<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zero Downtime Upgrade From R77.30 to R80.20 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60557#M12264</link>
    <description>&lt;P&gt;This is more-or-less the shorten version of&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Best_Practices/Cluster_Connectivity_Upgrade/html_frameset.htm?topic=documents/Best_Practices/Cluster_Connectivity_Upgrade/215132" target="_blank" rel="noopener"&gt;Connectivity Upgrade of a Security Gateway Cluster from R77.x to R80.x&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Aug 2019 19:44:25 GMT</pubDate>
    <dc:creator>JozkoMrkvicka</dc:creator>
    <dc:date>2019-08-18T19:44:25Z</dc:date>
    <item>
      <title>Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60493#M12253</link>
      <description>&lt;P&gt;As this is a season of R80 Upgrade, just sharing my experience of recent upgrades in the live environment from R77.30 to R80.20 without any service down&lt;/P&gt;&lt;P&gt;1.Upgrade the DA Agent to the latest version&lt;BR /&gt;2.Upload the R80.20 Image through CPUSE and verify for any errors&lt;BR /&gt;3. In CMA cluster Properties, Select Maintain current cluster Active member&lt;BR /&gt;4.Upgrade on the current standby FW(CPUSE) and let it Reboot&lt;BR /&gt;5. Once rebooted, Change the Gateway Object to R80.20 version(It will change for all 3 objects)&lt;BR /&gt;6.Install policy(Uncheck the option- For gateway clusters, if installation on a cluster member fails, do not install on that cluster)&lt;BR /&gt;7. Check the HA in new version FW,(HA module will be Ready)&lt;BR /&gt;8. Now do the upgrade in another gateway, During a reboot, the other pair on HA-Ready will become Active&lt;BR /&gt;9.No service Interruption and the other FW will take HA Active(Few Packet Drops-2 to 3 RTO)&lt;/P&gt;&lt;P&gt;Now verify both status and do a final Policy Installation by "Keep Check" the actions&lt;/P&gt;&lt;P&gt;10. Now Install the Hotfix.R80.20 Jumbo Hotfix Accumulator General Availability(Take 87)&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 00:49:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60493#M12253</guid>
      <dc:creator>Jain_Raj</dc:creator>
      <dc:date>2019-09-20T00:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60526#M12260</link>
      <description>Hi, thanks for sharing your experience.&lt;BR /&gt;Glad it was a successful one &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Sun, 18 Aug 2019 00:51:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60526#M12260</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-08-18T00:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60557#M12264</link>
      <description>&lt;P&gt;This is more-or-less the shorten version of&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Best_Practices/Cluster_Connectivity_Upgrade/html_frameset.htm?topic=documents/Best_Practices/Cluster_Connectivity_Upgrade/215132" target="_blank" rel="noopener"&gt;Connectivity Upgrade of a Security Gateway Cluster from R77.x to R80.x&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2019 19:44:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60557#M12264</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2019-08-18T19:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60563#M12267</link>
      <description>Thanks for sharing the detailed one and it will help for beginners.</description>
      <pubDate>Mon, 19 Aug 2019 00:53:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60563#M12267</guid>
      <dc:creator>Jain_Raj</dc:creator>
      <dc:date>2019-08-19T00:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60574#M12270</link>
      <description>&lt;P&gt;I can not see when you initiate the first failover - after step 6 ?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 07:24:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60574#M12270</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-08-19T07:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60576#M12272</link>
      <description>&lt;P&gt;I didn't do a Failover after step 6. Just went to Upgrade the other FW and during reboot, this Firewall to take Active&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 07:32:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60576#M12272</guid>
      <dc:creator>Jain_Raj</dc:creator>
      <dc:date>2019-08-19T07:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60602#M12275</link>
      <description>&lt;P&gt;Interesting ! In the original document i read:&lt;/P&gt;
&lt;P class="procedureheading"&gt;Step 13 of 19: On the Active old cluster member - Stop all Check Point services&lt;/P&gt;
&lt;TABLE class="tableintopic" border="0" width="907" cellspacing="0" cellpadding="2"&gt;
&lt;TBODY&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TH bgcolor="#515254" width="57"&gt;
&lt;P class="tableheadingwhite"&gt;Step&lt;/P&gt;
&lt;/TH&gt;
&lt;TH bgcolor="#515254" width="851"&gt;
&lt;P class="tableheadingwhite"&gt;Description&lt;/P&gt;
&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="57"&gt;
&lt;P class="tpbodytext"&gt;1&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="851"&gt;
&lt;P class="tpbodytext"&gt;Connect to the command line on the Active old cluster member M1.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR align="left" valign="top"&gt;
&lt;TD width="57"&gt;
&lt;P class="tpbodytext"&gt;2&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="851"&gt;
&lt;P class="tpbodytext"&gt;Stop all Check Point services:&lt;/P&gt;
&lt;P class="tpbodytext"&gt;&lt;CODE class="monospace"&gt;cpstop&lt;/CODE&gt;&lt;/P&gt;
