<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Maestro Upgrade in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275205#M4128</link>
    <description>&lt;P&gt;Maestro R81.20 → R82 Zero-Downtime MVC Upgrade – Upgraded SGM stuck in Down(R82) / DETACHED with FSYNC, POLICY, during_upgrade PNOTE&lt;BR /&gt;Problem Description:&lt;BR /&gt;I am performing a Zero-Downtime Multi-Version Cluster (MVC) upgrade on a Quantum Maestro Security Group from R81.20 to R82.&lt;BR /&gt;Environment:&lt;/P&gt;&lt;P&gt;Management Server: R82&lt;BR /&gt;Both Maestro Orchestrators (MHOs): R82&lt;BR /&gt;Security Group has 2 SGMs:&lt;BR /&gt;SGM 1_01 → Upgraded to R82&lt;BR /&gt;SGM 2 → Still on R81.20 Jumbo HF Take 119&lt;/P&gt;&lt;P&gt;Mode: [Please specify: Gateway mode or Traditional VSX mode?]&lt;/P&gt;&lt;P&gt;Current Symptoms:&lt;/P&gt;&lt;P&gt;The upgraded member (1_01) is stuck in Down(R82) state and shows as DETACHED in asg monitor.&lt;BR /&gt;Security Group status shows: Maestro (During Upgrade)&lt;BR /&gt;PNOTE on member 1_01: FSYNC, POLICY, during_upgrade&lt;BR /&gt;Previously also saw: "Site HA module not started"&lt;BR /&gt;Only SGM 2 (R81.20) is ACTIVE and handling traffic.&lt;BR /&gt;Policy installation fails with the classic error:&lt;BR /&gt;"Policy installation failed because the gateway version as defined in the SmartConsole does not match the version installed on the gateway."&lt;/P&gt;&lt;P&gt;Actions Already Performed:&lt;/P&gt;&lt;P&gt;Upgraded Management + both Orchestrators to R82 first.&lt;BR /&gt;Disabled SMO image auto-cloning (set smo image auto-clone state off).&lt;BR /&gt;Changed the Maestro Security Group object version to R82 in SmartConsole (multiple times) + Get Gateway Data.&lt;BR /&gt;Disabled Accelerated Policy Installation and attempted policy install multiple times.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Apr 2026 14:26:53 GMT</pubDate>
    <dc:creator>gemechis</dc:creator>
    <dc:date>2026-04-09T14:26:53Z</dc:date>
    <item>
      <title>Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275205#M4128</link>
      <description>&lt;P&gt;Maestro R81.20 → R82 Zero-Downtime MVC Upgrade – Upgraded SGM stuck in Down(R82) / DETACHED with FSYNC, POLICY, during_upgrade PNOTE&lt;BR /&gt;Problem Description:&lt;BR /&gt;I am performing a Zero-Downtime Multi-Version Cluster (MVC) upgrade on a Quantum Maestro Security Group from R81.20 to R82.&lt;BR /&gt;Environment:&lt;/P&gt;&lt;P&gt;Management Server: R82&lt;BR /&gt;Both Maestro Orchestrators (MHOs): R82&lt;BR /&gt;Security Group has 2 SGMs:&lt;BR /&gt;SGM 1_01 → Upgraded to R82&lt;BR /&gt;SGM 2 → Still on R81.20 Jumbo HF Take 119&lt;/P&gt;&lt;P&gt;Mode: [Please specify: Gateway mode or Traditional VSX mode?]&lt;/P&gt;&lt;P&gt;Current Symptoms:&lt;/P&gt;&lt;P&gt;The upgraded member (1_01) is stuck in Down(R82) state and shows as DETACHED in asg monitor.&lt;BR /&gt;Security Group status shows: Maestro (During Upgrade)&lt;BR /&gt;PNOTE on member 1_01: FSYNC, POLICY, during_upgrade&lt;BR /&gt;Previously also saw: "Site HA module not started"&lt;BR /&gt;Only SGM 2 (R81.20) is ACTIVE and handling traffic.&lt;BR /&gt;Policy installation fails with the classic error:&lt;BR /&gt;"Policy installation failed because the gateway version as defined in the SmartConsole does not match the version installed on the gateway."&lt;/P&gt;&lt;P&gt;Actions Already Performed:&lt;/P&gt;&lt;P&gt;Upgraded Management + both Orchestrators to R82 first.&lt;BR /&gt;Disabled SMO image auto-cloning (set smo image auto-clone state off).&lt;BR /&gt;Changed the Maestro Security Group object version to R82 in SmartConsole (multiple times) + Get Gateway Data.&lt;BR /&gt;Disabled Accelerated Policy Installation and attempted policy install multiple times.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 14:26:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275205#M4128</guid>
      <dc:creator>gemechis</dc:creator>
      <dc:date>2026-04-09T14:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275208#M4129</link>
      <description>&lt;P&gt;Just for curiosity, did you follow this procedure?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Content/Topics-SPG/Maestro/Upgrading-Maestro-Zero-Downtime-MVC.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Content/Topics-SPG/Maestro/Upgrading-Maestro-Zero-Downtime-MVC.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 14:45:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275208#M4129</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-09T14:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275212#M4130</link>
      <description>&lt;P&gt;I have tried Step 9 from these, but not succeded.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 15:22:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275212#M4130</guid>
