<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replacing R81.20 cluster with new R82 cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258544#M50702</link>
    <description>&lt;P&gt;I would just follow below process, had done it many times, never had an issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Sep 2025 12:51:14 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-09-30T12:51:14Z</dc:date>
    <item>
      <title>Replacing R81.20 cluster with new R82 cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258540#M50700</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a pair of 5800 gateway appliance running R81.20 in HA mode. These devices go end of hardware support today (30 Sep 25) and I have a pair of new 9400 appliances due to be delivered in the next few days.&lt;/P&gt;&lt;P&gt;I anticipated that the new devices will come with R82 and so I have pre-upgraded our management from R81.20 to R82 already.&lt;/P&gt;&lt;P&gt;I know that R82 and R81.20 appliances cannot sit in the same cluster and obviously cannot have the same HA or IP addresses as the existing devices, but what I cannot find is any documentation showing the best way to replace them.&lt;/P&gt;&lt;P&gt;This is how I am planning to approach this:&lt;/P&gt;&lt;P&gt;1. Build / Install the R82 gateways with a new management address (and adding them to firewall rules).&lt;/P&gt;&lt;P&gt;2. Configure interfaces and IP addresses the same as R81.20 counterparts, leaving them disabled.&lt;/P&gt;&lt;P&gt;3. Add routing tables and Proxy ARP the same as R81.20 counterparts.&lt;/P&gt;&lt;P&gt;4. Failover 81.20 to the Secondary&lt;/P&gt;&lt;P&gt;5. Shut down the R81.20 Primary&lt;/P&gt;&lt;P&gt;6. Reset SIC on the Primary host in the cluster object&lt;/P&gt;&lt;P&gt;7. Enable interfaces on R82 Primary.&lt;/P&gt;&lt;P&gt;8. Upgrade cluster object to R82 and rest/initialise SIC for Primary host.&lt;/P&gt;&lt;P&gt;9. Push policy to individual gateways (Should work on R82 and Fail on R81.20)&lt;/P&gt;&lt;P&gt;10. Failover to R82 Primary&lt;/P&gt;&lt;P&gt;11. Repeat steps 5, 6, 7 for Secondary appliance&lt;/P&gt;&lt;P&gt;12. Push policy to gateways&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know what will happen in step 7-9 when I bring the R82 primary online. Will there be two devices trying to become ACTIVE?&lt;/P&gt;&lt;P&gt;In step 10 will I have to shut down R81.20 Secondary to get the failover to work properly?&lt;/P&gt;&lt;P&gt;I would like to hear your comments and advice on this.&lt;BR /&gt;(Thanks in advance)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 11:09:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258540#M50700</guid>
      <dc:creator>Si_Dunford</dc:creator>
      <dc:date>2025-09-30T11:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing R81.20 cluster with new R82 cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258544#M50702</link>
      <description>&lt;P&gt;I would just follow below process, had done it many times, never had an issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 12:51:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258544#M50702</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-30T12:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing R81.20 cluster with new R82 cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258546#M50703</link>
      <description>&lt;P&gt;What a timely post! I am doing the exact same thing with the same old and new hardware as you in about a month.&lt;/P&gt;&lt;P&gt;I had to change some interface names because we are using more 10 gig interfaces and the old fw we used none.&lt;/P&gt;&lt;P&gt;Good luck to us both!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 13:00:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258546#M50703</guid>
      <dc:creator>vobryan</dc:creator>
      <dc:date>2025-09-30T13:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing R81.20 cluster with new R82 cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258556#M50704</link>
      <description>&lt;P&gt;I found same process I linked worked well even for R82.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 13:14:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258556#M50704</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-30T13:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing R81.20 cluster with new R82 cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258575#M50708</link>
      <description>&lt;P&gt;Thanks, this is fairly similar to the approach I was planning... will report back when completed.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 14:16:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258575#M50708</guid>
      <dc:creator>Si_Dunford</dc:creator>
      <dc:date>2025-09-30T14:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing R81.20 cluster with new R82 cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258576#M50709</link>
      <description>&lt;P&gt;Exactly! The best part is you dont need to worry about MVC feature, since its automatically enabled since R80.40&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 14:19:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258576#M50709</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-30T14:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing R81.20 cluster with new R82 cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258579#M50712</link>
      <description>&lt;P&gt;I don't have a delivery date for our replacement yet, but hope yours goes well...&lt;BR /&gt;We are moving up to 10G interfaces from 1G too, but in our case we bond them and add VLAN subinterfaces so the bond and the subinterface names will remain the same; only the bond members will be changing.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 14:35:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258579#M50712</guid>
      <dc:creator>Si_Dunford</dc:creator>
      <dc:date>2025-09-30T14:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing R81.20 cluster with new R82 cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258580#M50713</link>
      <description>&lt;P&gt;Just make sure if say sync interface would be different link/speed, something to keep in mind, as thats important.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Sep 2025 14:39:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Replacing-R81-20-cluster-with-new-R82-cluster/m-p/258580#M50713</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-30T14:39:39Z</dc:date>
    </item>
  </channel>
</rss>