&lt;P class="tpbodytext"&gt;&lt;STRONG class="bold"&gt;Important -&lt;/STRONG&gt; At this moment, the connections fail over from the old cluster member M1 to the &lt;STRONG class="menuoptions"&gt;Active&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="tpbodytext"&gt;upgraded cluster member (M2 or M3).&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Mon, 19 Aug 2019 09:01:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60602#M12275</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-08-19T09:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60629#M12278</link>
      <description>&lt;P&gt;Before the upgrade, also you have to change the ccp to broadcast and after the upgrade, change ccp to auto.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 13:14:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60629#M12278</guid>
      <dc:creator>lullejd</dc:creator>
      <dc:date>2019-08-19T13:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60640#M12282</link>
      <description>&lt;P&gt;Does this mean that you already had upgraded the rules set to R80?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 14:37:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60640#M12282</guid>
      <dc:creator>Noel_Rodriguez</dc:creator>
      <dc:date>2019-08-19T14:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60642#M12283</link>
      <description>&lt;P&gt;This steps works very well in all environments but we need pay attention because some connections and features do not survive after failover to an upgraded Cluster Member.&lt;/P&gt;
&lt;P&gt;Failover Limitations&lt;BR /&gt;- Connections initiated by the Cluster Member itself, do not survive failover.&lt;BR /&gt;- TCP connections handled by the Check Point Active Streaming (CPAS) or Passive Streaming Layer (PSL) mechanism do not survive failover. This can affect many blades as like DLP, IPS, Threat Emulation, VPN. To get more information you can see &lt;A href="https://sc1.checkpoint.com/documents/Best_Practices/Cluster_Connectivity_Upgrade/html_frameset.htm" target="_self"&gt;Connectivity Upgrade Limitations&lt;/A&gt;&lt;BR /&gt;- Connectivity Upgrade is supported only when CPU utilization on Cluster Members is below 50%.&lt;BR /&gt;- If a session that is authenticated with the Identity Awareness Software Blade is open when you start the Connectivity Upgrade, the session is terminated.&lt;BR /&gt;- IPv6 connections do not survive the Connectivity Upgrade.&lt;/P&gt;
&lt;P&gt;For additional limitations related to general failover, see the section Check Point Software Compatibility in the &lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=54804" target="_self"&gt;ClusterXL Administration Guide.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107042&amp;amp;partition=General&amp;amp;product=ClusterXL#Upgrade%20methods" target="_self"&gt;sk107042 - ClusterXL upgrade methods and paths&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 15:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60642#M12283</guid>
      <dc:creator>HelioLeite</dc:creator>
      <dc:date>2019-08-19T15:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60648#M12284</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have upgraded my cluster R77.30 to R80.20 last week and I faced an issue after upgrading as follow:&lt;/P&gt;&lt;P&gt;Unix server couldn`t send files to FTP server via FTP passive mode and after 2, 3 hours troubleshooting I disabled the SecureXL and issue resolved so do you have any suggestion or thought?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 16:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60648#M12284</guid>
      <dc:creator>Kamiar_Sh</dc:creator>
      <dc:date>2019-08-19T16:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60657#M12291</link>
      <description>&lt;P&gt;We are not having the HA for our R77.30 management server. Can some one help us on the steps to be followed&amp;nbsp; to migrate&amp;nbsp; from R77.30 to R80.20 withoout any impact.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 18:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60657#M12291</guid>
      <dc:creator>Ila</dc:creator>
      <dc:date>2019-08-19T18:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60682#M12301</link>
      <description>&lt;P&gt;If the R77.30 cluster runs in 32 bit mode and is upgraded to R80.20, I'm pretty sure that the state table is NOT synced at failover. This implies that the upgrade is zero downtime, but existing sessions do NOT survive.&lt;/P&gt;&lt;P&gt;Correct?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2019 06:59:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60682#M12301</guid>
      <dc:creator>peter_schumache</dc:creator>
      <dc:date>2019-08-20T06:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade From R77.30 to R80.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60879#M12349</link>
      <description>Hopefully your management server is implemented as a virtual machine. Then ist gets quite easy.&lt;BR /&gt;1. Use the migrte tools from R80.20 on your R77.30 server to if the DB is clean.&lt;BR /&gt;2. Do a migrate_export on your R77.30 mgmt server&lt;BR /&gt;3. Perform a new R80.20 installation from scratch on a new virtual machine with same IP-address as R77.30 Mgmt server, but on another vlan.&lt;BR /&gt;4. Perform the migrate_import on the new R80.20 Mgmt Server.&lt;BR /&gt;5. Do the necessary checks on the new Mgmt server.&lt;BR /&gt;6. lift your old R77.30 mgmt server from themgmt vlan and connect your new mgmt server to it.&lt;BR /&gt;7. Check if yout get the logs and can reach your gateways.&lt;BR /&gt;In case you notice any issus, yu can easily switch back to your old R77.30 mgmt server</description>
      <pubDate>Wed, 21 Aug 2019 14:39:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-From-R77-30-to-R80-20/m-p/60879#M12349</guid>
      <dc:creator>peter_schumache</dc:creator>
      <dc:date>2019-08-21T14:39:03Z</dc:date>
    </item>
  </channel>
</rss>