      <dc:creator>gemechis</dc:creator>
      <dc:date>2026-04-09T15:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275214#M4131</link>
      <description>&lt;P&gt;Did you also tried the command&amp;nbsp;&lt;CODE&gt;g_clusterXL_admin –b 1_1 up&lt;/CODE&gt;?&lt;/P&gt;
&lt;P&gt;1_1 should your member with ID 1 (the upgraded member).&lt;/P&gt;
&lt;P&gt;and after that tried the command&amp;nbsp;&lt;CODE&gt;g_clusterXL_admin –b 1_2 down&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;1_2 should be the member in R81.20, and then try to install the policy ... but it could be better to complete the upgrade to R82 for all the members.&lt;CODE&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 15:50:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275214#M4131</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-09T15:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275226#M4132</link>
      <description>&lt;P&gt;Can I just check, when you say "&lt;SPAN&gt;Changed the Maestro Security Group object version to R82 in SmartConsole (multiple times) + &lt;STRONG&gt;Get Gateway Data&lt;/STRONG&gt;."&amp;nbsp; Do you mean you clicked "Get" on the right of the SecGroup object?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If yes, you should not, as the 1st step (manually changing the setting) tells the system to use R82 (in your case), and then clicking Get, queries the running Sec Group, and the old member which is active (but still on R81.20) will say "I'm on 81.20" and revert the change you made, causing the policy push to fail due to version mismatch, the upgraded member to likely not leave the DOWN(Policy) state...&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That would be my thing to check first.&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_187d97d98b8158Tom_Kendrick_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 19:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275226#M4132</guid>
      <dc:creator>Tom_Kendrick</dc:creator>
      <dc:date>2026-04-09T19:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275242#M4133</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2895"&gt;@Tom_Kendrick&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;yes i mean I clicked Get.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But even without clicking the GET , i have tried and it still fails. Below are the screneshots for your refernece.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2026 06:52:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275242#M4133</guid>
      <dc:creator>gemechis</dc:creator>
      <dc:date>2026-04-10T06:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275243#M4134</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/79070"&gt;@simonemantovani&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;g_clusterXL_admin –b 1_1 up tried this, and it gave an error as per the attached screenshot.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2026 06:56:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275243#M4134</guid>
      <dc:creator>gemechis</dc:creator>
      <dc:date>2026-04-10T06:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275245#M4135</link>
      <description>&lt;P&gt;What happens if you try from the upgrade member the following command?&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;fw -d fetch -a -s -f -c&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2026 07:51:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275245#M4135</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-10T07:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275246#M4136</link>
      <description>&lt;P&gt;Make sure you're installing just the Access Control policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2026 08:04:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275246#M4136</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-10T08:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Upgrade</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275305#M4137</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2895"&gt;@Tom_Kendrick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/79070"&gt;@simonemantovani&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you guys for the help. Finally, it's solved by installing the latest hotfix which Take 91 on R82 on both SMS and the upgraded gateway.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Apr 2026 08:50:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Upgrade/m-p/275305#M4137</guid>
      <dc:creator>gemechis</dc:creator>
      <dc:date>2026-04-11T08:50:14Z</dc:date>
    </item>
  </channel>
</rss>

