<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No Downtime (Zero Downtime) hardware refresh in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235549#M45658</link>
    <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;I need an advice from you, experts!&lt;BR /&gt;One of my customers is going to upgrade some 5000 something gateways in a classic HA&amp;nbsp; A-P cluster&amp;nbsp; to some brand new 9400 gateways.&lt;/P&gt;&lt;P&gt;How in the world can I do this with zero downtime without messing with SND cores (as there's no way to revert back to 20/24 cores (or how many 9400 has) without , again, downtime!vI mean I could just&amp;nbsp; change the number of SND cores to one 9400,&amp;nbsp; join it in cluster&amp;nbsp; (5x00 + 9400 with lowered cores) and it will be just fine, but errr ... my brain is in a boot loop and I can't figure it out!&lt;/P&gt;&lt;P&gt;The only way I see it is to remove standby member of actual 5000 cluster,&amp;nbsp; add the new 9400 gateway and try to be flash fast to disable clusterXL on 5000 when 9400 becomes active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas ? (will be highly appreciated).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 17:36:29 GMT</pubDate>
    <dc:creator>melcu</dc:creator>
    <dc:date>2024-12-12T17:36:29Z</dc:date>
    <item>
      <title>No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235549#M45658</link>
      <description>&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;I need an advice from you, experts!&lt;BR /&gt;One of my customers is going to upgrade some 5000 something gateways in a classic HA&amp;nbsp; A-P cluster&amp;nbsp; to some brand new 9400 gateways.&lt;/P&gt;&lt;P&gt;How in the world can I do this with zero downtime without messing with SND cores (as there's no way to revert back to 20/24 cores (or how many 9400 has) without , again, downtime!vI mean I could just&amp;nbsp; change the number of SND cores to one 9400,&amp;nbsp; join it in cluster&amp;nbsp; (5x00 + 9400 with lowered cores) and it will be just fine, but errr ... my brain is in a boot loop and I can't figure it out!&lt;/P&gt;&lt;P&gt;The only way I see it is to remove standby member of actual 5000 cluster,&amp;nbsp; add the new 9400 gateway and try to be flash fast to disable clusterXL on 5000 when 9400 becomes active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas ? (will be highly appreciated).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 17:36:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235549#M45658</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-12-12T17:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235552#M45659</link>
      <description>&lt;P&gt;I would follow below process. I had done it many times and no issues,&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/157228#M27268" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/157228#M27268&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 17:52:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235552#M45659</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T17:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235559#M45660</link>
      <description>&lt;P&gt;Hey Andy.&lt;/P&gt;&lt;P&gt;I know about that but I was thinking about something like "mvc" but for hardware. Beliveit or not, but the customer doesn't want a single packet or session to be lost &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp; Difficult one but it is what it is.&lt;/P&gt;&lt;P&gt;I already did this once with messing up the SND cores but it was a cluster with 7000 gateways doing about 2Mbps with "peak" at 8Mbps :))) I could afford to have 2 SND cores for everything.&lt;/P&gt;&lt;P&gt;This one is different though .. 5400's CPUs are screaming so I cannot mess with 9400 SND.&lt;/P&gt;&lt;P&gt;I think I will let them know that there will a little outage and that's it. Move traffic to the other site and do the hardware upgrade.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 18:24:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235559#M45660</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-12-12T18:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235561#M45661</link>
      <description>&lt;P&gt;Sadly, I doubt anyone can guarantee them they would not lose a single packet. Last time I did this, no packets were lots, though I always see one time out when we run constant ping.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 18:28:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235561#M45661</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T18:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235564#M45662</link>
      <description>&lt;P&gt;I agree with Andy, we promise always 99,999% only.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 18:49:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235564#M45662</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-12-12T18:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235566#M45663</link>
      <description>&lt;P&gt;I think there is a saying in North America (well maybe more specifically USA, not sure here in Canada), but I think it says "Only 2 things in life are guaranteed...taxes and death". Though, thats true no matter where in the world you go lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 18:51:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235566#M45663</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T18:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235568#M45664</link>
      <description>&lt;P&gt;Haha! That's a really good one!&lt;/P&gt;&lt;P&gt;Indeed, I've messed up a whole cluster in the middle of the day with a simple accelerated policy installation. Both members rebooted (kernel panic) at the same time! So .. nothing is guaranteed (beside what you've already indicated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 18:53:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235568#M45664</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-12-12T18:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235569#M45665</link>
      <description>&lt;P&gt;What was the version?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 18:55:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235569#M45665</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-12-12T18:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235570#M45666</link>
      <description>&lt;P&gt;Lets see...I messed up in the past with Fortinet, Palo Alto, Cisco, Check Point, haha. If life was perfect, none of us would have these jobs lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 18:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235570#M45666</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T18:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235571#M45667</link>
