<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practices Guide for upgrading endpoint clients in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33695#M842</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the way that I do upgrades and create packages for my environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We first started off with the default rule for all the endpoints.&amp;nbsp; Then, to upgrade those clients to a new version, I would upload the new installers, create a package/rule for export (for new machines) and then in the software deployment rules, create a new rule with the new group I created.&amp;nbsp; I can now just add the users/computers to this group and they will get the upgrades.&amp;nbsp; Once everyone is in that group, you can&amp;nbsp;just change the default global rule to be the same rule as the one you created to do the upgrades, then delete that rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have computers that need different rules, the upgrade path is pretty much the same.&amp;nbsp; Just move the users/computers into the new group and when you are done you can just delete the old group/rule they had.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is good as you can put your test machines, then test users in there first before you just blanket everyone.&amp;nbsp; Also, if you have certain machines with certain blades/rules, you will always be using groups anyway.&amp;nbsp; We have the default rule&amp;nbsp; and upgrade group for&amp;nbsp;computer that do not use FDE, and a group/upgrade group for computers with FDE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make it easier, you can specify what group a brand new client goes in to in the Packages for Export tab in Deployment when you install CheckPoint Endpoint on a brand new computer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jun 2018 13:42:56 GMT</pubDate>
    <dc:creator>Steve_Lander</dc:creator>
    <dc:date>2018-06-26T13:42:56Z</dc:date>
    <item>
      <title>Best Practices Guide for upgrading endpoint clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33691#M838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have approx 1500 endpoint clients and most are running version E80.65 and our Management Sever is&amp;nbsp; R77.30.03.&lt;/P&gt;&lt;P&gt;We currently have 3 versions in environment, E80.65, E80.71 and now E80.83.&lt;/P&gt;&lt;P&gt;Is there a best practices guide on how to upgrade the clients?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 17:06:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33691#M838</guid>
      <dc:creator>Michael_Overby</dc:creator>
      <dc:date>2018-06-22T17:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices Guide for upgrading endpoint clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33692#M839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can deploy new versions from the Endpoint Security Server.&lt;/P&gt;&lt;P&gt;Instructions are here:&amp;nbsp;&lt;A class="link-titled" href="http://downloads.checkpoint.com/dc/download.htm?ID=53788" title="http://downloads.checkpoint.com/dc/download.htm?ID=53788"&gt;Endpoint Security Admin Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't want to use the Endpoint Security Server to do it:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108833" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108833"&gt;How to upgrade Endpoint Security Client without using Endpoint Security Server&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If any of your clients are Windows 10 and you are running Full Disk Encryption, see:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120667" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120667"&gt;How to upgrade to Windows 10 1607 and above with FDE in-place&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 18:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33692#M839</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-22T18:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices Guide for upgrading endpoint clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33693#M840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dameon, I have looked at those previously and none of them help.&lt;/P&gt;&lt;P&gt;I want to be able to push the new version out to all the clients without having to touch them.&lt;/P&gt;&lt;P&gt;I know I can create a deployment rule and change the version.&lt;/P&gt;&lt;P&gt;Upgrading 1500 devices at one time would bring&amp;nbsp;any network to a crawl.&lt;/P&gt;&lt;P&gt;How is everyone else pushing out new versions in a test environment&amp;nbsp; and then to the production environment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 18:48:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33693#M840</guid>
      <dc:creator>Michael_Overby</dc:creator>
      <dc:date>2018-06-22T18:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices Guide for upgrading endpoint clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33694#M841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While I am not an Endpoint expert, I would think you would&amp;nbsp;create a few different groups and deploy to one group at a time, versus all 1500 at once.&lt;/P&gt;&lt;P&gt;And, in fact,&amp;nbsp;that's along the lines of what the documentation suggests under the heading "Gradual Upgrade."&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;To upgrade more gradually, you can create a new deployment profile and distribute it only to specified computers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note - For an exported package, save the new package in a different location than the previous package.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you are prepared to upgrade all clients, upgrade all deployment profiles&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, I'd love to see what others are doing as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2018 21:04:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33694#M841</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-22T21:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices Guide for upgrading endpoint clients</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33695#M842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the way that I do upgrades and create packages for my environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We first started off with the default rule for all the endpoints.&amp;nbsp; Then, to upgrade those clients to a new version, I would upload the new installers, create a package/rule for export (for new machines) and then in the software deployment rules, create a new rule with the new group I created.&amp;nbsp; I can now just add the users/computers to this group and they will get the upgrades.&amp;nbsp; Once everyone is in that group, you can&amp;nbsp;just change the default global rule to be the same rule as the one you created to do the upgrades, then delete that rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have computers that need different rules, the upgrade path is pretty much the same.&amp;nbsp; Just move the users/computers into the new group and when you are done you can just delete the old group/rule they had.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is good as you can put your test machines, then test users in there first before you just blanket everyone.&amp;nbsp; Also, if you have certain machines with certain blades/rules, you will always be using groups anyway.&amp;nbsp; We have the default rule&amp;nbsp; and upgrade group for&amp;nbsp;computer that do not use FDE, and a group/upgrade group for computers with FDE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make it easier, you can specify what group a brand new client goes in to in the Packages for Export tab in Deployment when you install CheckPoint Endpoint on a brand new computer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 13:42:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Best-Practices-Guide-for-upgrading-endpoint-clients/m-p/33695#M842</guid>
      <dc:creator>Steve_Lander</dc:creator>
      <dc:date>2018-06-26T13:42:56Z</dc:date>
    </item>
  </channel>
</rss>

