<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VSX appliance upgrade to R80.40 T78 - first impressions in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99930#M8699</link>
    <description>&lt;P&gt;My usual "morning after" report, in case it might help some one.&lt;/P&gt;
&lt;P&gt;We were on R80.30 T215 before upgrade running on 23800 appliances that was NOT hyperthreaded before upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Good stuff:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Really impressed with CPUSE CLI upgrade! Especially considering the complexity - kernel upgrade from 2.6 to 3.10, enabling hyper-threading etc. Well done Checkpoint! I used&amp;nbsp;&lt;STRONG&gt;Multi-Version Cluster (MVC) Upgrade&lt;/STRONG&gt; option and it worked like a charm - connections synchronised in the cluster and I was able to failover one VS at a time.&lt;/P&gt;
&lt;P&gt;Why did we decided against clean install and vsx_util reconfigure?&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;easier rollback on the gateway as file system remains EXT3 you are able to use snapshots created prior R80.40. With clean install file system would change to XFS therefore snapshot revert would not work&lt;/LI&gt;
&lt;LI&gt;no need to take care of any customisations i.e.:
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;manual CoreXL settings&lt;/LI&gt;
&lt;LI&gt;non-default IA settings&lt;/LI&gt;
&lt;LI&gt;scripts&lt;/LI&gt;
&lt;LI&gt;contents of user folders&lt;/LI&gt;
&lt;LI&gt;SSH keys and known hosts used by external monitoring&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So actual upgrade was a breeze I have to admit!&lt;/P&gt;
&lt;P&gt;I do not want to celebrate too early but first indications are that our RX-DRP issues might be cured with a better MQ implementation in 3.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Potential show-stoppers or things you will need to take care of:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;User &lt;STRONG&gt;crontab&lt;/STRONG&gt; is reset, so you will have to add it back manually. For us it's a normal procedure anyways for any upgrade, but be mindful&lt;/LI&gt;
&lt;LI&gt;Not 100% sure but for some reason on one box we saw &lt;STRONG&gt;IA nested groups&lt;/STRONG&gt; reset to default setting of 20. We have it disabled. Just check it if you have customised it from 20. This is to deal with high CPU utilisation by pdpd&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Interface RX ring buffer&lt;/STRONG&gt; settings were defaulted during upgrade. We were forced to increase it in R80.30 due to noticeable RX-DRP presence that affected Teams voice&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;SNMP v3&lt;/STRONG&gt; stopped working after upgrade leaving us pretty much blind without any graphs to assess R80.40 performance properly. Major problem if you ask me. &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9754"&gt;@Friedrich_Recht&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":flexed_biceps:"&gt;💪&lt;/span&gt; saved my night - here's link to the&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/VSX/R80-40-snmpv3/m-p/91926#M953" target="_self"&gt;VSX SNMP v3 workaround&lt;/A&gt;&amp;nbsp;, TAC case still open with CP for permanent fix&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;SNMP OID ifDescr&lt;/STRONG&gt; (1.3.6.1.2.1.2.2.1.2) has changed from interface name to interface card description. It is actually "correct" move but it "broke" our monitoring systems i.e. good old MRTG as it used ifDescr to fetch interface index therefore after upgrade it failed to match interface name to an index:
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;R80.30.&amp;nbsp;iso.3.6.1.2.1.2.2.1.2.2 = STRING: "Mgmt"&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;R80.40:&amp;nbsp;iso.3.6.1.2.1.2.2.1.2.2 = STRING: "Intel Corporation I211 Gigabit Network Connection&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;MultiQueue&lt;/STRONG&gt; manual settings will be replaced with default Auto. Left it at that for now, seems to do a good job&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Unable to display NAT table&lt;/STRONG&gt;&amp;nbsp;(fwx_alloc) on a busy VS. Only cpview works from R80.40 onwards (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk156852&amp;amp;partition=Basic&amp;amp;product=SmartLog" target="_self"&gt;sk156852&lt;/A&gt;&amp;nbsp;). But I'm unable to pull stats using SNMP as described in SK - only VS0 seems to be supported&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;FQDN domain object issue&lt;/STRONG&gt; (added 29/10). Description and workaround available