<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issues Replacing/Upgrading Appliances in H/A Cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/252061#M49364</link>
    <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;How did it go last night? Did&amp;nbsp; not see email from you, though I stayed up till 1 am just in case you needed help, so hope no news is GOOD news? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jun 2025 14:12:17 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-06-26T14:12:17Z</dc:date>
    <item>
      <title>Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251811#M49288</link>
      <description>&lt;P&gt;I currently have two 6600s in a H/A cluster. I am replacing these two appliances with two 9100s. Below is my current plan of attack, but I run into issues and cannot establish SIC on the second appliance and DNS stops resolving (Step 7).&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Make sure FW-01 is active.&lt;/LI&gt;&lt;LI&gt;Unplug cables from the standby 6600 (FW-02).&lt;/LI&gt;&lt;LI&gt;Connect the cables to the new 9100 as the standby member with same settings as FW-02.&lt;/LI&gt;&lt;LI&gt;Install SIC, change cluster version, and install policy removing the check box.&lt;/LI&gt;&lt;LI&gt;Unplug cables from the active 6600 (FW-01).&lt;OL&gt;&lt;LI&gt;The 9100 (FW-02) becomes active. &lt;EM&gt;(DNS stops resolving at this point. I can reach internal and external IPs from the appliance itself while I am consoling in, but not from a laptop hardwired into the network).&lt;/EM&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Connect the new 9100 with the same settings as FW-01.&lt;/LI&gt;&lt;LI&gt;Install SIC, and install policy &lt;U&gt;adding&lt;/U&gt; the check box.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;SIC will not install on the second replacement. I have tried rebooting and running fw unloadlocal. DNS &lt;U&gt;&lt;STRONG&gt;does not&lt;/STRONG&gt;&lt;/U&gt; resolve at this point and I am forced to revert.&lt;/P&gt;&lt;P&gt;Attached is what I see in SC for the first replacement (FW-02).&lt;/P&gt;&lt;P&gt;Does anyone see anything glaringly obvious?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 20:56:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251811#M49288</guid>
      <dc:creator>cmale</dc:creator>
      <dc:date>2025-06-23T20:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251845#M49296</link>
      <description>&lt;P&gt;Do both the old and new cluster nodes have the same Version and Jumbo Take installed ? If not, you have to use MVC during change.&lt;/P&gt;
&lt;P&gt;Also see here:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/69325#M5302" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/m-p/69325#M5302&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Migrating-cluster-from-old-to-new-hardware/m-p/11364#M717" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Migrating-cluster-from-old-to-new-hardware/m-p/11364#M717&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 08:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251845#M49296</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-06-24T08:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251864#M49309</link>
      <description>&lt;P&gt;Same version, yes. I will have to double check the Jumbo Take. I did not mention that I plan to reuse IP addresses for the two appliances as well as hostnames. Those are already changed. I just plan to take down the standby, bring up the new replacement (with same IP and hostname). I am using the same cluster.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 11:41:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251864#M49309</guid>
      <dc:creator>cmale</dc:creator>
      <dc:date>2025-06-24T11:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251915#M49333</link>
      <description>&lt;P&gt;That should be totally fine. As I mentioned in the other post where you initially asked about this issue, did you make sure 100% that routes are the same and sic port is communicating?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 18:09:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251915#M49333</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-24T18:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251917#M49335</link>
      <description>&lt;P&gt;I will verify tomorrow evening during my scheduled maintenance window. One thing I did not double check are the interfaces and topology when I had the new appliances up, although I did set up everything in GAIA that way it was set up for the current 6600s. I will keep you posted.&lt;/P&gt;&lt;P&gt;These settings should carry over if I am using the same cluster as the 6600s, though, correct? Or would they change after I bring the 9100s up?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 18:47:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251917#M49335</guid>
      <dc:creator>cmale</dc:creator>
      <dc:date>2025-06-24T18:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251918#M49336</link>
      <description>&lt;P&gt;Here is what I ALWAYS do with customers and never had a problem. So you generate clish config in a file, say for example from current fw in expert (say if its master, though name can be anything) -&amp;gt; clish -c "show configuration" &amp;gt; /var/log/masterfwconfig.txt&lt;/P&gt;
&lt;P&gt;Get it off fw from winscp (you can enable ot by changing admin shell to bin bash with command chsh -s /bin/bash admin) and once you have the file downloaded, copy bits and pieces until donw to clish of new fw, just ommit parts say for mgmt interface, unless you have constant console to it, and you dont care for web UI access till its cutover. Then, manually download recommended jumbo from cp site, install it, reboot, then ENSURE config matches from existing to new fw by getting config file with same command and comparing the differences (you can do this in notepad++ or even compare it free download tool).&lt;/P&gt;
&lt;P&gt;If this matches, there is no way you would have any problems, trust me. I had done this too many times not to be confident 100% in the process.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 19:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251918#M49336</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-24T19:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251920#M49337</link>
      <description>&lt;P&gt;Thank you. I will give this a try.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 19:41:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251920#M49337</guid>
      <dc:creator>cmale</dc:creator>
      <dc:date>2025-06-24T19:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251921#M49338</link>
      <description>&lt;P&gt;Please be free to message me directly if any issues, Im confident I can help you if you get stuck.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 19:42:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251921#M49338</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-24T19:42:19Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251939#M49344</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Try to check from the CLI with cphaprob command. If no problem detected, mostly is the management cache unable to be cleared and not updating to the latest status from the gateway.&lt;/P&gt;&lt;P&gt;Or else, a deep configuration verification is required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;CM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 06:18:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/251939#M49344</guid>
      <dc:creator>garrod</dc:creator>
      <dc:date>2025-06-25T06:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/252061#M49364</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;How did it go last night? Did&amp;nbsp; not see email from you, though I stayed up till 1 am just in case you needed help, so hope no news is GOOD news? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 14:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/252061#M49364</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-26T14:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Issues Replacing/Upgrading Appliances in H/A Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/252074#M49365</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/97363"&gt;@cmale&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I REALLY would love to help you get this working, so since you got my contact, please message me when you try this again tonight. Or, if you are around later, say 2 pm or so, we can have quick zoom meeting to go over things.&lt;/P&gt;
&lt;P&gt;Let me know your thoughts.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 15:44:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issues-Replacing-Upgrading-Appliances-in-H-A-Cluster/m-p/252074#M49365</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-26T15:44:35Z</dc:date>
    </item>
  </channel>
</rss>

