<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro R81.10 Jumbo Hotfix install in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139037#M752</link>
    <description>&lt;P&gt;&lt;CODE&gt;cphaprob list&lt;/CODE&gt;&amp;nbsp;would have been helpful to check why it was in down state.&lt;BR /&gt;Did you try to perform&amp;nbsp;&amp;nbsp;&lt;CODE&gt;cpstop&lt;/CODE&gt; on the other SGMs to check if the upgraded SGM turns active?&lt;BR /&gt;What do you mean by "&lt;FONT color="#008080"&gt;&lt;EM&gt;removed one member from the cluster&lt;/EM&gt;&lt;/FONT&gt;"? You performed a &lt;CODE&gt;cpstop&lt;/CODE&gt;?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jan 2022 21:05:11 GMT</pubDate>
    <dc:creator>Danny</dc:creator>
    <dc:date>2022-01-20T21:05:11Z</dc:date>
    <item>
      <title>Maestro R81.10 Jumbo Hotfix install</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139035#M751</link>
      <description>&lt;P&gt;I believe I have successfully migrated one of our Maestro environments from R80.20SP to R81.10. Now I've run into a problem when I attempted to install the latest Jumbo (at the time Take 22). The upgrade of the Orchestrators was not an issue, but it was during the upgrade of our security group that I ran into problems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, I downloaded the latest update and transferred it over to the security group and imported it. I then removed one member from the cluster. It was on that member that I installed Take 22. Upon a reboot, it never came Active again. It stayed in the Down state for hours. I even did a reboot of the member and it still would come back online in the Down state. I uninstalled the hotfix and returned the security group back to what it was before trying to install Take 22 on that member. The member came back up after the reboot and showed all members Active again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just curious if anyone else had attempted to update to a newer Take on their upgraded R81.10 Maestro environment and seen any issues or for that matter no issues. I see that Take 30 is now out, but I didn't see anything in it that lead me to believe it would make a difference. I should have captured what cphaprob -state showed after the upgrade on the one member, but I forgot to. If it makes a difference, I chose the member of the security group that was not the SMO. Again, shouldn't make a difference as in the past with R80.20SP I would always start with the non-SMO member when updating takes without any issue.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 19:38:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139035#M751</guid>
      <dc:creator>Trevor_Bruss</dc:creator>
      <dc:date>2022-01-20T19:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.10 Jumbo Hotfix install</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139037#M752</link>
      <description>&lt;P&gt;&lt;CODE&gt;cphaprob list&lt;/CODE&gt;&amp;nbsp;would have been helpful to check why it was in down state.&lt;BR /&gt;Did you try to perform&amp;nbsp;&amp;nbsp;&lt;CODE&gt;cpstop&lt;/CODE&gt; on the other SGMs to check if the upgraded SGM turns active?&lt;BR /&gt;What do you mean by "&lt;FONT color="#008080"&gt;&lt;EM&gt;removed one member from the cluster&lt;/EM&gt;&lt;/FONT&gt;"? You performed a &lt;CODE&gt;cpstop&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 21:05:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139037#M752</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-01-20T21:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.10 Jumbo Hotfix install</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139039#M753</link>