here&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/VSX/FQDN-objects-allowing-non-relevant-IP-addresses-in-R80-40-T78/m-p/100441#M1272" target="_self"&gt;FQDN objects allow many unrelated IPs&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;LAST WORD:&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#FF0000"&gt;I personally would not recommend to deploy R80.40 on VSX with current take 78 in critical production environments due to too many issues with SNMP v3 as you loose service and performance visibility. Unless you need to resolve interface performance related issues i.e. RX buffer overflows that are causing operational problems. I will review and update this when we deploy next take&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Feb 2021 09:15:14 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2021-02-19T09:15:14Z</dc:date>
    <item>
      <title>VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99930#M8699</link>
      <description>&lt;P&gt;My usual "morning after" report, in case it might help some one.&lt;/P&gt;
&lt;P&gt;We were on R80.30 T215 before upgrade running on 23800 appliances that was NOT hyperthreaded before upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Good stuff:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;Really impressed with CPUSE CLI upgrade! Especially considering the complexity - kernel upgrade from 2.6 to 3.10, enabling hyper-threading etc. Well done Checkpoint! I used&amp;nbsp;&lt;STRONG&gt;Multi-Version Cluster (MVC) Upgrade&lt;/STRONG&gt; option and it worked like a charm - connections synchronised in the cluster and I was able to failover one VS at a time.&lt;/P&gt;
&lt;P&gt;Why did we decided against clean install and vsx_util reconfigure?&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;easier rollback on the gateway as file system remains EXT3 you are able to use snapshots created prior R80.40. With clean install file system would change to XFS therefore snapshot revert would not work&lt;/LI&gt;
&lt;LI&gt;no need to take care of any customisations i.e.:
&lt;UL class="lia-list-style-type-square"&gt;
&lt;LI&gt;manual CoreXL settings&lt;/LI&gt;
&lt;LI&gt;non-default IA settings&lt;/LI&gt;
&lt;LI&gt;scripts&lt;/LI&gt;
&lt;LI&gt;contents of user folders&lt;/LI&gt;
&lt;LI&gt;SSH keys and known hosts used by external monitoring&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So actual upgrade was a breeze I have to admit!&lt;/P&gt;
&lt;P&gt;I do not want to celebrate too early but first indications are that our RX-DRP issues might be cured with a better MQ implementation in 3.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Potential show-stoppers or things you will need to take care of:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;User &lt;STRONG&gt;crontab&lt;/STRONG&gt; is reset, so you will have to add it back manually. For us it's a normal procedure anyways for any upgrade, but be mindful&lt;/LI&gt;
&lt;LI&gt;Not 100% sure but for some reason on one box we saw &lt;STRONG&gt;IA nested groups&lt;/STRONG&gt; reset to default setting of 20. We have it disabled. Just check it if you have customised it from 20. This is to deal with high CPU utilisation by pdpd&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Interface RX ring buffer&lt;/STRONG&gt; settings were defaulted during upgrade. We were forced to increase it in R80.30 due to noticeable RX-DRP presence that affected Teams voice&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;SNMP v3&lt;/STRONG&gt; stopped working after upgrade leaving us pretty much blind without any graphs to assess R80.40 performance properly. Major problem if you ask me. &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9754"&gt;@Friedrich_Recht&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":flexed_biceps:"&gt;💪&lt;/span&gt; saved my night - here's link to the&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/VSX/R80-40-snmpv3/m-p/91926#M953" target="_self"&gt;VSX SNMP v3 workaround&lt;/A&gt;&amp;nbsp;, TAC case still open with CP for permanent fix&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;SNMP OID ifDescr&lt;/STRONG&gt; (1.3.6.1.2.1.2.2.1.2) has changed from interface name to interface card description. It is actually "correct" move but it "broke" our monitoring systems i.e. good old MRTG as it used ifDescr to fetch interface index therefore after upgrade it failed to match interface name to an index:
