<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Zero Downtime Upgrade - R80.10 - R80.40 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117252#M21840</link>
    <description>&lt;P&gt;For the policy question, it depends. 'vsx_util upgrade' changes the version of the VSX cluster object, all the physical member objects, all of the hidden VS member objects, and all of the VS cluster objects. You should install policy with the new version before failing traffic to a member (physical or VS) running the new version. If you're doing the VSLS trick, you only need to install the VS0 policy to get it updated, then you can install the individual VS policies as you are ready to fail them over.&lt;/P&gt;
&lt;P&gt;As for the second part, a Zero Downtime Upgrade &lt;STRONG&gt;&lt;EM&gt;is&amp;nbsp;not a normal failover&lt;/EM&gt;&lt;/STRONG&gt;. R80.10 can't sync the connection table with R80.40. Think of it as rebooting the firewall, but it comes back up instantly rather than needing to wait for POST, wait for OS startup, wait for service startup, and so on. If somebody is downloading a 100 GB file, and you do the Zero Downtime Upgrade when they have 99 GB, &lt;EM&gt;that connection will not survive the failover&lt;/EM&gt;. They will have to start the download over again (fortunately, most applications have ways to recover from interrupted connections now, but some still don't).&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2021 13:26:27 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2021-04-29T13:26:27Z</dc:date>
    <item>
      <title>Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117175#M21812</link>
      <description>&lt;P&gt;I will be following the following sk to upgrade my VSX Cluster from R80.10 to R80.40.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Installation_and_Upgrade_Guide/Topics-IUG/Zero-Downtime-Upgrade-of-VSX-Cluster.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Installation_and_Upgrade_Guide/Topics-IUG/Zero-Downtime-Upgrade-of-VSX-Cluster.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;My confusion is on the following part..&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In the&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Install Policy&lt;/SPAN&gt;&amp;nbsp;window:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;In the&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Policy&lt;/SPAN&gt;&amp;nbsp;field, select the default policy for this&amp;nbsp;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_cl variable"&gt;VSX Cluster&lt;/SPAN&gt;&amp;nbsp;object.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This policy is called:&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;lt;&lt;EM&gt;Name of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_cl variable"&gt;VSX Cluster&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;object&lt;/EM&gt;&amp;gt;_VSX&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, i have a VS also which carries the traffic of my envrionment..so in this step do i need to install only Cluster Policy or Cluster + VS Policy as well ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, in the following part :&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stop all&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Other_Vars.tp_cp variable"&gt;Check Point&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;services:&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;cpstop&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN class="Note"&gt;Notes:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;This forces a controlled cluster failover from the old&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_clmb variable"&gt;VSX Cluster Member&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;M1&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to one of the upgraded&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_clmbs variable"&gt;VSX Cluster Members&lt;/SPAN&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;At this moment, all connections that were initiated through the old&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_clmb variable"&gt;VSX Cluster Member&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;M1&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are dropped (because&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_vsx_clmbs variable"&gt;VSX Cluster Members&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with different software versions cannot synchronize).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is this like a normal failover where on switching the members it cause a few timeouts and traffic is shifted to the new member..so ideally traffic should be normal after a few timeouts ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 15:17:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117175#M21812</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-28T15:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117187#M21815</link>
      <description>&lt;P&gt;Good point there...I dont think same process is applicable on vsx as regular fw cluster. You might wish to check with TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 17:10:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117187#M21815</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-04-28T17:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117190#M21817</link>
      <description>&lt;P&gt;The "&lt;STRONG&gt;In the&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;Install Policy&lt;/SPAN&gt;&amp;nbsp;window&lt;/STRONG&gt;" part occurs multiple times in the process. Which one are you concerned about?&amp;nbsp;It's specifically talking about the VS0 policy, which normally governs management access to the cluster members themselves. This policy is installed as a part of vsx_util reconfigure, but pushing after that is a good idea to get the policy rebuilt for the new version.&lt;/P&gt;
&lt;P&gt;The failover when you stop services on member 1 would be a stateless failover. All ongoing connections will be lost, and new connections should work immediately. There is no time at which a new connection cannot be formed, thus zero downtime. If you want your upgrade to be more like a normal failover (to preserve long-running connections), you should look at the Multi-Version Cluster Upgrade.&lt;/P&gt;
