<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: speed up VSX upgrade R81.10 =&amp;gt; R81.20 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223499#M42859</link>
    <description>&lt;P&gt;Just had a thought. The 15600 shipped with spinning rust by default. Most of my VSX systems have SSDs. I would expect dealing with each VS to involve a lot of small-file operations, so that could make a pretty big difference in upgrade duration.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2024 13:58:24 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2024-08-13T13:58:24Z</dc:date>
    <item>
      <title>speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223481#M42852</link>
      <description>&lt;P&gt;Recently we upgraded a VSX cluster from R81.10 to R81.20. Everything was fine, no problems, no connections broken. Main problem was the time it took to upgrade the whole cluster. Some log reading und investigation shows that the upgrade procedure was running about 20 minutes for every virtual system, regardless if this was only a virtual switch, - router or a virtual firewall.&lt;/P&gt;
&lt;P&gt;We are on the way to upgrade another system with about 20 virtual systems. Any ideas to speed up this upgrade process ? The expected timeline will expand our maintenance schedule.&lt;/P&gt;
&lt;P&gt;The upgrade was done on a pair of 15600 appliances with no CPU utilization problems.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 13:24:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223481#M42852</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-08-13T13:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223485#M42853</link>
      <description>&lt;P&gt;Which part took the time? The vsx_util upgrade on the management, or actually upgrading the members?&lt;/P&gt;
&lt;P&gt;If it was the vsx_util upgrade, you can kick that off several hours ahead of your upgrade window. It's just updating the management database and rebuilding all of the policies.&lt;/P&gt;
&lt;P&gt;If the part which took all the time was actually upgrading the members, what upgrade method did you use?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 13:36:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223485#M42853</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-08-13T13:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223490#M42855</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;upgrading the members was the problematic long running part. We did a "&lt;FONT size="4"&gt;Multi-Version Cluster&amp;nbsp;(MVC) upgrade&lt;/FONT&gt;"&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 13:46:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223490#M42855</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-08-13T13:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223496#M42857</link>
      <description>&lt;P&gt;In-place ('installer upgrade'), or did you do a clean install then reprovision? The latter is how I do most VSX upgrades (including some R81.10 to R81.20), and they're consistently pretty fast.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 13:54:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223496#M42857</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-08-13T13:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223499#M42859</link>
      <description>&lt;P&gt;Just had a thought. The 15600 shipped with spinning rust by default. Most of my VSX systems have SSDs. I would expect dealing with each VS to involve a lot of small-file operations, so that could make a pretty big difference in upgrade duration.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 13:58:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223499#M42859</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-08-13T13:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223501#M42860</link>
      <description>&lt;P&gt;We did an inplace upgrade. I think "&lt;SPAN&gt;clean install then reprovision&lt;/SPAN&gt;" will be much faster. But our next system to upgrade will be a Maestro/VSX environment and I don't know this will be possible?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 14:01:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223501#M42860</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-08-13T14:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223547#M42875</link>
      <description>&lt;P&gt;We tend to do in-place upgrade of VSX R81.10 to R81.20 with Blink and MVC and as you mention it works well.&lt;/P&gt;
&lt;P&gt;Our preferred methods of upgrading VSX is normally format and reconfigure. However with R81.20 management, we encounter quite frequently the issue that it fails at the end with "Operation ended with errors" and the workaround is to run "reset_gw" on the member that was formatted and restart the vsx_util procedure. This always works on the second run.&lt;/P&gt;
&lt;P&gt;So we gave a shot to Blink and it went perfectly fine.&lt;/P&gt;
&lt;P&gt;With large systems, running this twice takes a lot of time even on modern appliances.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 20:49:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223547#M42875</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-08-13T20:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223553#M42880</link>
      <description>&lt;P&gt;The other thing thing about using the Blink files for in-place upgrades is that there are a number of boot time fixes in the JHF that will be included, plus you don't then have to do a separate JHF install afterwards.&lt;/P&gt;
&lt;P&gt;Unfortunately there's not a lot we can do about slow HDDs if that's what's in the boxes but at least using Blink is something.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 02:05:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223553#M42880</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-08-14T02:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: speed up VSX upgrade R81.10 =&gt; R81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223578#M42886</link>
      <description>&lt;P&gt;We used the blink image with included JHF, as a result no extra reboots are needed. The timesteps of the logfiles shows the time needed for upgrading&amp;nbsp; a VS (see attached screenshot). There was no high disk utilization during the upgrade process, but maybe this is the limitation.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="R81.20_install.log.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27235i0C042DF9CDB1656B/image-size/large?v=v2&amp;amp;px=999" role="button" title="R81.20_install.log.png" alt="R81.20_install.log.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 07:28:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/speed-up-VSX-upgrade-R81-10-gt-R81-20/m-p/223578#M42886</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-08-14T07:28:58Z</dc:date>
    </item>
  </channel>
</rss>

