<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81 Upgrade Tips in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157837#M26643</link>
    <description>&lt;P&gt;After the upgrade and the first policy is pushed to upgraded gateways, you might not be able to login into the&amp;nbsp;&lt;SPAN&gt;SmartConsole .If this occurs, check your&amp;nbsp;implied rules.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Sep 2022 12:57:35 GMT</pubDate>
    <dc:creator>Abi</dc:creator>
    <dc:date>2022-09-22T12:57:35Z</dc:date>
    <item>
      <title>R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155437#M26421</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a number of R81 upgrades coming up over coming months for various clients, mainly from R80.x.&lt;/P&gt;&lt;P&gt;Aside from the upgrade guide (which I will read), Im looking for some tech tips, or best practices for increasing the chances of a smooth upgrade i.e. pre / post checks, HA best practices etc. stuff that may not neccassarily be in the upgrade guides.&lt;/P&gt;&lt;P&gt;Ive had a number of issues with upgrades between R80 versions (some documented here, and still ongoing), so I really want to try gather as much prep as I can from the experts here.&lt;/P&gt;&lt;P&gt;Also, if theres any known issues / gotchas when going from R80.x to R81, that would be great.&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Im hoping if we can get some good responses here, it will also be a helpful resource for other Checkpoint customers moving to R81).&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 14:31:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155437#M26421</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-08-22T14:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155448#M26422</link>
      <description>&lt;P&gt;I did bunch of those and I find it always goes smoothly from web UI. You can also do it via smart dashboard, but its been a while since I did that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 16:49:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155448#M26422</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-22T16:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155453#M26423</link>
      <description>&lt;P&gt;I would suggest R81.10 instead of R81.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 17:07:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155453#M26423</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-08-22T17:07:55Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155454#M26424</link>
      <description>&lt;P&gt;TOTALLY!!!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 17:08:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155454#M26424</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-08-22T17:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155455#M26425</link>
      <description>&lt;P&gt;I would upgrade the SMS using GAiA WebGUI and then the GWs using Smart Dashboard.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 17:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155455#M26425</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-08-22T17:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155457#M26426</link>
      <description>&lt;P&gt;&amp;nbsp;I don't know how many gateways you're talking about and how many customization you have, but it can be a good moment to do a clean install and review your config why system variables are set etc.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 17:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155457#M26426</guid>
      <dc:creator>Piet_vd_Maas</dc:creator>
      <dc:date>2022-08-22T17:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155488#M26427</link>
      <description>&lt;P&gt;Thanks Piet, noted. And its generally a cluster and SMS.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 08:23:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155488#M26427</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-08-23T08:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155490#M26428</link>
      <description>&lt;P&gt;Thanks. Can i get your rational behind this? I thought using blink directly on GW GUI would be best method.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 08:24:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155490#M26428</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-08-23T08:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155491#M26429</link>
      <description>&lt;P&gt;For sure, yes. I assume R81.10 SMS can happily co-exist and manage R80 GWs?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 08:25:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155491#M26429</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-08-23T08:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155497#M26430</link>
      <description>&lt;P&gt;Configure and test your Lights Out Management before you start (especially if you are not doing the upgrades on-site).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example: I recently ran into a a very annoying bug at a couple of deployments where if you had IOC feeds configured the gateway would reboot with the initial policy and having access to the console allowed me to do a "fw fetch".&amp;nbsp; Allowed me to finish the upgrades on schedule and saved me from a several hours round-trip.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 09:14:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155497#M26430</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-08-23T09:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155508#M26433</link>
      <description>&lt;P&gt;If you go for a fresh install using Blink, yes. In SmartDashboard, you can download the upgrade package once and then locally install it on several GWs.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 10:33:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155508#M26433</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-08-23T10:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155548#M26438</link>
      <description>&lt;P&gt;I concur on checking lights-out first. Out of 5 clusters on 69000 appliance only one cluster was working. The other 4 clusters (2 nodes each) connectivity failed. Reboot of 3 clusters fixed connectivity. The last one needed a datacentre visit to pull the power cable to reset both nodes.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 20:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155548#M26438</guid>
