<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failed to upgrade checkpoint 6200P from r81.10 to r81.20 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225247#M43331</link>
    <description>&lt;P&gt;Hi checkmates !&lt;/P&gt;&lt;P&gt;Greetings !&lt;/P&gt;&lt;P&gt;Recently, we had planned to upgrade 6200 security gateway from r81.10 to r81.20 but we could not do that. We followed below steps:&lt;/P&gt;&lt;P&gt;1. Downloaded the checkpoint major version upgrade package from status and Action&amp;gt;packages&lt;/P&gt;&lt;P&gt;2. Verified the packages&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Displayed install and upgrade allowed was shown but below that i noticed install allowed section.&lt;/P&gt;&lt;P&gt;4. Proceed with upgrade option&lt;/P&gt;&lt;P&gt;5. Device reboots, all network goes down&lt;/P&gt;&lt;P&gt;5. Failed to open gaia portal or management network or any network that was passing through that gateway.&lt;/P&gt;&lt;P&gt;6. Used console cable to see the version shows r81.20 with warnings&lt;/P&gt;&lt;P&gt;I revert back using autosnapshot and the connectivity was restored, don't know what happened or what did i miss here. i observed same thing in my perimeter device as well the device was successfully upgraded but other internal network were not able to reach internet, while checkpoint itself was able to reach internet.&lt;/P&gt;&lt;P&gt;I revert it back and the all device were able to reach internet, If someone had faced same issue with 6200 device. please let me know. what did i miss or what was wrong in this scenario.&lt;/P&gt;&lt;P&gt;The management server which was in vm was only successfully upgraded following the same steps.&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;Rabindra&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 01 Sep 2024 07:19:12 GMT</pubDate>
    <dc:creator>Rabin</dc:creator>
    <dc:date>2024-09-01T07:19:12Z</dc:date>
    <item>
      <title>Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225247#M43331</link>
      <description>&lt;P&gt;Hi checkmates !&lt;/P&gt;&lt;P&gt;Greetings !&lt;/P&gt;&lt;P&gt;Recently, we had planned to upgrade 6200 security gateway from r81.10 to r81.20 but we could not do that. We followed below steps:&lt;/P&gt;&lt;P&gt;1. Downloaded the checkpoint major version upgrade package from status and Action&amp;gt;packages&lt;/P&gt;&lt;P&gt;2. Verified the packages&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Displayed install and upgrade allowed was shown but below that i noticed install allowed section.&lt;/P&gt;&lt;P&gt;4. Proceed with upgrade option&lt;/P&gt;&lt;P&gt;5. Device reboots, all network goes down&lt;/P&gt;&lt;P&gt;5. Failed to open gaia portal or management network or any network that was passing through that gateway.&lt;/P&gt;&lt;P&gt;6. Used console cable to see the version shows r81.20 with warnings&lt;/P&gt;&lt;P&gt;I revert back using autosnapshot and the connectivity was restored, don't know what happened or what did i miss here. i observed same thing in my perimeter device as well the device was successfully upgraded but other internal network were not able to reach internet, while checkpoint itself was able to reach internet.&lt;/P&gt;&lt;P&gt;I revert it back and the all device were able to reach internet, If someone had faced same issue with 6200 device. please let me know. what did i miss or what was wrong in this scenario.&lt;/P&gt;&lt;P&gt;The management server which was in vm was only successfully upgraded following the same steps.&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;Rabindra&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 07:19:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225247#M43331</guid>
      <dc:creator>Rabin</dc:creator>
      <dc:date>2024-09-01T07:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225248#M43332</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/104214"&gt;@Rabin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Without logs, the investigation almost is impossible. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But no worries, we try to give tips and trick for the next time:&lt;/P&gt;
&lt;P&gt;DAagent:&lt;/P&gt;
&lt;P&gt;the DAagent was updated to the latest version?&lt;/P&gt;
&lt;P&gt;Collect the Deployment agent logs use this command da_cli collect_logs -&amp;gt;check it, maybe there is any nasty in it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk92449" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk92449&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The install logs are here:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;/var/log/install_Major_R81.20_ivory_main_T631_detailed.log&lt;/P&gt;
&lt;P&gt;And also a lot of log here: /opt/CPInstLog/&lt;/P&gt;
&lt;P&gt;You wrote this "&lt;SPAN&gt;Used console cable to see the version shows r81.20 with warnings"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What were the warnings?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Sun, 01 Sep 2024 11:27:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225248#M43332</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-01T11:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225250#M43333</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You for the response, the&amp;nbsp;&lt;SPAN&gt;Deployment Agent build was: 2443&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp; and the device which did not come had warnings, i used show version all command, and the output was r81.20 with warning the device was not upgraded fully something like that, and&amp;nbsp; as you mentioned the logs, i&amp;nbsp;&lt;/SPAN&gt;have those&amp;nbsp;&lt;SPAN&gt;install_Major_R81.20_ivory_main_T631_detailed.log&lt;/SPAN&gt;&amp;nbsp; logs. Can you give what had happened by analysing it or should i open case for TAC and to add i also noticed there are no core dumps generated.&lt;/P&gt;&lt;P&gt;Thank You.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 09:10:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225250#M43333</guid>