      <description>&lt;P&gt;some R81 (not R81.x0 .. just R81) .. ancient times &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; First time when Accelerated Policy was implemented.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 18:57:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235571#M45667</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-12-12T18:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235574#M45669</link>
      <description>&lt;P&gt;As another saying goes "No point crying over spilled milk" as in to say all we can do is learn from our mistake and not repeat it again.&lt;/P&gt;
&lt;P&gt;Thats it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 19:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235574#M45669</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T19:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235580#M45671</link>
      <description>&lt;P&gt;What is current version on 5000 cluster ?&lt;/P&gt;
&lt;P&gt;If 9400 appliance has more cores than 5000 one, it should be better way to go. If naming of all configured interfaces will match between old and new member, then you should be able to disconnect old standby member from cluster (cpstop and/or shut all ports), connect new 9400 member, reset SIC, push policy and should go into standby state.&lt;/P&gt;
&lt;P&gt;You can also disable checking out-of-state packets in Global Properties during the initial first failover.&lt;/P&gt;
&lt;P&gt;Best option is to have new 9400 member configured in advance while using new cablings and do not play with cables during the change window. You will simple have new 9400 member cabled, but ports on switch (or fw) should be disabled/enabled depending where you want to work (old vs new member). During the replacement change itself you will just shut all ports on old member, enable on new member and thats it.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 20:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235580#M45671</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-12-12T20:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235583#M45673</link>
      <description>&lt;P&gt;It is wise to not guarantee zero downtime for such a swap.&lt;/P&gt;
&lt;P&gt;For awareness the devices also operate with different SecureXL modes by default.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 21:27:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235583#M45673</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-12-12T21:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235584#M45674</link>
      <description>&lt;P&gt;Agree 100% &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 21:31:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235584#M45674</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T21:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235585#M45675</link>
      <description>&lt;P&gt;Since I literally keep all my emails and notes from ages ago, I checked one case back with a client in R76 days and they asked the TAC this same question...how to ensure they would not lose a single packet. Answer from TAC was that there was no one in Check Point that could give them guarantee for something like that.&lt;/P&gt;
&lt;P&gt;Im 100% positive that even if you opened a case now days and ask them this, they would most likely tell you the same.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 23:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235585#M45675</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-12T23:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235613#M45684</link>
      <description>&lt;P&gt;I see there are lots of opinions already expressed here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just want to add a note from my personal experience. Even if you are confident you can perform an upgrade or HW migration with only minimal downtime, announce an extended service window interruption beforehand. Unexpected happens, even to the best of us.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It is always better to tell the business there will be a service interruption and manage the procedure without it than hope for the best and miss it because of a random contingency.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 08:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235613#M45684</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-12-13T08:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235615#M45685</link>
      <description>&lt;P&gt;Hey Val&lt;/P&gt;&lt;P&gt;Of course!&amp;nbsp; My usual window for this kind of stuff is 30 minutes and I like to tell my customers that even if I know everything will go smooth they still have to be aware that a full outage may occur in this time frame.&lt;/P&gt;&lt;P&gt;I did lots of replacements but this is the second time when I am asked to have "no downtime". It worked once &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; messing with SND cores&amp;nbsp; but now it's not possible due to high traffic passing the gateways.&lt;/P&gt;&lt;P&gt;So in the end customer has to be aware that even a policy installation can go wrong!&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 08:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235615#M45685</guid>
      <dc:creator>melcu</dc:creator>
      <dc:date>2024-12-13T08:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235657#M45693</link>
      <description>&lt;P&gt;I would say 30 mins is a bit too short, maybe at least 60, or even 90 mins if possible.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 12:09:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235657#M45693</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-13T12:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: No Downtime (Zero Downtime) hardware refresh</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235659#M45694</link>
      <description>&lt;P&gt;I agree with Andy, and don't forget the revert process, and its time consumption.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you stuck somewhere in the process (15min)-&amp;gt; you start to debug (30min) -&amp;gt; no success -&amp;gt; decision point (10min)- &amp;gt; decide by revert -&amp;gt; the revert process (30 min)&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 12:14:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/No-Downtime-Zero-Downtime-hardware-refresh/m-p/235659#M45694</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-12-13T12:14:12Z</dc:date>
    </item>
  </channel>
</rss>

