<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best Practices for Upgrading an HA Cluster from R81.10 to R81.20 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254748#M42804</link>
    <description>&lt;P&gt;I just do it this way:&lt;/P&gt;
&lt;P&gt;-get backup of backup fw&lt;/P&gt;
&lt;P&gt;-in web UI, verify upgrade is possible&lt;/P&gt;
&lt;P&gt;-if good, upgrade to R81.20 with recommended jumbo 105&lt;/P&gt;
&lt;P&gt;-once rebooted, confirm cluster state with cphaprob state&lt;/P&gt;
&lt;P&gt;-if good, follow same process for current master&lt;/P&gt;
&lt;P&gt;-once rebooted, you can flip the cluster over (if needed&lt;/P&gt;
&lt;P&gt;No need to enable MVC, as it is on by default starting R80.40, but you can check by running cphaprob mvc&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 07 Aug 2025 15:44:52 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-08-07T15:44:52Z</dc:date>
    <item>
      <title>Best Practices for Upgrading an HA Cluster from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254747#M42803</link>
      <description>&lt;P data-start="77" data-end="262"&gt;Hi everyone,&lt;BR data-start="89" data-end="92" /&gt;In a few days, I’ll be performing an upgrade of an HA cluster from R81.10 to R81.20, and I was wondering if anyone here has already done this kind of operation on-site.&lt;/P&gt;
&lt;P data-start="264" data-end="402"&gt;What steps do you usually follow?&lt;BR data-start="297" data-end="300" /&gt;Do you typically go for a fresh install and then migrate the data from the old version to the new one?&lt;/P&gt;
&lt;P data-start="404" data-end="417" data-is-last-node="" data-is-only-node=""&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2025 14:22:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254747#M42803</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-08-07T14:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Upgrading an HA Cluster from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254748#M42804</link>
      <description>&lt;P&gt;I just do it this way:&lt;/P&gt;
&lt;P&gt;-get backup of backup fw&lt;/P&gt;
&lt;P&gt;-in web UI, verify upgrade is possible&lt;/P&gt;
&lt;P&gt;-if good, upgrade to R81.20 with recommended jumbo 105&lt;/P&gt;
&lt;P&gt;-once rebooted, confirm cluster state with cphaprob state&lt;/P&gt;
&lt;P&gt;-if good, follow same process for current master&lt;/P&gt;
&lt;P&gt;-once rebooted, you can flip the cluster over (if needed&lt;/P&gt;
&lt;P&gt;No need to enable MVC, as it is on by default starting R80.40, but you can check by running cphaprob mvc&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2025 15:44:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254748#M42804</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-07T15:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Upgrading an HA Cluster from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254751#M42806</link>
      <description>&lt;P&gt;Is it full HA (management HA and firewall HA on two boxes total), a VSX cluster, or a normal HA cluster?&lt;/P&gt;
&lt;P&gt;For full HA, I would take a migrate_export (to restore to your current version if needed) and a 'migrate server' for the upgrade. I would then wipe the box, do a clean installation, and import the 'migrate server' file. This is pretty complicated. Management upgrades go wrong much more often than firewall upgrades do.&lt;/P&gt;
&lt;P&gt;For VSX, I would use 'vsx_util upgrade' on the management, reinstall one member, use 'vsx_util reconfigure' on the management to reprovision it (same process you would use to replace a failed member), then repeat on the other member(s).&lt;/P&gt;
&lt;P&gt;For a normal HA cluster, I would right-click the cluster in SmartConsole and pick Actions &amp;gt; Version Upgrade. Pick the version, hit "Install", and let it cook for about an hour. Out pops an upgraded cluster, though one without a jumbo. You can use Actions &amp;gt; Install Hotfix/Jumbo to handle that. This method is super simple, and there's no opportunity to forget a step and cause an outage.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2025 16:15:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254751#M42806</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-08-07T16:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Upgrading an HA Cluster from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254787#M42817</link>
      <description>&lt;P&gt;Thank you very much. Yes, it’s a normal HA (active-standby), so there’s no major problem doing it from SmartConsole. Also, by doing it this way, the current configuration will remain, right?&amp;nbsp;You’ll just need to apply the JHF afterward.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 07:12:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254787#M42817</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-08-08T07:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices for Upgrading an HA Cluster from R81.10 to R81.20</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254795#M42820</link>
      <description>&lt;P&gt;Yes, upgrading with CDT in SmartConsole keeps the CLI config. Internally, it's running the upgrade using the same steps you would use on the command line, it's just doing all the steps in order &lt;EM&gt;for you&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;And of course, the rule config lives on the management, which isn't directly affected by a firewall upgrade.&lt;/P&gt;
&lt;P&gt;I would take a manual snapshot ahead of time so you can revert if the upgrade goes wrong, but it has been a few years since this upgrade method has gone wrong for me.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Aug 2025 12:56:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-Practices-for-Upgrading-an-HA-Cluster-from-R81-10-to-R81-20/m-p/254795#M42820</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-08-08T12:56:04Z</dc:date>
    </item>
  </channel>
</rss>

