<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterXL - moving to newer appliances in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255463#M49978</link>
    <description>&lt;P&gt;Not necessarily. The Where Used dialog has a "Replace" button in the upper right. Hit that and you can replace the old object with the new object in rules and group memberships. You'll still have some manual cleanup to do, though. This can't replace the cluster in a policy package's Installation Targets, in threat prevention update schedules, and a bunch of other places.&lt;/P&gt;
&lt;P&gt;This is part of why I really dislike replacing a cluster with a whole new cluster. I greatly prefer having the new members take over the old objects. There's a lot less to go wrong.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Aug 2025 20:55:35 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2025-08-19T20:55:35Z</dc:date>
    <item>
      <title>ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255437#M49970</link>
      <description>&lt;P&gt;Hi mates,&lt;/P&gt;
&lt;P&gt;I'm moving from 6900 to 9300 appliances.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Option A&lt;/P&gt;
&lt;P&gt;I plan to add one of the 9300 appliances in as a 3rd member.&amp;nbsp; &amp;nbsp; Then, remove one of the 6900s as a member.&amp;nbsp; &amp;nbsp;None of these licenses specify active vs standby node (HA).&amp;nbsp; &amp;nbsp; Will I be able to push policy to the three members ok?&amp;nbsp; &amp;nbsp;This is clusterXL not the newer ElasticXL.&amp;nbsp; Then, do the same for the other 6900.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Option B&lt;/P&gt;
&lt;P&gt;Push policy to the new cluster.&amp;nbsp; Shutdown the old cluster.&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 15:51:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255437#M49970</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-08-19T15:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255444#M49971</link>
      <description>&lt;P&gt;I would just shut down one of the 6900s, build the new 9300, establish SIC, push policy (should work, as long as they're running the same version), then fail over (this will involve a hard outage, since the 6900 and 9300 almost certainly won't sync) and repeat the process.&lt;/P&gt;
&lt;P&gt;You &lt;EM&gt;could&lt;/EM&gt; add it as a third member, but that seems like a lot of headache to me for very little benefit. That method would also involve a hard outage when you fail to a 9300 for the first time.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 16:27:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255444#M49971</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-08-19T16:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255452#M49972</link>
      <description>&lt;P&gt;I would 100% go with option B, sounds way safer to me. Yes, option 1 would PROBABLY work, but bit risky and most likely not supported.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 19:47:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255452#M49972</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-19T19:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255453#M49973</link>
      <description>&lt;P&gt;I've done option B and I'll go with that again.&amp;nbsp; But I think option A would work fine too.&amp;nbsp; &amp;nbsp;Thanks all.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 19:49:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255453#M49973</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-08-19T19:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255454#M49974</link>
      <description>&lt;P&gt;I just checked and says that gateways of different hardware models are NOT supported. ie you cant mix and match say 6900 and 9300 in clusterXL config...would it work? Maybe, but why even bother if its not officially supported? : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 19:53:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255454#M49974</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-19T19:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255455#M49975</link>
      <description>&lt;P&gt;6900 and 9300 cannot sync each other ? Even if both are running the same version and Jumbo ? At least R81.20 minimal Take 14 where MVC is enabled by default ?&lt;/P&gt;
&lt;P&gt;Not sure how sync works between cluster members running different Firewall Modes (USFW vs. KSFW) and different SecureXL Modes (UPPAK vs. KPPAK).&lt;/P&gt;
&lt;P&gt;Different number of cores shouldnt be an issue with enabled MVC.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 19:55:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255455#M49975</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2025-08-19T19:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255456#M49976</link>
      <description>&lt;P&gt;I only tested cross-CoreXL-topology sync with MVC back in the R80.20 days, and it did not allow machines with different CoreXL topologies to sync at the time. If that has changed, it wouldn't exactly surprise me, but this is the first I've heard about it.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 20:16:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255456#M49976</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-08-19T20:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255460#M49977</link>
      <description>&lt;P&gt;So, my current cluster object&amp;nbsp; ROCK_on with the 6900s is used in 103 objects and 143 policies.&amp;nbsp; &amp;nbsp; If I&amp;nbsp; rename my old cluster object&amp;nbsp; ROCK_on to ROCK_off, then those objects and polices will all be set to Rock_off which doesn't help.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Then, if I rename my new blackROCK cluster object to ROCK_on it won't accomplish anything.&amp;nbsp; &amp;nbsp;I will need to manually change all those objects and policies to blackROCK?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 20:29:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255460#M49977</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2025-08-19T20:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255463#M49978</link>
      <description>&lt;P&gt;Not necessarily. The Where Used dialog has a "Replace" button in the upper right. Hit that and you can replace the old object with the new object in rules and group memberships. You'll still have some manual cleanup to do, though. This can't replace the cluster in a policy package's Installation Targets, in threat prevention update schedules, and a bunch of other places.&lt;/P&gt;
&lt;P&gt;This is part of why I really dislike replacing a cluster with a whole new cluster. I greatly prefer having the new members take over the old objects. There's a lot less to go wrong.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 20:55:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255463#M49978</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-08-19T20:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL - moving to newer appliances</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255468#M49981</link>
      <description>&lt;P&gt;Good point about replacing.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2025 23:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ClusterXL-moving-to-newer-appliances/m-p/255468#M49981</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-19T23:27:35Z</dc:date>
    </item>
  </channel>
</rss>