      <dc:creator>spottex</dc:creator>
      <dc:date>2022-08-23T20:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155551#M26439</link>
      <description>&lt;P&gt;Keep a close eye on the important files -in case you'd some custom config, mainly&amp;nbsp;trac_client_1.ttm, etc. these will be over-written so make sure to copy them prior to upgrade. It's clearly mentioned in the upgrade guide.&lt;BR /&gt;&lt;BR /&gt;Also I noticed on a VSX cluster the MAC address for the bond has changed post upgrade, impacting the proxy arp config, we ended up updating the local.arp.&lt;BR /&gt;&lt;BR /&gt;Had a problem with one VS post upgrade member 1, I was able to push policies to every single VS but was complaining about one VS not having SIC with it! While waiting over 40 minutes for a TAC engineer to join the call, I rebooted the appliance which fixed the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 22:01:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155551#M26439</guid>
      <dc:creator>_Daniel_</dc:creator>
      <dc:date>2022-08-23T22:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155552#M26440</link>
      <description>&lt;P&gt;Oh yes we had the VS issue as well. One of the cluster members SIC was showing as initiating.&lt;BR /&gt;reboot didn't help us.&amp;nbsp;sk97833 did though&lt;BR /&gt;Pulling the cert to the gateway. I think I needed to delete the current initiating cert but can't remember.&lt;/P&gt;&lt;P&gt;[Expert@HostName]# vsenv &amp;lt;relevant VSID&amp;gt;&lt;BR /&gt;[Expert@HostName]#cp_pull_cert -d -h &amp;lt;MGMT_IP&amp;gt; -n &amp;lt;VSX_Name_VS Name&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 22:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/155552#M26440</guid>
      <dc:creator>spottex</dc:creator>
      <dc:date>2022-08-23T22:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/156051#M26496</link>
      <description>&lt;P&gt;&lt;BR /&gt;If possible - reboot server to give a clean system going into upgrade - (a personal thing).&lt;/P&gt;&lt;P&gt;Backup OS level and VM level (if applicable)&lt;/P&gt;&lt;P&gt;Check system for manually edited files, and copy of manually.&lt;BR /&gt;• SMS check /conf/user.def etc&lt;BR /&gt;• GW check trac_client_1.ttm, etc.&lt;BR /&gt;• On newly installed version, edit the mentioned files, do not copy in old one.&lt;/P&gt;&lt;P&gt;Check disk space from cli with df -k, and remove large files if disk space is low&lt;/P&gt;&lt;P&gt;• find / -type f -size +100000 -exec ls -lh {} \; 2&amp;gt; /dev/null | awk '{ print $NF ": " $5 }' | sort -nk 2,2&lt;/P&gt;&lt;P&gt;Remove old snapshots&lt;/P&gt;&lt;P&gt;Upgrade DA agent&lt;/P&gt;&lt;P&gt;Install latest upgrade tools&lt;/P&gt;&lt;P&gt;Use blink preferably, contains latest HFA, less reboots.&lt;/P&gt;&lt;P&gt;In CPUSE Right Click blink image to be installed and &lt;EM&gt;Verify&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Start the upgrade, and monitor Blink log - /var/log/blink/&amp;lt;filename&amp;gt;/main_log.elg&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 20:11:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/156051#M26496</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-09-30T20:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157812#M26637</link>
      <description>&lt;P&gt;I ran into a recent issue with an R81 upgrade, where the user.def file had changed between R80.40 and R81. It caused some major issues with VPN users. It had to be manaully copied into R81.&lt;/P&gt;&lt;P&gt;Just an FYI in case this benefits someone else.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Configuring_Implied_Rules_or_Kernel_Tables_for_Security_Gateways_user.def.htm?Highlight=user.def" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Configuring_Implied_Rules_or_Kernel_Tables_for_Security_Gateways_user.def.htm?Highlight=user.def&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I guess this was the nature of my initial post. Could there be any other such .def or .conf files which require consideration between versions?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 12:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157812#M26637</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-09-22T12:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157827#M26639</link>
      <description>&lt;P&gt;Very good point, something to keep in mind, for sure!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 12:20:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157827#M26639</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-22T12:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157837#M26643</link>
      <description>&lt;P&gt;After the upgrade and the first policy is pushed to upgraded gateways, you might not be able to login into the&amp;nbsp;&lt;SPAN&gt;SmartConsole .If this occurs, check your&amp;nbsp;implied rules.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 12:57:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157837#M26643</guid>
      <dc:creator>Abi</dc:creator>
      <dc:date>2022-09-22T12:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157838#M26644</link>
      <description>&lt;P&gt;I believe thats more related to CPM process sometimes taking a bit of time, specially after upgrade and reboot. You can simply check it by running watch $FWDIR/scripts/./cpm_status.sh from expert mode and when it shows up and ready, that means console will work.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 13:00:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/157838#M26644</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-22T13:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Upgrade Tips</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/158544#M26703</link>
      <description>&lt;P&gt;Guys, Ive updated the solution here with some information which Im hoping might help with CP upgrades.. which is based on my recent upgrade experiences and challenges.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 20:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R81-Upgrade-Tips/m-p/158544#M26703</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-09-30T20:13:17Z</dc:date>
    </item>
  </channel>
</rss>