      <dc:creator>Rabin</dc:creator>
      <dc:date>2024-09-01T09:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225258#M43336</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/104214"&gt;@Rabin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hard to reprodicate the issue in my&amp;nbsp; head, but from this:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"r81.20 with warning the device was not upgraded fully.... "&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;I conclude that, the post installations scripts, which run after there reboot didn't finished.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How much time had passed betwen the reboot, and the revert?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you open a TAC case, the TAC wants a session where you can do the upgrade again.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 11:27:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225258#M43336</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-01T11:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225259#M43337</link>
      <description>&lt;P&gt;Can you list EXACT steps you followed to upgrade? Is it just single fw or cluster? Either way, you would need to check fw stat after reboot, as it may load initial policy, which blocks everything, except local ssh and web ui on port 443. Also, version in smart console object would need to be updated.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 11:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225259#M43337</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-01T11:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225260#M43338</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/104214"&gt;@Rabin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And one more thing. If you have time, do this upgrade in LAB. I mean that, install an R81.10, then upgrade it.&amp;nbsp; I always did this if I had time.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 11:19:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225260#M43338</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-01T11:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225261#M43339</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You for the guidance, I have upgraded the checkpoint firewall in lab from r81.10 to r81.20 in vm. I had upgraded in different version and model in production environment too but with only difference was from r80.30 or r80.40 to r81.10 upgrade path in different model device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could not find out what, why this upgrade was unsuccessful, as it was not even in cluster but in standalone deployment.&lt;/P&gt;&lt;P&gt;Rabindra&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 11:41:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225261#M43339</guid>
      <dc:creator>Rabin</dc:creator>
      <dc:date>2024-09-01T11:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225262#M43340</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was in single fw and to check the firewall status after reboot, there was not reachability or any services up, no ssh, no web ui, after system went down for reboot, we waited long enough to finalize it had some issue and&amp;nbsp; we rushed to datacenter and through console, we revert it back using autosnapshot and the service was restored.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The steps taken were:-&lt;/P&gt;&lt;P&gt;1. Take backup and snapshots&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Fetch updates from checkpoint cloud through cpuse&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Verified the deployment agent was latest&lt;/P&gt;&lt;P&gt;3. Verified the recommended package, clean install and upgrade was allowed.&lt;/P&gt;&lt;P&gt;4. Clicked upgrade&lt;/P&gt;&lt;P&gt;5. And monitor the system, system went down for reboot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rabindra&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 11:56:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225262#M43340</guid>
      <dc:creator>Rabin</dc:creator>
      <dc:date>2024-09-01T11:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225263#M43341</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/104214"&gt;@Rabin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case there are two ways:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Open a TAC Case, arrange a maintanace window, and wait for the date.&amp;nbsp; (of course on-site)&lt;/LI&gt;
&lt;LI&gt;Such strange things happen. I can list a lot of interesting things, which solution was to reinstall the GW from scratch, and (re)SIC it with the MGMT.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The second solution based on my experience. I can be fast. The disadvantage is that, we didn't find the exact solution or the root cause of the issue.&lt;/P&gt;
&lt;P&gt;And one more: Does the GW have LOM?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 11:59:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225263#M43341</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-01T11:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to upgrade checkpoint 6200P from r81.10 to r81.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225269#M43347</link>
      <description>&lt;P&gt;Sounds like for some reason, though I cant say for sure, may had loaded whats called default filter policy, which would have blocked EVERYTHING.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 13:54:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Failed-to-upgrade-checkpoint-6200P-from-r81-10-to-r81-20/m-p/225269#M43347</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-01T13:54:53Z</dc:date>
    </item>
  </channel>
</rss>