      <description>&lt;P&gt;My Maestro security group contains two members. I cannot risk taking the Active (non-patched) server down while the second member (patched) is in a Down state to see if it just happens to go active.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So basically, I'm following the normal Maestro instructions on how to install a jumbo hotfix on a security group. Since their are only two members in the group I begin patching with member 2, and when it is done and both members show Active I move on to doing member 1. This is the first time I'm putting a jumbo hotfix on a newly updated R81.10 Maestro environment. So the hotfix was finished installing and it rebooted member 2. When it came back up, member 2 stayed in a Down state. I'll have to run an update again to see if I can capture the cphaprob state if it fails again. It had to do with something about it not being able to communicate or sync with the other member.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 21:34:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139039#M753</guid>
      <dc:creator>Trevor_Bruss</dc:creator>
      <dc:date>2022-01-20T21:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.10 Jumbo Hotfix install</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139040#M754</link>
      <description>&lt;P&gt;My guess is that R81.10 cannot sync with R80.20SP.&lt;/P&gt;
&lt;P&gt;So after finishing your upgrade on one SGM to R81.10 JHF 30, when is stays in down state:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;log into SmartConsole and change the SGO's version to R81.10, install policy&lt;/LI&gt;
&lt;LI&gt;verify the running security policy on all SGMs via &lt;CODE&gt;fw stat&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;run &lt;CODE&gt;cphaprob stat&lt;/CODE&gt;; &lt;CODE&gt;cphaprob list&lt;/CODE&gt; on both SGMs&lt;/LI&gt;
&lt;LI&gt;in case your R81.10 SGM is still down, within a maintenance window run&amp;nbsp;&lt;CODE&gt;cpstop &amp;amp;&amp;amp; sleep 300 &amp;amp;&amp;amp; cpstart&lt;/CODE&gt;&amp;nbsp;on your R80.20SP SGM
&lt;UL&gt;
&lt;LI&gt;if your R81.10 SGM turns active, kill the sleep routine on the R80.20SP SGM&lt;/LI&gt;
&lt;LI&gt;if your R81.10 SGM stays in down state, try to install the security policy again&lt;/LI&gt;
&lt;LI&gt;if your R80.10 SGM still stays in down state, if possible run &lt;CODE&gt;cphaprob stat&lt;/CODE&gt;; &lt;CODE&gt;cphaprob list&lt;/CODE&gt;. No worries, your R80.20SP SGM will turn active again in a couple seconds&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;U&gt;Glossary:&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;SGO&lt;/STRONG&gt; - Single Gateway Object &amp;gt; Maestro Security Group object within SmartConsole that talks to the SMO&lt;BR /&gt;&lt;STRONG&gt;SGM&lt;/STRONG&gt; - Single Gateway Module/Security Group Member &amp;gt; Check Point Appliance that's part of a Security Group&lt;BR /&gt;&lt;STRONG&gt;SMO&lt;/STRONG&gt;&amp;nbsp; - Single Management Object - Active Check Point Appliance with the lowest SGM ID#&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Maestro/Check-Point-Maestro-FAQ/m-p/127280/highlight/true#M577" target="_self"&gt;Check Point Maestro - FAQ&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 22:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139040#M754</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-01-20T22:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.10 Jumbo Hotfix install</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139043#M755</link>
      <description>&lt;P&gt;My Maestro environment is &lt;STRONG&gt;already&lt;/STRONG&gt; upgrade to R81.10. My problem occurred when I began the process of installing R81.10 Jumbo Take 22 on these newly upgraded machines, specifically the security gateways as I had no problem installing the jumbo on the MHO devices. Apologies if I didn't make that clear.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 23:03:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139043#M755</guid>
      <dc:creator>Trevor_Bruss</dc:creator>
