lt;/P&gt;&lt;P&gt;"...to benefit from changes that cannot be implemented through an in-place upgrade:"&lt;/P&gt;&lt;P&gt;What do you mean by this?&lt;BR /&gt;Could you maybe give me an "example" of what would be these "changes" you are referring to, to give me an idea?&lt;/P&gt;&lt;P&gt;Thanks for your support.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 16:32:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161474#M28580</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-07T16:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161477#M28581</link>
      <description>&lt;P&gt;I personally recommend "blink" package, always had success with it, except it may take longer for mgmt server, depending on how large database is. For gateways, always worked fine.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 16:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161477#M28581</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-07T16:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161491#M28582</link>
      <description>&lt;P&gt;There are two reasons I am aware of you can’t do an in-place upgrade:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You’re upgrading the hardware&lt;/LI&gt;
&lt;LI&gt;You need to change something that about the underlying filesystem and/or disk partitioning (i.e. the two specific examples I provided)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Like I said, you are welcome—and it is supported—to upgrade from R80.30 to a newer release with CPUSE.&lt;BR /&gt;You will just not obtain the benefits of the newer filesystem/partitioning unless a clean install of the relevant release is performed as part of the upgrade.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 19:38:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161491#M28582</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-07T19:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161504#M28587</link>
      <description>&lt;P&gt;The explanation is clearer to me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I still have a doubt, if I perform the UPGRADE with the FRESH INSTALL mechanism with the USB/ISO, to take it from version R80.30 to R81.10, do I have to "convert" the "policy package" of my FW that are in "Standalone (SMS+SG)" mode to work without problems in the new version, R81.10?&amp;nbsp; For example, I understand that when you need to work an UPGRADE for an SMS with the FRESH INSTALL, you have to convert the "policy package" in such a way that it is compatible with the new version. Is this correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 23:21:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161504#M28587</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-07T23:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161590#M28624</link>
      <description>&lt;P&gt;If you follow the procedure&amp;nbsp;documented in R81.10 Install and Upgrade Guide, yes, it will convert the policy configuration to the new version.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Installation_and_Upgrade_Guide/Topics-IUG/Upgrading-Mmgt-Server-or-Log-Server-from-R80_20-and-higher-with-Advanced-Upgrade.htm?tocpath=Upgrade%20of%20Security%20Management%20Servers%20and%20Log%20Servers%7CUpgrading%20a%20Security%20Management%20Server%20or%20Log%20Server%20from%20R80.20%20and%20higher%7C_____2" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Installation_and_Upgrade_Guide/Topics-IUG/Upgrading-Mmgt-Server-or-Log-Server-from-R80_20-and-higher-with-Advanced-Upgrade.htm?tocpath=Upgrade%20of%20Security%20Management%20Servers%20and%20Log%20Servers%7CUpgrading%20a%20Security%20Management%20Server%20or%20Log%20Server%20from%20R80.20%20and%20higher%7C_____2&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 15:27:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161590#M28624</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-08T15:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161734#M28668</link>
      <description>&lt;P&gt;Blink is a type of package (for fast installation of a version + Jumbo and sometimes private HFs). CPUSE is an installer, which supports "regular" packages as well as Blink packages.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Blink packages are specific to the machine role, and unfortunately Blink upgrade for Standalone are not available.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 08:07:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161734#M28668</guid>
      <dc:creator>Tsahi_Etziony</dc:creator>
      <dc:date>2022-11-10T08:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161758#M28673</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;Does it mean that doing an UPGRADE with the "methodology" of "BLINK UPGRADE" is only possible in a distributed environment (SMS and SG separately)?&lt;/P&gt;&lt;P&gt;This methodology can be done in solutions that "run" on OPEN SERVER? Or can it only be done on Checkpoint Appliances?&lt;/P&gt;&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 13:11:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161758#M28673</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-10T13:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161760#M28674</link>
      <description>&lt;P&gt;Indeed - only distributed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the methodology, just like any CPUSE package, can be used also on open servers, as long as they have a GAiA OS installed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 13:38:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161760#M28674</guid>
      <dc:creator>Tsahi_Etziony</dc:creator>
      <dc:date>2022-11-10T13:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161762#M28676</link>
      <description>&lt;P&gt;I understand.&lt;/P&gt;&lt;P&gt;In a Standalone environment, it is a criterion of the administrator, to know which methodology to use to make an UPGRADE to his solution, right?&lt;/P&gt;&lt;P&gt;I understand that the methodology would be between choosing to use a CPUSE package to upgrade the equipment, or in any case use the "ADVANCED UPGRADE", is this correct?&lt;/P&gt;&lt;P&gt;In your opinion, do you have any recommendation based on your experience?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 13:49:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161762#M28676</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2022-11-10T13:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161773#M28687</link>
      <description>&lt;P&gt;My team develops CPUSE and other tools, and I have complete faith in those. As for a recommendation based on experience - this is exactly what we have this community for, so let's see what others answer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 14:48:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161773#M28687</guid>
      <dc:creator>Tsahi_Etziony</dc:creator>
      <dc:date>2022-11-10T14:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices to perform version UPGRADE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161791#M28697</link>
      <description>&lt;P&gt;Regardless of the deployment, you should have some understanding of what upgrade method to use in your specific circumstances.&lt;BR /&gt;In general, either method will work, obviously, but the choice of which tool(s) you use will depend on:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Source/target versions involved (for example, if upgrading R77.30 to R81.10, this will require a multi-stage upgrade)&lt;/LI&gt;
&lt;LI&gt;Hardware changes (if you are changing from one appliance to another)&lt;/LI&gt;
&lt;LI&gt;You need to leverage (or make) low-level changes that can't be implemented through an in-place upgrade (the filesystem/disk partitioning issues I mentioned previously)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I've explained why I recommend using the Advanced Upgrade process for your specific situation.&lt;BR /&gt;However, you can do an in-place upgrade, but will miss out on some of the performance benefits by doing that. (The filesystem changes improve performance)&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 17:08:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-practices-to-perform-version-UPGRADE/m-p/161791#M28697</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-10T17:08:39Z</dc:date>
    </item>
  </channel>
</rss>