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;R80.30.&amp;nbsp;iso.3.6.1.2.1.2.2.1.2.2 = STRING: "Mgmt"&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;R80.40:&amp;nbsp;iso.3.6.1.2.1.2.2.1.2.2 = STRING: "Intel Corporation I211 Gigabit Network Connection&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;MultiQueue&lt;/STRONG&gt; manual settings will be replaced with default Auto. Left it at that for now, seems to do a good job&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Unable to display NAT table&lt;/STRONG&gt;&amp;nbsp;(fwx_alloc) on a busy VS. Only cpview works from R80.40 onwards (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk156852&amp;amp;partition=Basic&amp;amp;product=SmartLog" target="_self"&gt;sk156852&lt;/A&gt;&amp;nbsp;). But I'm unable to pull stats using SNMP as described in SK - only VS0 seems to be supported&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;FQDN domain object issue&lt;/STRONG&gt; (added 29/10). Description and workaround available here&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/VSX/FQDN-objects-allowing-non-relevant-IP-addresses-in-R80-40-T78/m-p/100441#M1272" target="_self"&gt;FQDN objects allow many unrelated IPs&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;LAST WORD:&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#FF0000"&gt;I personally would not recommend to deploy R80.40 on VSX with current take 78 in critical production environments due to too many issues with SNMP v3 as you loose service and performance visibility. Unless you need to resolve interface performance related issues i.e. RX buffer overflows that are causing operational problems. I will review and update this when we deploy next take&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 09:15:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99930#M8699</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-02-19T09:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99942#M8700</link>
      <description>&lt;P&gt;Adding:&lt;/P&gt;
&lt;P&gt;8. SNMP OID&amp;nbsp;&lt;STRONG&gt;ifHighSpeed&lt;/STRONG&gt; (.1.3.6.1.2.1.31.1.1.1.15) and &lt;STRONG&gt;ifSpeed&lt;/STRONG&gt; (.1.3.6.1.2.1.2.2.1.5) are set to zero for &lt;STRONG&gt;bond&lt;/STRONG&gt; interfaces, affects our monitoring system as it relies on this info to read 32 or 62 bit counter:&lt;/P&gt;
&lt;P&gt;for example in R80.40&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;iso.3.6.1.2.1.2.2.1.2.38 = STRING: "bond2"&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;iso.3.6.1.2.1.2.2.1.5.38 = Gauge32: 0&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;iso.3.6.1.2.1.31.1.1.1.1.38 = STRING: "bond2"&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;iso.3.6.1.2.1.31.1.1.1.15.38 = Gauge32: 0&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;compared to R80.30:&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#000000"&gt;iso.3.6.1.2.1.31.1.1.1.1.62 = STRING: "bond1"&lt;BR /&gt;&lt;FONT color="#339966"&gt;iso.3.6.1.2.1.31.1.1.1.15.62 = Gauge32: 20000&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#000000"&gt;iso.3.6.1.2.1.2.2.1.2.62 = STRING: "bond1"&lt;BR /&gt;&lt;FONT color="#339966"&gt;iso.3.6.1.2.1.2.2.1.5.62 = Gauge32: 4294967295&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 11:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99942#M8700</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-10-23T11:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99952#M8701</link>
      <description>&lt;P&gt;damit i was just about to change to&amp;nbsp;&lt;SPAN&gt;1.3.6.1.2.1.2.2.1.2 as OP5 seams to f* up the interface names all the time.&lt;BR /&gt;More or less it changing each time its rebooted so description was a way for me to resolve it..&lt;BR /&gt;&lt;BR /&gt;Great work&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 12:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99952#M8701</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-10-23T12:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99956#M8702</link>
      <description>&lt;P&gt;And those looking for performance improvements with MQ and interface discards, here's a little teaser for difference between 2.6 and 3.10 kernel. Same HW.. 10Gbps interface loaded to approx 5Gbps average load but high short bursts on top&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 613px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8565iA1BE8B6B7C2D0F0B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 12:45:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99956#M8702</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-10-23T12:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99959#M8703</link>