      <dc:date>2022-01-20T23:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.10 Jumbo Hotfix install</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139047#M756</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27023"&gt;@Trevor_Bruss&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had not worked with Maestro but did something similar recently on regular Quantum Security gateways running r81.10 on a HA Cluster XL. What i did is checked that clusters showed active&amp;gt;standby with cphaprob stat then did a clusterXL_admin down on Active member. After that downloaded the JHT via Web (Gaia) with CPUSU thing &amp;gt; run verifier after downloaded and then installed. After successfully installation and reboot i waited 15 minutes and then upgraded the active member the same way via WEB and after waiting 15 minutes ran clusterXL_admin up and check sync again. I did not experienced any downtime.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 00:15:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139047#M756</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2022-01-21T00:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.10 Jumbo Hotfix install</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139180#M761</link>
      <description>&lt;P&gt;Hi Trevor.&lt;/P&gt;
&lt;P&gt;We have installed R81.10 JHF take 22 successfully in our labs (and also 30). So yes, it is expected to work.&lt;/P&gt;
&lt;P&gt;If issue persists go ahead and open a support ticket.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 07:58:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/139180#M761</guid>
      <dc:creator>Tal_Ben_Avraham</dc:creator>
      <dc:date>2022-01-23T07:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro R81.10 Jumbo Hotfix install</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/156462#M1145</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have exactly same problem as Trevor.&lt;/P&gt;&lt;P&gt;2 mho-140&lt;/P&gt;&lt;P&gt;2 SGM 16500HS (R80.30SP - take 97)&lt;/P&gt;&lt;P&gt;1 vsx gateway - 3 Virtual system&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem: unable to upgrade with the last hotfix take 101.&lt;/P&gt;&lt;P&gt;following the procedure, I first turn SGM2 in down state and start upgrade on it. when this SGM2 finsih installation of the hotfix and reboot, it stay in Down state.&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;[Expert@FW-MAESTRO-IA-ch01-01:0]# cphaprob state&lt;/P&gt;&lt;P&gt;Cluster Mode: HA Over LS&lt;/P&gt;&lt;P&gt;ID Unique Address Assigned Load State Name&lt;/P&gt;&lt;P&gt;1 (local) 192.0.2.1 100% ACTIVE FW-MAESTRO-IA-ch01-01&lt;BR /&gt;2 192.0.2.2 0% DOWN FW-MAESTRO-IA-ch01-02&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Active PNOTEs: None&lt;/P&gt;&lt;P&gt;Last member state change event:&lt;BR /&gt;Event Code: CLUS-112004&lt;BR /&gt;State change: DOWN -&amp;gt; ACTIVE&lt;BR /&gt;Reason for state change: USER DEFINED PNOTE&lt;BR /&gt;Event time: Fri Sep 2 15:37:03 2022&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;some differences on cphaprob list command&lt;/P&gt;&lt;P&gt;[Expert@FW-MAESTRO-IA-ch01-01:0]# cphaprob list&lt;/P&gt;&lt;P&gt;There are no pnotes in problem state&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@FW-MAESTRO-IA-ch01-02:0]# cphaprob list&lt;/P&gt;&lt;P&gt;Registered Devices:&lt;/P&gt;&lt;P&gt;Device Name: Fullsync&lt;BR /&gt;Registration number: 0&lt;BR /&gt;Timeout: none&lt;BR /&gt;Current state: problem&lt;BR /&gt;Time since last report: 430 sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;On smart console, only vsx gateway is green, but the 3 Virtual systems seems disconnected (red). Yet SIC seems to be good on both gateways:&lt;/P&gt;&lt;P&gt;[Expert@FW-MAESTRO-IA-ch01-01:0]# cp_conf sic state&lt;/P&gt;&lt;P&gt;Trust State: Trust established&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 SGM show differents policy install. but unable to push any policies&lt;/P&gt;&lt;P&gt;[Expert@FW-MAESTRO-IA-ch01-01:0]# fw stat&lt;BR /&gt;HOST POLICY DATE&lt;BR /&gt;localhost FW-SNET-IA_VSX 2Sep2022 15:36:52 : [&amp;gt;Sync] [&amp;lt;Sync] [&amp;gt;magg3] [&amp;lt;magg3]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@FW-MAESTRO-IA-ch01-02:0]# fw stat&lt;BR /&gt;HOST POLICY DATE&lt;BR /&gt;localhost InitialPolicy 5Sep2022 9:01:07 : [&amp;gt;Sync] [&amp;lt;Sync] [&amp;gt;magg3] [&amp;lt;magg3]&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2022 07:18:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-R81-10-Jumbo-Hotfix-install/m-p/156462#M1145</guid>
      <dc:creator>kainneb</dc:creator>
      <dc:date>2022-09-05T07:18:00Z</dc:date>
    </item>
  </channel>
</rss>

