<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateway upgrade R77.30 to R80.20, CPUSE or Fresh Install? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14963#M90373</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Going from R77.30 -&amp;gt; R80.20, I've used the "Clean Install" option that CPUSE gives in the web UI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/76321_Clean install.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've done this for management and for gateways. One issue I found was that even with the "Clean Install", the IP addresses (at least for non-vlan'd interfaces) and routes are left behind. It was a bit confusing when I tried to connect to the appliances over the Mgmt interfaces at &lt;A href="https://192.168.1.1"&gt;https://192.168.1.1&lt;/A&gt;&amp;nbsp;only to find that the interfaces still had their previous IPs. I have a ticket open with support about this - my SE thinks this is by design, I think "Clean Install" should mean everything gets wiped out (though I can understand why you would want the IPs still around if you are doing this remotely).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides this issue, I've had good success using this method.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Dec 2018 20:37:21 GMT</pubDate>
    <dc:creator>David_C1</dc:creator>
    <dc:date>2018-12-11T20:37:21Z</dc:date>
    <item>
      <title>Gateway upgrade R77.30 to R80.20, CPUSE or Fresh Install?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14960#M90370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Greetings, There are usually valid arguments to be made when you would chose a fresh install vs&amp;nbsp;an in place upgrade&amp;nbsp;via CPUSE from one version to another, depending on the&amp;nbsp;environment, amount of customization made, etc.&amp;nbsp;As far as I've read, gateway appliances do not take advantage of the new 3.10 kernel yet, which would be a Pro for a fresh install. For the jump to R80.20, what are some of the opinions out there? I've tested both in the lab, and have had positive results with both.&amp;nbsp; Thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2018 20:03:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14960#M90370</guid>
      <dc:creator>Bob_Delinsky</dc:creator>
      <dc:date>2018-12-11T20:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway upgrade R77.30 to R80.20, CPUSE or Fresh Install?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14961#M90371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is possible and needs reasonable effort, i‘d go for the fresh install.&lt;/P&gt;&lt;P&gt;if possible (spare hardware) I would backup the old management, update to r80.10 or .20 and migrate objects and policies via api to an fresh installed machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pro:&lt;/P&gt;&lt;P&gt;this is kind of an opportunity for policy review and clean up.&lt;/P&gt;&lt;P&gt;you don’t have to take the Risk in carrying errors or other bugs with you. Or can clean up other workarounds..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;con:&lt;/P&gt;&lt;P&gt;more work to do, perhaps additions hardware needed. Takes more time&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2018 20:23:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14961#M90371</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2018-12-11T20:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway upgrade R77.30 to R80.20, CPUSE or Fresh Install?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14962#M90372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Daniel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SMS management , 100% agree. Plus mgmt. R80.20 build takes advantage of the new kernel build. Gateway on existing appliances however, do not as far as I've read it is only on some G10 open servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also prefer fresh build when possible and if an in place upgrade has already occurred previously. For current project, client has many modified files on gateways that were fresh build on R77.30, so weighing the odds of both approaches. I am looking for any advantages either in performance gains, etc that a fresh R80.20 build would provide over a CPUSE upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2018 20:32:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14962#M90372</guid>
      <dc:creator>Bob_Delinsky</dc:creator>
      <dc:date>2018-12-11T20:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway upgrade R77.30 to R80.20, CPUSE or Fresh Install?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14963#M90373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Going from R77.30 -&amp;gt; R80.20, I've used the "Clean Install" option that CPUSE gives in the web UI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/76321_Clean install.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've done this for management and for gateways. One issue I found was that even with the "Clean Install", the IP addresses (at least for non-vlan'd interfaces) and routes are left behind. It was a bit confusing when I tried to connect to the appliances over the Mgmt interfaces at &lt;A href="https://192.168.1.1"&gt;https://192.168.1.1&lt;/A&gt;&amp;nbsp;only to find that the interfaces still had their previous IPs. I have a ticket open with support about this - my SE thinks this is by design, I think "Clean Install" should mean everything gets wiped out (though I can understand why you would want the IPs still around if you are doing this remotely).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides this issue, I've had good success using this method.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2018 20:37:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14963#M90373</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2018-12-11T20:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway upgrade R77.30 to R80.20, CPUSE or Fresh Install?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14964#M90374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bob,&lt;/P&gt;&lt;P&gt;Are they aware of the changes or is it kind of an Überraschungsei? &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/grin.png" /&gt;&lt;/P&gt;&lt;P&gt;If the gateways are clustered, maybe tear apart the nodes, take a backup of the whole machine, update one with a fresh install. Now you can try to elaborate, what changes are still needed and go for some tests.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally i‘d prefer a fresh install on gateways too, if possible and enough time is given.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2018 21:21:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-upgrade-R77-30-to-R80-20-CPUSE-or-Fresh-Install/m-p/14964#M90374</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2018-12-11T21:21:51Z</dc:date>
    </item>
  </channel>
</rss>