      <description>&lt;P&gt;ifDescr SNMP OID change is actually documented here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk168601&amp;amp;partition=Advanced&amp;amp;product=Security" target="_self"&gt;sk168601&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 12:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/99959#M8703</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-10-29T12:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/100122#M8704</link>
      <description>&lt;P&gt;Seems like FWK CPU usage has gone up in R80.40 accross all VSes by approx 20%. No change in SXL/F2F split so this is pure CPU increase on FWK&lt;/P&gt;
&lt;DIV id="tinyMceEditor_22388d87807d8cKaspars_Zibarts_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="2020-10-26_8-57-29.jpg" style="width: 398px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8624i576864512717B41D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-10-26_8-57-29.jpg" alt="2020-10-26_8-57-29.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 08:01:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/100122#M8704</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-10-26T08:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/100540#M8705</link>
      <description>&lt;P&gt;CPU usage increase was "fixed"after FQDN object misbehaviour (see point #8) workaround was implemented1! Yay&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 11:31:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/100540#M8705</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-10-29T11:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/112372#M15595</link>
      <description>&lt;P&gt;&lt;STRONG&gt;SMALL UPDATE&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;We upgraded one more VSX cluster this time to T91 so i need highlight three potential issues and one documentation note:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT color="#FF0000"&gt;&lt;STRIKE&gt;&lt;STRONG&gt;increased CPU usage&lt;/STRONG&gt;, approx +10-20%. Solution is still the same - DNS passive learning that's enabled by default. Disabling will reduce the CPU but you will lose additional functionality, especially for O365 updatable object for domains with wildcards&amp;nbsp;&lt;/STRIKE&gt;&lt;FONT color="#000000"&gt; not the case! pls ignore. DPL is working without CPU impact. New suspect has arrived, working on details!&lt;/FONT&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;captive portal&lt;/STRONG&gt; not working, fix is in&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170433&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_self"&gt;sk170433&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;loss of web traffic&lt;/STRONG&gt; for approx 5min after cutover, the root cause was updatable objects including O365 services were not properly initialised so we had to do manual kick described here&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121877" target="_self"&gt;sk121877&lt;/A&gt;. As soon as we run&amp;nbsp;&lt;EM&gt;unified_dl UPDATE ONLINE_SERVICES&lt;/EM&gt; command on corresponding VS, UO populated and all started working. We have added now additional check in the procedure&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;upgrade manual is incorrect&lt;/STRONG&gt;&amp;nbsp;for MVC cluster section and does not tell you to run &lt;EM&gt;vsx_util upgrade&lt;/EM&gt; before running CPUSE upgrade on gateways. It is correct for single VSX gateway though.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Hope it helps someone else!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 14:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/112372#M15595</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-03-25T14:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/113560#M15848</link>
      <description>&lt;P&gt;Regarding &lt;STRONG&gt;crontab&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;-&amp;nbsp;&lt;/SPAN&gt;When adding the jobs using Gaia (Web portal - Job Scheduler / Clish command&amp;nbsp;add cron job) they are preserved after CPUSE Upgrade&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 14:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/113560#M15848</guid>
      <dc:creator>IdanC</dc:creator>
      <dc:date>2021-03-15T14:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: VSX appliance upgrade to R80.40 T78 - first impressions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/113633#M15858</link>
      <description>&lt;P&gt;Indeed, this is about tasks that are run more often than possible with job scheduler&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 09:26:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-appliance-upgrade-to-R80-40-T78-first-impressions/m-p/113633#M15858</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-03-16T09:26:38Z</dc:date>
    </item>
  </channel>
</rss>

