<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HA Management upgrade issues R80.40 --&amp;gt; R81.10 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172510#M28769</link>
    <description>&lt;P&gt;Neither sk mentions ICMP. At least sk52421 should be updated to reflect this requirement for management HA environments.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2023 14:51:27 GMT</pubDate>
    <dc:creator>David_C1</dc:creator>
    <dc:date>2023-02-23T14:51:27Z</dc:date>
    <item>
      <title>HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/171967#M28695</link>
      <description>&lt;P&gt;Yesterday I attempted to upgrade our lab HA Smart-1 appliances from R80.40 to R81.10. I decided to do an in-place upgrade using CPUSE. High level procedure:&lt;BR /&gt;1. Upgrade CPUSE to latest on each appliance&lt;BR /&gt;2. Install (manually) the R81.10 upgrade tools package on each appliance&lt;BR /&gt;3. Run the upgrade verifier on each appliance. This did not report any issues on either appliance except to remind me to install JHFA after the upgrade&lt;BR /&gt;4. Take appropriate backups&lt;BR /&gt;5. Upgrade the primary/active. This completed without issue.&lt;BR /&gt;6. Install JHFA Take 87 on the primary&lt;BR /&gt;7. Confirm SmartConsole access, successfully pushed policy&lt;/P&gt;
&lt;P&gt;This is where it got interesting.&lt;BR /&gt;8. Attempted to upgrade the standby, but no upgrade option was available. After verification was run again, I got this result:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Standby verification.jpg" style="width: 485px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19666i89915BB0500C70B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Standby verification.jpg" alt="Standby verification.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;(The primary server was upgraded and running).&lt;/P&gt;
&lt;P&gt;I fought with this for a while. I even rolled back to a snapshot on the standby I created before starting any upgrades, but still was not given the option to upgrade the standby, only a clean install. I eventually went through with the clean install and everything is back up and running, but I curious if anyone else has seen this, I did something wrong, or I missed something in the upgrade documentation.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 16:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/171967#M28695</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-02-18T16:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/171968#M28696</link>
      <description>&lt;P&gt;Hi David&lt;/P&gt;
&lt;P&gt;I have sent the details to relevant R&amp;amp;D owners so that they can look at the issue.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 16:57:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/171968#M28696</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-02-18T16:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172069#M28719</link>
      <description>&lt;P&gt;I did find that ICMP was being dropped from the secondary mgmt server to the primary management server (the two SMS servers are in different datacenters behind firewalls, i.e. no unfiltered communication) during the general times I was attempting to upgrade the secondary. Could it be this simple?&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 14:41:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172069#M28719</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-02-20T14:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172082#M28727</link>
      <description>&lt;P&gt;To answer my own question...yes, it can be that simple. After seeing the ICMP drops in the logs, I found sk179794, this tipped me off that the failed ICMP could be the cause. Apparently, as part of the secondary's verification that the primary has been upgraded, it tries to ping the primary. If this fails, the verification fails. Although it may be unusual to have HA management servers with firewalls between them, having this requirement in the upgrade documentation would have saved me several hours of work.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 16:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172082#M28727</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-02-20T16:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172122#M28730</link>
      <description>&lt;P&gt;Thank you for the update. There are definitely two issues we need to improve:&lt;/P&gt;
&lt;P&gt;1) Improve message given in CPUSE stating that the Primary Management Server should be up and running but also reachable by the Secondary Management Server.&lt;/P&gt;
&lt;P&gt;2) Add this requirement to the Installation and Upgrade Administration Guide.&lt;/P&gt;
&lt;P&gt;I'll send the requirements to the relevant R&amp;amp;D owners.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 06:53:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172122#M28730</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-02-21T06:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172124#M28731</link>
      <description>&lt;P&gt;My suggestion is to be more specific what does it mean "Primary management is up and running and is reachable from Secondary management". Up and running means I see login prompt. But it doesnt say that all the proccesses must be up. The same for "reachable". What does it mean exactly ? I can ping them each other = is reachable? Or any API call must be successful ? Or ssh connection possible ? or some specific port must be listening ?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 07:08:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172124#M28731</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-02-21T07:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172125#M28732</link>
      <description>&lt;P&gt;I faced exactly the same issue. The issue was that I have installed Jumbo Hotfix on upgraded Primary Management while Secondary was not yet upgraded. You need to upgrade Primary while NOT installing any hotfix. Then upgrade Secondary. Once Secondary is upgraded, install all needed hotfixes on Primary, then on Secondary.&lt;/P&gt;
&lt;P&gt;It is also mentioned in the &lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Installation_and_Upgrade_Guide/Topics-IUG/Upgrading-MDSs-in-Mgmt-HA-from-R80_20-and-higher-with-CPUSE.htm?tocpath=Upgrade%20of%20Multi-Domain%20Servers%20and%20Multi-Domain%20Log%20Servers%7CUpgrading%20Multi-Domain%20Servers%20in%20High%20Availability%20from%20R80.20%20and%20higher%7C_____1" target="_blank" rel="noopener"&gt;upgrade guide:&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="Important_Note"&gt;Important&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;- Before you can install&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_hotfixes variable"&gt;Hotfixes&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;on servers that work in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_mgmt_ha variable"&gt;Management High Availability&lt;/SPAN&gt;&lt;SPAN&gt;, you must upgrade all these servers.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 07:16:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172125#M28732</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-02-21T07:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172170#M28738</link>
      <description>&lt;P&gt;Interesting...after I allowed ICMP between the managers, I was able to upgrade the secondary (I rolled back to an R80.40 snapshot on the secondary) and I had installed JHFA Take 87 on the primary before upgrading the secondary. No issues.&lt;/P&gt;
&lt;P&gt;I will however likely adjust my procedure when it's time to upgrade the production managers.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 13:34:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172170#M28738</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-02-21T13:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172438#M28760</link>
      <description>&lt;P&gt;Processes required for MGMT functionality are mentioned in&amp;nbsp;&lt;SPAN&gt;sk97638, Management Server section. Ports required for management communication are listed in&amp;nbsp;sk52421, management section again.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 08:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172438#M28760</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-02-23T08:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: HA Management upgrade issues R80.40 --&gt; R81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172510#M28769</link>
      <description>&lt;P&gt;Neither sk mentions ICMP. At least sk52421 should be updated to reflect this requirement for management HA environments.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 14:51:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HA-Management-upgrade-issues-R80-40-gt-R81-10/m-p/172510#M28769</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-02-23T14:51:27Z</dc:date>
    </item>
  </channel>
</rss>

