<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro + VSX - MDS Upgrade from R81.20 to R82 in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/267012#M3906</link>
    <description>&lt;P&gt;Last year I was verifying a Maestro upgrade (R81.20 to R82) in a lab environment. The setup is exactly what you mentioned (MDS + Maestro + VSX).&lt;/P&gt;&lt;P&gt;I cannot say much about the MDS upgrade, but the Maestro environment is pretty much unaffected by this anyway.&lt;/P&gt;&lt;P&gt;For the Maestro upgrade stick to the procedure in the Admin Guide. This should be pretty much straight forward:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Content/Topics-SPG/Maestro/Upgrading-Maestro-Zero-Downtime-MVC.htm?tocpath=Working%20with%20Quantum%20Maestro%20%7CUpgrading%20Maestro%20to%20R82%20%7C_____1" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Content/Topics-SPG/Maestro/Upgrading-Maestro-Zero-Downtime-MVC.htm?tocpath=Working%20with%20Quantum%20Maestro%20%7CUpgrading%20Maestro%20to%20R82%20%7C_____1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I took some notes during the upgrade procedure because I ran into several problems. They may or may not have been fixed in a more recent JHF take.&lt;/P&gt;&lt;P&gt;In general be aware, that you have to update the CPUSE agent to 2550 or higher and install JHF take 92 or higher before you upgrade the MHO or SG (&lt;A href="https://support.checkpoint.com/results/sk/sk181127" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181127&lt;/A&gt;). This may take a lot of time, especially on the SGM. Also run the HCP utility before you upgrade to avoid troubleshooting errors which existed before already. HCP will be your friend, especially after the upgrade.&lt;/P&gt;&lt;P&gt;The MHO upgrade went through pretty much seamless. Just be aware, that the disk space on the MHO is very limited. Delete any existing snapshots and do not upload JHF or upgrade packages to the disk. Instead download or upload them directly to the CPUSE repository -&amp;gt; avoid using "installer import local".&lt;/P&gt;&lt;P&gt;The upgrade for the SG was also not really an issue and worked as described in the guide (including vsx_util upgrade). However, after running hcp again after the upgrade I noticed several issues:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HCP Post Upgrade Verifier (check 109). MVC was not turned off automatically after the last SGM was upgraded. HCP adviced me to run "sp_upgrade cleanup_upgrade" which did not fix the issue. Instead I ran "g_all chpaconf mvc off", which the cleanup script should do anyway.&lt;/LI&gt;&lt;LI&gt;HCP Policy in Security Group (check 108). The FW policy for the VS had a signature mismatch on the SGM. I opened an SR with support and we were able to fix it by deleting all policy files in the VS context -&amp;gt; rm -rf $FWDIR/state/__tmp/FW1/*; rm -rf $FWDIR/state/local/FW1/*. And then installing the policy again. This fixed the issue.&lt;/LI&gt;&lt;LI&gt;I was not able to view the performance statistics for a VS in Insights. Insights just crashed when doing so. Same for the new "cluster-cli" command which was introduced for Maestro in R82. I opened another SR. It looks like a daemon is not registered correctly when doing an upgrade. We fixed it by running "stats-streamer-cli daemon register". You have to run this on each SGM locally. Do not run it with g_all, since this does not work.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Apart from those issues, I had no other problems and and everything went as expected.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jan 2026 09:34:58 GMT</pubDate>
    <dc:creator>Serge_Wuethrich</dc:creator>
    <dc:date>2026-01-12T09:34:58Z</dc:date>
    <item>
      <title>Maestro + VSX - MDS Upgrade from R81.20 to R82</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/266984#M3902</link>
      <description>&lt;P&gt;I have a similar requirement as well this year to upgrade from R81.20 to R82.&lt;BR /&gt;The customer environment is based on Maestro + VSX, which I believe makes the upgrade even more complex.&lt;BR /&gt;I’d really appreciate hearing from anyone who has gone through a similar upgrade, and any lessons learned or pitfalls to watch out for.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 08:25:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/266984#M3902</guid>
      <dc:creator>Vanness_Chen</dc:creator>
      <dc:date>2026-01-12T08:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: MDS Upgrade from R81.20 to R82</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/266991#M3903</link>
