<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrading an standalone cluster offline in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207503#M34428</link>
    <description>&lt;P&gt;Absolute worst case, this process should get you to R80.40:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use ISOmorphic and the R81.20 ISO image to build an R81.20 installation drive. Use R81.20, as it has some fixes during the installation which persist even when you downgrade. Some of these fixes make disk access dramatically faster, so the import in step 9 won't take as long.&lt;/LI&gt;
&lt;LI&gt;Use the upgrade tools ('migrate server', I think; might be 'migrate export' on R77.30) on your existing primary management (note, this may not be your active management; I forget how to confirm which one is primary on R77.30 full HA) to export a copy of your management config.&lt;/LI&gt;
&lt;LI&gt;Save a copy of the clish config.&lt;/LI&gt;
&lt;LI&gt;Use the R81.20 thumb drive to wipe one node and install R81.20 on it.&lt;/LI&gt;
&lt;LI&gt;Import the R80.40 package to CPUSE.&lt;/LI&gt;
&lt;LI&gt;Use 'installer clean-install Check_Point_R80.40_T294_Fresh_Install_and_Upgrade.tgz' to downgrade in-place to R80.40.&lt;/LI&gt;
&lt;LI&gt;Go through the first-time config. This can be done with the web UI, but I prefer the command line tool config_system.&lt;/LI&gt;
&lt;LI&gt;After rebooting, apply your clish config.&lt;/LI&gt;
&lt;LI&gt;Use the upgrade tools to import the config into the R80.40 member. Management sync will not work, but you should be able to log in to the R80.40 member with SmartConsole and see all your rules and objects.&lt;/LI&gt;
&lt;LI&gt;Push policy from the R80.40 member to itself. Be sure to uncheck the box which says to push to both cluster members.&lt;/LI&gt;
&lt;LI&gt;Install jumbo 206 on the R80.40 member.&lt;/LI&gt;
&lt;LI&gt;Enable cross-version sync on the R80.40 member (cphaconf mvc on). After a few seconds, the firewall software should go from Ready to Standby.&lt;/LI&gt;
&lt;LI&gt;Fail over from the R77.30 member to the R80.40 member.&lt;/LI&gt;
&lt;LI&gt;Repeat steps 3-8 and 11 on the second member. No need to do the management-side stuff again, since it will just synchronize with the existing R80.40 member.&lt;/LI&gt;
&lt;LI&gt;Establish SIC trust from the management to the second member. Start the management sync.&lt;/LI&gt;
&lt;LI&gt;Push policy to both members.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Check Point's big advantage to me is it's just software. Except at the low end (Quantum Spark) and high end (Maestro, Quantum LightSpeed), their hardware is nothing special; it's just overpriced x86 servers with weird card slots. This is relevant here because their software works just as well in a VM as it does on real hardware.&lt;/P&gt;
&lt;P&gt;Build some VMs and try this process at least once. I probably forgot something in that list of steps. Testing it on VMs will help confirm the process works before you try it on your production boxes. This process is complicated enough I would try it several times. Back when I was doing upgrades by hand, I would try most of my significant upgrades in VMs at least 20 times to build familiarity before trying them for real.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Feb 2024 19:06:47 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2024-02-29T19:06:47Z</dc:date>
    <item>
      <title>Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206875#M34333</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;We've got an standalone cluster (that is, two machines, both SG and MGMT, un MGMT primary, the other secondary) still in R77.30 and with no connection to the Internet.&lt;/P&gt;&lt;P&gt;So the challenge is to upgrade them to R81.10 (we are not using R81.20 yet). I expected that getting the package from Check Point, copying the file to the appliances and doing an installer import local would be enough. But CPUSE says it's not a valid CPUSE package.&lt;/P&gt;&lt;P&gt;I've tried also getting the package from a same series appliance (5xxxx), copying it to the appliances, installer import... Nothing. Same result.&lt;/P&gt;&lt;P&gt;Could anybody please point me to the correct packages to download?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:17:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206875#M34333</guid>
      <dc:creator>Jose_Luis_Mart1</dc:creator>
      <dc:date>2024-02-22T16:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206877#M34334</link>
      <description>&lt;P&gt;So you have full-HA? 2&amp;nbsp;standalone in a cluster? I wish upgrade wizard was available, but it is not. Maybe contact TAC to confirm the right package...do you see anything from web UI that shows as valid if you right click and verify for upgrade?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206877#M34334</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T16:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206879#M34336</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, WebUI is another problem. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; It's an R77.30 and the machines we have to acces it don't have Internet Explorer anymore. I've tried an old Firefox portable and nothing.&lt;/P&gt;&lt;P&gt;Anyway, I'm going through command line with installer. And since it gets no packages, nothing to verify...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think you are right, I can ask TAC the right way to do this. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206879#M34336</guid>
