<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practice for Upgrade from R80.10 to R80.40 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108227#M20628</link>
    <description>&lt;P&gt;1) CPUSE is the tool used to update or upgrade. You can interact with CPUSE via the web UI or via clish. The results are identical. I prefer using clish, as I can write out exact commands well ahead of the upgrade window. As opposed to having to tell a person "Click on this, then click on that, then click on the other thing.", I can say "Copy all of these commands, paste them into the CLI, and wait ten minutes." Execution effort goes &lt;EM&gt;way&lt;/EM&gt; down, which 2-AM-Zimmie appreciates.&lt;/P&gt;
&lt;P&gt;2) I know R80.10 management actually can manage higher-version firewalls. You just don't get most of the new features from the new firewall version. Improvements to existing features generally work. I suspect this is a pretty rare situation to be in, though, as a SmartCenter or MDS is generally much less political effort to upgrade than a firewall.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 21:16:03 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2021-01-19T21:16:03Z</dc:date>
    <item>
      <title>Best practice for Upgrade from R80.10 to R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108219#M20624</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;We are planning to upgrade our Environment:&lt;/P&gt;&lt;P&gt;Check Point Security Management – Vmware – R80.10 take 462&lt;/P&gt;&lt;P&gt;Check Point Security Gateway 5400 - 1632BA1462 – R80.10 take 462&lt;/P&gt;&lt;P&gt;Check Point Security Gateway 5400 - 1632BA1426 – R80.10 take 462&lt;/P&gt;&lt;P&gt;I have got a couple of questions here:&lt;/P&gt;&lt;P&gt;1) Is it recommended to upgrade from clish, or cpuse or both are the same?&lt;/P&gt;&lt;P&gt;2) Is it better to upgrade the SMS before the gateways?&lt;/P&gt;&lt;P&gt;3) Is the "snapshot" the best backup option in case of upgrade or there is a better option? for both Gws and SMS&lt;/P&gt;&lt;P&gt;4) What's the difference between blink/clean install and upgrade, and which one I should install if am planning to install the latest HF?&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Clean.jpg" style="width: 950px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10270i272F5F9059657818/image-size/large?v=v2&amp;amp;px=999" role="button" title="Clean.jpg" alt="Clean.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 19:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108219#M20624</guid>
      <dc:creator>Dyslexic155</dc:creator>
      <dc:date>2021-01-19T19:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Upgrade from R80.10 to R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108221#M20625</link>
      <description>&lt;P&gt;Let me try answer your questions the best of my ability and knowledge : )&lt;/P&gt;&lt;P&gt;1) Is it recommended to upgrade from clish, or cpuse or both are the same? Its RECOMMENDED via cpuse. Its possible via clish, but I dont know anyone that does it that way these days.&lt;/P&gt;&lt;P&gt;2) Is it better to upgrade the SMS before the gateways? Thats ALWAYS a must. Otherwise, if you do it the other way around, you cant manage the gateways via server before they are on at least same version.&lt;/P&gt;&lt;P&gt;3) Is the "snapshot" the best backup option in case of upgrade or there is a better option? for both Gws and SMS. You can take snapshot, but backup is enough. If you really want to be safe, take both.&lt;/P&gt;&lt;P&gt;4) What's the difference between blink/clean install and upgrade, and which one I should install if am planning to install the latest HF? Difference is this...think about it if you were to upgrade your home router...it just gets new firmware and if you do clean install, it installs blank version with no config at all. As far as latest HFA, that is checked automatically after upgrade.&lt;/P&gt;&lt;P&gt;I had done upgrade many times, so be free to message me privately if you have any concerns or other questions and I am happy to help you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers and be safe!&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 20:06:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108221#M20625</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-19T20:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Upgrade from R80.10 to R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108227#M20628</link>
      <description>&lt;P&gt;1) CPUSE is the tool used to update or upgrade. You can interact with CPUSE via the web UI or via clish. The results are identical. I prefer using clish, as I can write out exact commands well ahead of the upgrade window. As opposed to having to tell a person "Click on this, then click on that, then click on the other thing.", I can say "Copy all of these commands, paste them into the CLI, and wait ten minutes." Execution effort goes &lt;EM&gt;way&lt;/EM&gt; down, which 2-AM-Zimmie appreciates.&lt;/P&gt;
&lt;P&gt;2) I know R80.10 management actually can manage higher-version firewalls. You just don't get most of the new features from the new firewall version. Improvements to existing features generally work. I suspect this is a pretty rare situation to be in, though, as a SmartCenter or MDS is generally much less political effort to upgrade than a firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 21:16:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108227#M20628</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-01-19T21:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Upgrade from R80.10 to R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108259#M20630</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Thanks alot for your detailed feedback, helped me to sort things out.&lt;/P&gt;&lt;P&gt;For the last point am still confused, does this mean that if I use the "clean install", I will have to restore/import a backup to restore the data? But if I just upgrade, it will be upgraded with all the data with no need to restore a backup?&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 07:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108259#M20630</guid>
      <dc:creator>Dyslexic155</dc:creator>
      <dc:date>2021-01-20T07:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Upgrade from R80.10 to R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108273#M20634</link>
      <description>&lt;P&gt;In-Place CPUSE update will keep all the data with no need to restore a backup. Clean install will need the &lt;SPAN style="font-family: -webkit-standard; color: black;"&gt;config export from clish for the GWs and migrate_server export from SMS.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 09:54:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108273#M20634</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-01-20T09:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Upgrade from R80.10 to R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108274#M20635</link>
      <description>&lt;P&gt;A snapshot is no use here as it will restore the old OS?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 09:59:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108274#M20635</guid>
      <dc:creator>Dyslexic155</dc:creator>
      <dc:date>2021-01-20T09:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Upgrade from R80.10 to R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108427#M20647</link>
      <description>&lt;P&gt;&lt;FONT color="#000000"&gt;Hi&amp;nbsp;&lt;SPAN&gt;Dyslexic.&lt;BR /&gt;&lt;BR /&gt;If you do an Upgrade via CPUSE is automatically created a snapshot.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;The differences between Blink images and "old type" of images are:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;1) Each Blink image allows to install a specific role&amp;nbsp;of a machine (GW/MGMT/MDS)- resulting in faster installation.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;2) Blink image&amp;nbsp;can contain Jumbo, and it allows to install version + the latest jumbo in a single step.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;The Blink image for R80.40+JHF T89&amp;nbsp;&lt;STRONG&gt;GW&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;"&gt;allows clean install or upgrade.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN style="background-color: #ffffff;"&gt;The&amp;nbsp;&lt;SPAN&gt;Blink image for R80.40+JHF T89&amp;nbsp;&lt;STRONG&gt;MGMT&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;allows clean install only.&amp;nbsp;But we plan that the blink with the next jumbo (or one after that) will allow upgrade for MGMT as well.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color: #ffffff;"&gt;&lt;FONT color="#000000"&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 17:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108427#M20647</guid>
      <dc:creator>Dov_Fraivert</dc:creator>
      <dc:date>2021-01-21T17:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for Upgrade from R80.10 to R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108429#M20648</link>
      <description>&lt;P&gt;Dont use snapshot, it takes way too much space and you probably wont need it...backup is fine. In worst case, if upgrade fails or something is not compatible, it will revert it anyway.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 17:09:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-practice-for-Upgrade-from-R80-10-to-R80-40/m-p/108429#M20648</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-21T17:09:15Z</dc:date>
    </item>
  </channel>
</rss>