&lt;P&gt;Normal failovers shouldn't involve a few timeouts. The last several upgrades I have installed, nobody outside my team even noticed the change.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 19:17:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117190#M21817</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-28T19:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117202#M21820</link>
      <description>&lt;P&gt;I would definitely go with MVC upgrade. Plus if you are running VSLS cluster mode as opposed to HA, you can fail over one VS at a time thus having better control over upgrade&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 02:41:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117202#M21820</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-04-29T02:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117206#M21821</link>
      <description>&lt;P&gt;During upgrade from R80.10 to R80.30 i have experienced a few active / active scenarios that was less fun.&lt;BR /&gt;So i try to be extra careful for those and actually turn of the production nics to the VSX node (in the switch) to just make sure that everything works correct. and just keep the sync and vs0 open.&lt;BR /&gt;&lt;BR /&gt;Am not 100% sure what the reason where anymore. but we experience on 3 clusters upgrades and after that we just said "F*** it lets make it bulletproof"&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 06:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117206#M21821</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2021-04-29T06:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117207#M21822</link>
      <description>&lt;P&gt;it's never 100% guaranteed, i saw weird state even with only Mgmt and Sync connected during one of the latest rollbacks.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Plus we are talking R80.40 and it's totally different beast to R80.30 hehe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 06:10:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117207#M21822</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-04-29T06:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117208#M21823</link>
      <description>&lt;P&gt;hehe, i have no production vsx on r80.40 yet &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;But am suspecting its similar upgrade as am running the r80.30 3.10 kernel.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 06:13:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117208#M21823</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2021-04-29T06:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117233#M21830</link>
      <description>&lt;P&gt;yes thats correct..it specifically say install cluster object policy.. my confusion is..after upgrading secondary member i need to force a failover..in that case the upgraded member should have VS policy as well so as to cater the running VS traffic.. but in the sk it says install cluster object policy ..hence my confusion that only cluster policy is to be installed or cluster and VS both.&lt;/P&gt;&lt;P&gt;Also,normally during failover testing users didnt even noticed that something went wrong or changed..i just wanted to confirm that this is going to be same in this case..do you mean to say during the upgrade when the member is switched it takes more time to build connections as compared to failover scenario ?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 11:56:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117233#M21830</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-29T11:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117235#M21831</link>
      <description>&lt;P&gt;i looked at the MVC upgrade but the connections i have are static NAT based..and it is a limitation in MVC&amp;nbsp; &amp;nbsp; &amp;nbsp;...hence going with Zero Downtime ..i wouldn't mind a few drops in connections as long as it gets restored in a min or two&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 11:59:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117235#M21831</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-29T11:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117237#M21833</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9282"&gt;@Magnus-Holmberg&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;your conversation is making me nervous..&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 12:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117237#M21833</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-29T12:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117239#M21834</link>
      <description>&lt;P&gt;hey Magnus.. big fan of your youtube content .. good to hear from you..&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Active/Active scenario can occur once the members are switched ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 12:08:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117239#M21834</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-29T12:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117240#M21835</link>
      <description>&lt;P&gt;I dont fully remember the senario, but i do believe it was after we have made the failover with VSLS and 1 member was on R80.10 (possible 32bit vs) and then second member came up with R80.30 (without any HFA) and then 64bit for the VS.&lt;BR /&gt;And the members simply didn´t see each other anymore so both went active instead of being Active / ready.&lt;BR /&gt;We didn´t spend much time troubleshooting as it was in the middle of the night, so instead when doing those jumps we killed all the interfaces except vs0 and sync so even if it would go active it would not take any traffic.&lt;BR /&gt;&lt;BR /&gt;Having said that we recently made some testing upgrading r80.10 VSLS to R80.30 with CDT and it worked perfectly.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 12:16:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117240#M21835</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2021-04-29T12:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117247#M21837</link>
      <description>&lt;P&gt;You are right - document only refers to VS0 policy. If I'm honest, I always install all VSes just to be sure. Takes extra time but I think it's worth it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As for failover to do damage control you can set to allow out of state connections before upgrade and revert back to normal after upgrade. This way if any of TCP connections isn't synchronised but is still ongoing, it will get accepted and there will be no need to restart that TCP connection (i.e. long running jobs like backups)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11562i8AE2A9BBFDB6A5A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 12:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117247#M21837</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-04-29T12:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117248#M21838</link>