      <dc:creator>Jose_Luis_Mart1</dc:creator>
      <dc:date>2024-02-22T16:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206881#M34338</link>
      <description>&lt;P&gt;Try this, its an old trick I used to do for who knows how long...do windows + R, type iexplore and see if that works, though that may open edge browser lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:46:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206881#M34338</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T16:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206885#M34339</link>
      <description>&lt;P&gt;I also found that sometimes it works in private window (any browser really, but most likely Google Chrome)&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 17:04:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206885#M34339</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T17:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206900#M34340</link>
      <description>&lt;P&gt;You should upgrade in at least two steps. One to &lt;A href="https://support.checkpoint.com/results/download/101084" target="_self"&gt;R80.40&lt;/A&gt;, then one to &lt;A href="https://support.checkpoint.com/results/download/115152" target="_self"&gt;R81.10&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;If you aren't already running &lt;A href="https://support.checkpoint.com/results/download/80931" target="_self"&gt;CPUSE 2379&lt;/A&gt;, you may also need to update it manually.&lt;/P&gt;
&lt;P&gt;Note that there are some significant OS improvements you don't get from an upgrade (filesystem, partition table alignment, etc.). You should eventually reinstall from scratch at R81.20 using &lt;A href="https://support.checkpoint.com/results/sk/sk65205" target="_self"&gt;ISOmorphic&lt;/A&gt;. You can bring your configuration over, but it takes a few extra steps. You should start researching and planning all that now.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 18:51:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206900#M34340</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-02-22T18:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206902#M34341</link>
      <description>&lt;P&gt;Excellent point Bob.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 18:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/206902#M34341</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T18:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207004#M34356</link>
      <description>&lt;P&gt;You are right, hadn't noticed till now that the management needs a two step with R80.40 as the first one. That's probably why currently cpuse is saying the R81.10 packages are not right.&lt;/P&gt;&lt;P&gt;So, more work to do... Nice... &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 10:18:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207004#M34356</guid>
      <dc:creator>Jose_Luis_Mart1</dc:creator>
      <dc:date>2024-02-23T10:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207010#M34357</link>
      <description>&lt;P&gt;Is web ui still broken?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 12:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207010#M34357</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T12:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207462#M34418</link>
      <description>&lt;P&gt;Hi! Yes, no way to get an IE working to access WebUI. But no problem, I can work on CLI.&lt;/P&gt;&lt;P&gt;I'm still struggling anyway. Now I've tried to import locally the R80.40 upgrade package and... again, installer says it is not a valid CPUSE package.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess next try is to upgrade installer, but I wonder if an R77.30 is going to accept the latest version&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 11:51:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207462#M34418</guid>
      <dc:creator>Jose_Luis_Mart1</dc:creator>
      <dc:date>2024-02-29T11:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207470#M34421</link>
      <description>&lt;P&gt;There is command to trey update it from cli, I mean da agent, not sure if it works in R77.30...&lt;/P&gt;
&lt;P&gt;Here it is in R81.20&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can simply type da_cli, hit enter and it will give all the options&lt;/P&gt;
&lt;P&gt;[Expert@cpazurecluster1:0]# da_cli check_for_updates&lt;BR /&gt;{&lt;BR /&gt;"Action ID" : "-1",&lt;BR /&gt;"Message" : "Checking for new available packages. This operation may take a few moments"&lt;BR /&gt;}&lt;/P&gt;
&lt;P&gt;[Expert@cpazurecluster1:0]#&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 13:16:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207470#M34421</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-29T13:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207503#M34428</link>
      <description>&lt;P&gt;Absolute worst case, this process should get you to R80.40:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Use ISOmorphic and the R81.20 ISO image to build an R81.20 installation drive. Use R81.20, as it has some fixes during the installation which persist even when you downgrade. Some of these fixes make disk access dramatically faster, so the import in step 9 won't take as long.&lt;/LI&gt;