      <description>&lt;P&gt;Probably best to open a new thread for your question/s.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Be sure to read all the R82 documentation that is relevant (links above) and pay attention to the VSX parts and Maestro parts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Content/Topics-RN/Supported-Upgrade-Paths.htm?tocpath=Supported%20Upgrade%20Paths%20in%20R82%7C_____0#Supported_Upgrade_Paths_in_R82" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Content/Topics-RN/Supported-Upgrade-Paths.htm?tocpath=Supported%20Upgrade%20Paths%20in%20R82%7C_____0#Supported_Upgrade_Paths_in_R82&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you can test upgrades and procedures in the lab first that will be a big benefit.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 07:48:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/266991#M3903</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2026-01-12T07:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: MDS Upgrade from R81.20 to R82</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/266993#M3904</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/118758"&gt;@Vanness_Chen&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18248"&gt;@Don_Paterson&lt;/a&gt;&amp;nbsp;I moved the discussion to the Maestro space and changed the title, for convenience&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 08:27:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/266993#M3904</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2026-01-12T08:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - MDS Upgrade from R81.20 to R82</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/266996#M3905</link>
      <description>&lt;P&gt;Thil will a really interesting topic &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 08:36:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/266996#M3905</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2026-01-12T08:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - MDS Upgrade from R81.20 to R82</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/267012#M3906</link>
      <description>&lt;P&gt;Last year I was verifying a Maestro upgrade (R81.20 to R82) in a lab environment. The setup is exactly what you mentioned (MDS + Maestro + VSX).&lt;/P&gt;&lt;P&gt;I cannot say much about the MDS upgrade, but the Maestro environment is pretty much unaffected by this anyway.&lt;/P&gt;&lt;P&gt;For the Maestro upgrade stick to the procedure in the Admin Guide. This should be pretty much straight forward:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Content/Topics-SPG/Maestro/Upgrading-Maestro-Zero-Downtime-MVC.htm?tocpath=Working%20with%20Quantum%20Maestro%20%7CUpgrading%20Maestro%20to%20R82%20%7C_____1" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Content/Topics-SPG/Maestro/Upgrading-Maestro-Zero-Downtime-MVC.htm?tocpath=Working%20with%20Quantum%20Maestro%20%7CUpgrading%20Maestro%20to%20R82%20%7C_____1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I took some notes during the upgrade procedure because I ran into several problems. They may or may not have been fixed in a more recent JHF take.&lt;/P&gt;&lt;P&gt;In general be aware, that you have to update the CPUSE agent to 2550 or higher and install JHF take 92 or higher before you upgrade the MHO or SG (&lt;A href="https://support.checkpoint.com/results/sk/sk181127" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181127&lt;/A&gt;). This may take a lot of time, especially on the SGM. Also run the HCP utility before you upgrade to avoid troubleshooting errors which existed before already. HCP will be your friend, especially after the upgrade.&lt;/P&gt;&lt;P&gt;The MHO upgrade went through pretty much seamless. Just be aware, that the disk space on the MHO is very limited. Delete any existing snapshots and do not upload JHF or upgrade packages to the disk. Instead download or upload them directly to the CPUSE repository -&amp;gt; avoid using "installer import local".&lt;/P&gt;&lt;P&gt;The upgrade for the SG was also not really an issue and worked as described in the guide (including vsx_util upgrade). However, after running hcp again after the upgrade I noticed several issues:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;HCP Post Upgrade Verifier (check 109). MVC was not turned off automatically after the last SGM was upgraded. HCP adviced me to run "sp_upgrade cleanup_upgrade" which did not fix the issue. Instead I ran "g_all chpaconf mvc off", which the cleanup script should do anyway.&lt;/LI&gt;&lt;LI&gt;HCP Policy in Security Group (check 108). The FW policy for the VS had a signature mismatch on the SGM. I opened an SR with support and we were able to fix it by deleting all policy files in the VS context -&amp;gt; rm -rf $FWDIR/state/__tmp/FW1/*; rm -rf $FWDIR/state/local/FW1/*. And then installing the policy again. This fixed the issue.&lt;/LI&gt;&lt;LI&gt;I was not able to view the performance statistics for a VS in Insights. Insights just crashed when doing so. Same for the new "cluster-cli" command which was introduced for Maestro in R82. I opened another SR. It looks like a daemon is not registered correctly when doing an upgrade. We fixed it by running "stats-streamer-cli daemon register". You have to run this on each SGM locally. Do not run it with g_all, since this does not work.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Apart from those issues, I had no other problems and and everything went as expected.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 09:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-MDS-Upgrade-from-R81-20-to-R82/m-p/267012#M3906</guid>
      <dc:creator>Serge_Wuethrich</dc:creator>
      <dc:date>2026-01-12T09:34:58Z</dc:date>
    </item>
  </channel>
</rss>