      <description>&lt;P&gt;Thanks... this looks helpful&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 13:05:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117248#M21838</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-29T13:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117250#M21839</link>
      <description>&lt;P&gt;I think you misunderstood the limitation. It only applies to failovers from R80.40 back to an earlier version, which should only happen if the upgrade breaks things anyway. It also only applies if you are using VMAC mode.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 13:16:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117250#M21839</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-29T13:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117252#M21840</link>
      <description>&lt;P&gt;For the policy question, it depends. 'vsx_util upgrade' changes the version of the VSX cluster object, all the physical member objects, all of the hidden VS member objects, and all of the VS cluster objects. You should install policy with the new version before failing traffic to a member (physical or VS) running the new version. If you're doing the VSLS trick, you only need to install the VS0 policy to get it updated, then you can install the individual VS policies as you are ready to fail them over.&lt;/P&gt;
&lt;P&gt;As for the second part, a Zero Downtime Upgrade &lt;STRONG&gt;&lt;EM&gt;is&amp;nbsp;not a normal failover&lt;/EM&gt;&lt;/STRONG&gt;. R80.10 can't sync the connection table with R80.40. Think of it as rebooting the firewall, but it comes back up instantly rather than needing to wait for POST, wait for OS startup, wait for service startup, and so on. If somebody is downloading a 100 GB file, and you do the Zero Downtime Upgrade when they have 99 GB, &lt;EM&gt;that connection will not survive the failover&lt;/EM&gt;. They will have to start the download over again (fortunately, most applications have ways to recover from interrupted connections now, but some still don't).&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 13:26:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117252#M21840</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-29T13:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117256#M21842</link>
      <description>&lt;P&gt;Thank&amp;nbsp; you.. this clears my confusion&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 13:44:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117256#M21842</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-29T13:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117257#M21843</link>
      <description>&lt;P&gt;That's what I meant by allowing out-of-state connections - then 99G will continue&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 13:45:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117257#M21843</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-04-29T13:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117261#M21846</link>
      <description>&lt;P&gt;ok..got it&lt;/P&gt;&lt;P&gt;One more thing here which is putting me off..&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Installation_and_Upgrade_Guide/Topics-IUG/Planning-Cluster-Upgrade.htm" target="_blank" rel="noopener noreferrer"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Installation_and_Upgrade_Gui...&lt;/A&gt;&lt;/P&gt;&lt;P&gt;at the bottom of this link a note states..&lt;/P&gt;&lt;P&gt;&lt;EM&gt;When&amp;nbsp;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_clmbs variable"&gt;Cluster Members&lt;/SPAN&gt;&amp;nbsp;of different versions are on the same network,&amp;nbsp;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_clmbs variable"&gt;Cluster Members&lt;/SPAN&gt;&amp;nbsp;of the new (upgraded) version remain in the state&amp;nbsp;&lt;STRONG&gt;Ready&lt;/STRONG&gt;, and&amp;nbsp;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_clmbs variable"&gt;Cluster Members&lt;/SPAN&gt;&amp;nbsp;of the previous version remain in state&amp;nbsp;&lt;STRONG&gt;Active Attention&lt;/STRONG&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_clmbs variable"&gt;Cluster Members&lt;/SPAN&gt;&amp;nbsp;in the state&amp;nbsp;&lt;STRONG&gt;Ready&lt;/STRONG&gt;&amp;nbsp;do not process traffic and do not synchronize with other&amp;nbsp;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_clmbs variable"&gt;Cluster Members&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;this is the condition before switching on MVC and will change once MVC is switched on.. is this correct ?&lt;/P&gt;&lt;P&gt;wudnt this condition auto correct once MVC is enabled.. isnt this always the condition during MVC upgrade that an upgraded member will always be in "Ready" state at first...But why then the next steps might be required like removing physical interfaces , shutdown interfaces etc..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 14:25:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117261#M21846</guid>
      <dc:creator>LostBoY</dc:creator>
      <dc:date>2021-04-29T14:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Downtime Upgrade - R80.10 - R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117280#M21849</link>
      <description>&lt;P&gt;Yeah, but that has some other concerns. Most notably, it's a global property, so it applies to all firewalls in the environment. Very few people run just one VSX cluster by itself in a management, so this setting might get pushed to other firewalls completely unrelated to the upgrade.&lt;/P&gt;
&lt;P&gt;Also, I don't think it adds ongoing connections to the connections table, it just doesn't drop them. This would deal with some long-running connections like the download or backup which eventually end, but some systems like ATMs often keep the same connection open for over a year with very little data. When you eventually switch the setting off, I think any connections like that will be dropped when you push policy.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 18:38:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Zero-Downtime-Upgrade-R80-10-R80-40/m-p/117280#M21849</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-29T18:38:53Z</dc:date>
    </item>
  </channel>
</rss>