&lt;LI&gt;Use the upgrade tools ('migrate server', I think; might be 'migrate export' on R77.30) on your existing primary management (note, this may not be your active management; I forget how to confirm which one is primary on R77.30 full HA) to export a copy of your management config.&lt;/LI&gt;
&lt;LI&gt;Save a copy of the clish config.&lt;/LI&gt;
&lt;LI&gt;Use the R81.20 thumb drive to wipe one node and install R81.20 on it.&lt;/LI&gt;
&lt;LI&gt;Import the R80.40 package to CPUSE.&lt;/LI&gt;
&lt;LI&gt;Use 'installer clean-install Check_Point_R80.40_T294_Fresh_Install_and_Upgrade.tgz' to downgrade in-place to R80.40.&lt;/LI&gt;
&lt;LI&gt;Go through the first-time config. This can be done with the web UI, but I prefer the command line tool config_system.&lt;/LI&gt;
&lt;LI&gt;After rebooting, apply your clish config.&lt;/LI&gt;
&lt;LI&gt;Use the upgrade tools to import the config into the R80.40 member. Management sync will not work, but you should be able to log in to the R80.40 member with SmartConsole and see all your rules and objects.&lt;/LI&gt;
&lt;LI&gt;Push policy from the R80.40 member to itself. Be sure to uncheck the box which says to push to both cluster members.&lt;/LI&gt;
&lt;LI&gt;Install jumbo 206 on the R80.40 member.&lt;/LI&gt;
&lt;LI&gt;Enable cross-version sync on the R80.40 member (cphaconf mvc on). After a few seconds, the firewall software should go from Ready to Standby.&lt;/LI&gt;
&lt;LI&gt;Fail over from the R77.30 member to the R80.40 member.&lt;/LI&gt;
&lt;LI&gt;Repeat steps 3-8 and 11 on the second member. No need to do the management-side stuff again, since it will just synchronize with the existing R80.40 member.&lt;/LI&gt;
&lt;LI&gt;Establish SIC trust from the management to the second member. Start the management sync.&lt;/LI&gt;
&lt;LI&gt;Push policy to both members.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Check Point's big advantage to me is it's just software. Except at the low end (Quantum Spark) and high end (Maestro, Quantum LightSpeed), their hardware is nothing special; it's just overpriced x86 servers with weird card slots. This is relevant here because their software works just as well in a VM as it does on real hardware.&lt;/P&gt;
&lt;P&gt;Build some VMs and try this process at least once. I probably forgot something in that list of steps. Testing it on VMs will help confirm the process works before you try it on your production boxes. This process is complicated enough I would try it several times. Back when I was doing upgrades by hand, I would try most of my significant upgrades in VMs at least 20 times to build familiarity before trying them for real.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 19:06:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/207503#M34428</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-02-29T19:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/210452#M34840</link>
      <description>&lt;P&gt;Hi! Still working on this. I'm stuck on the migrate import step.&lt;/P&gt;&lt;P&gt;After a while importing I get an error saying import has failed. Checking the migrate log file:&lt;/P&gt;&lt;P&gt;[4 Apr 15:41:51] [ExecCommandGetOutput] Going to execute command: '"/opt/CPsuite-R80.40/fw1/bin/upgrade_tools/././/ips_upgrade_tool" import "/opt/CPsuite-R80.40/fw1/tmp/migrate/regular_files/fwdir/tmp/ips_files" "/opt/CPsuite-R80.40/fw1/bin/upgrade_tools/././/"'&lt;BR /&gt;[4 Apr 15:41:52] [ExecCommandGetOutput] Command completed with an exit code 1&lt;BR /&gt;[4 Apr 15:41:52] [ExecCommandGetOutput] ERR: The given exit code indicates an error&lt;BR /&gt;[4 Apr 15:41:52] ...&amp;lt;-- ExecCommandGetOutput&lt;BR /&gt;[4 Apr 15:41:52] [CommandRunner::exec] ERR: Command execution had failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then in the ips upgrade log file:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[4 Apr 15:41:52] [ReadFwsetFile] Going to read file '/opt/CPsuite-R80.40/fw1/tmp&lt;BR /&gt;/migrate/regular_files/fwdir/tmp/ips_files/ips_upgrade_tool.conf'&lt;BR /&gt;[4 Apr 15:41:52] [ReadFwsetFile] ERR: Failed to open file: No such file or direc&lt;BR /&gt;tory&lt;BR /&gt;[4 Apr 15:41:52] ..&amp;lt;-- ReadFwsetFile&lt;BR /&gt;[4 Apr 15:41:52] .&amp;lt;-- GetConfigFileSet&lt;BR /&gt;[4 Apr 15:41:52] [RunSMCImport] ERR: Failed to read configuration file!&lt;BR /&gt;[4 Apr 15:41:52] &amp;lt;-- RunSMCImport&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea? Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 13:50:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/210452#M34840</guid>
      <dc:creator>Jose_Luis_Mart1</dc:creator>
      <dc:date>2024-04-04T13:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/210453#M34841</link>
      <description>&lt;P&gt;Appears something wrong with config file, thats final error it gives...did you ever open TAC case on it?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 13:55:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/210453#M34841</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-04T13:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an standalone cluster offline</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/210457#M34842</link>
      <description>&lt;P&gt;I'm on it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 14:05:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Upgrading-an-standalone-cluster-offline/m-p/210457#M34842</guid>
      <dc:creator>Jose_Luis_Mart1</dc:creator>
      <dc:date>2024-04-04T14:05:49Z</dc:date>
    </item>
  </channel>
</rss>

