<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Confusion with Security Management Upgrade Process (Primary, Secondary, Log) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184964#M30815</link>
    <description>&lt;P&gt;Ah that makes sense, thanks for the reply! So in our scenario, with all 3 of the appliances on R81.10, installing the blink package with JHF should be OK, as we're not changing Major version. Initially I wasn't sure if we'd need to update to R81.20 firstly, and then update the JHF secondly in two phases.&lt;/P&gt;&lt;P&gt;The blink package is: &lt;STRONG&gt;R81.20 Security Management + JHF T10 for Appliances and Open Servers.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;And I could be getting my documentation mixed up again, but I have a snippet saying to upgrade the primary first, would this be the best practice?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;"Primary server should be upgraded first, and should be up and running during upgrades of the Secondary Management server and Log server."&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Ah it was from the "new upgrade process" SK:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk163814" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk163814&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jun 2023 14:57:03 GMT</pubDate>
    <dc:creator>Parabol</dc:creator>
    <dc:date>2023-06-27T14:57:03Z</dc:date>
    <item>
      <title>Confusion with Security Management Upgrade Process (Primary, Secondary, Log)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184914#M30805</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We are planning to upgrade our management servers from R81.10 to R81.20. Traditionally in the past we did this all through CPUSE similar to this guide which had always been fairly simple, essentially just download and install in CPUSE.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Installation_and_Upgrade_Guide/Topics-IUG/Upgrading-SecMmgt-Servers-in-Mmgt-HA-from-R80_20-and-higher.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Installation_and_Upgrade_Guide/Topics-IUG/Upgrading-SecMmgt-Servers-in-Mmgt-HA-from-R80_20-and-higher.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However I note it says "&lt;STRONG&gt;This procedure is supported only for servers that run&amp;nbsp;&lt;SPAN class=""&gt;R80.20.M1&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;R80.20&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;R80.20.M2&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;R80.30&lt;/SPAN&gt;, or&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;R80.40"&lt;/STRONG&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;The&amp;nbsp;&lt;A href="http://sk163814" target="_self"&gt;New Upgrade Process - sk163814&lt;/A&gt;&amp;nbsp;implies it should be upgraded by running a CLI command (&lt;EM&gt;&lt;STRONG&gt;migrate_server).&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Although in the known limitations section it does say the following, implying that CPUSE upgrades can still be used:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;"CPUSE upgrades&amp;nbsp;- Installing Jumbo HF or HF can be done only after upgrade of all servers, otherwise upgrade of Secondary Management or Log Server will fail."&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;I'm quite confused with the different guides/sk's giving slightly different impressions of how it should be done. Should we be using this new method, or can the "traditional" way through CPUSE still be used?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 09:23:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184914#M30805</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-06-27T09:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Confusion with Security Management Upgrade Process (Primary, Secondary, Log)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184921#M30806</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Supported-Upgrade-Paths.htm?tocpath=Supported%20Upgrade%20Paths%7C_____0#Supported_Upgrade_Paths" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Supported-Upgrade-Paths.htm?tocpath=Supported%20Upgrade%20Paths%7C_____0#Supported_Upgrade_Paths&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Prerequisites-for-Upgrading-and-Migrating-of-Mgmt-Servers-and-Log-Servers.htm?tocpath=Upgrade%20Options%20and%20Prerequisites%7C_____1" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Guide/Content/Topics-IUG/Prerequisites-for-Upgrading-and-Migrating-of-Mgmt-Servers-and-Log-Servers.htm?tocpath=Upgrade%20Options%20and%20Prerequisites%7C_____1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 09:57:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184921#M30806</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-06-27T09:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Confusion with Security Management Upgrade Process (Primary, Secondary, Log)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184937#M30808</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first message you gave&amp;nbsp;&lt;STRONG&gt;This procedure is supported only for servers that run&amp;nbsp;&lt;SPAN class=""&gt;R80.20.M1&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;R80.20&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;R80.20.M2&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class=""&gt;R80.30&lt;/SPAN&gt;, or&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;R80.40&lt;/STRONG&gt; is from the R81 Installation and Upgrade Guide so the message was correct for that time.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;The second message&amp;nbsp;&lt;STRONG&gt;CPUSE upgrades&amp;nbsp;- Installing Jumbo HF or HF can be done only after upgrade of all servers, otherwise upgrade of Secondary Management or Log Server will fail. &lt;/STRONG&gt;refers to an issue where HF/JHF were applied before Secondary machines were upgrade to the same Major Version.&lt;BR /&gt;&lt;BR /&gt;Adding&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32"&gt;@Liat_Cihan&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27826"&gt;@IrinaK&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 12:03:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184937#M30808</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-06-27T12:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Confusion with Security Management Upgrade Process (Primary, Secondary, Log)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184940#M30809</link>
      <description>&lt;P&gt;I had done simlar before and what I followd was this...secondary, then primary, then jumbo on both, lastly log server. That seemed to work fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 12:53:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184940#M30809</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-27T12:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Confusion with Security Management Upgrade Process (Primary, Secondary, Log)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184964#M30815</link>
      <description>&lt;P&gt;Ah that makes sense, thanks for the reply! So in our scenario, with all 3 of the appliances on R81.10, installing the blink package with JHF should be OK, as we're not changing Major version. Initially I wasn't sure if we'd need to update to R81.20 firstly, and then update the JHF secondly in two phases.&lt;/P&gt;&lt;P&gt;The blink package is: &lt;STRONG&gt;R81.20 Security Management + JHF T10 for Appliances and Open Servers.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;And I could be getting my documentation mixed up again, but I have a snippet saying to upgrade the primary first, would this be the best practice?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;"Primary server should be upgraded first, and should be up and running during upgrades of the Secondary Management server and Log server."&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Ah it was from the "new upgrade process" SK:&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk163814" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk163814&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 14:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184964#M30815</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-06-27T14:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Confusion with Security Management Upgrade Process (Primary, Secondary, Log)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184966#M30816</link>
      <description>&lt;P&gt;Thanks for the feedback! I do have a snippet here relating to upgrading the primary first, it might have been in relation to the new upgrade process though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;"Primary server should be upgraded first, and should be up and running during upgrades of the Secondary Management server and Log server."&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Ah yes it's from the new upgrade process SK:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk163814" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk163814&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 14:56:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184966#M30816</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2023-06-27T14:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Confusion with Security Management Upgrade Process (Primary, Secondary, Log)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184967#M30817</link>
      <description>&lt;P&gt;Hm, I would always upgrade STANDBY first (like gateway cluster) and it always worked. So, just to make sure we are not confusing the terminology...so secondary will ALWAYS be secondary, and primary will ALWAYS be primary, but secondary can be active and primary can be standby. Now, since sk says to upgrade primary first, follow that, so in case anything gets messed up (hope not...knock on wood), if TAC case is needed, you can be sure proper recommendations were followed.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 15:04:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confusion-with-Security-Management-Upgrade-Process-Primary/m-p/184967#M30817</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-27T15:04:05Z</dc:date>
    </item>
  </channel>
</rss>

