<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SMB Cluster automatic firmware updates in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-automatic-firmware-updates/m-p/40063#M1640</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At the first glance, it is a welcome feature to let the SMB update itself to the most recent firmware. Of course, there is always a chance of side effects &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Usually, the update and reboot can occur at a scheduled off hour, so the impact is very low as the reboot takes about 3mins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a HA config with clustered SMBs we could expect the update to be handled differently on actve and standby node. But f&lt;SPAN style="font-size: 11.0pt;"&gt;irmware is not synchronized, each member has to upgrade individually. &amp;nbsp;It is not possible to set a different time for the search for firmware updates on the nodes, so both will always have the same time for update and make that three minute gap inevitable. A possible workaround is to set the date on each member with ~5m difference.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;This a a CP statement from Mai 2015 - i just wonder if it is still working the same way, but i see no new feature that could help here. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;An alternative is not to schedule automatic firmware updates in WebGUI, but to trigger it by scripting - Embedded GAiA lets you activate immediate search and install of firmware updates usind CLI:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-size: 11pt;"&gt;set cloud-services-firmware-upgrade activate true frequency immediately-when-available&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;After a certain number of minutes, you can switch it off again:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-size: 11pt;"&gt;set cloud-services-firmware-upgrade activate false&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;This can either be perfomed using any GAiA devices System Management &amp;gt; Job Scheduler page or by activating the crond on the SMB unit, see my CheckMates article &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2617-perform-scheduled-scripted-tasks-on-smb-devices"&gt;Perform scheduled scripted tasks on SMB devices.&lt;/A&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Dieses Dokument wurde aus folgender Diskussion erzeugt:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/7843"&gt;SMB Cluster automatic firmware updates&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 May 2018 13:50:01 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-05-24T13:50:01Z</dc:date>
    <item>
      <title>SMB Cluster automatic firmware updates</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-automatic-firmware-updates/m-p/40063#M1640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At the first glance, it is a welcome feature to let the SMB update itself to the most recent firmware. Of course, there is always a chance of side effects &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Usually, the update and reboot can occur at a scheduled off hour, so the impact is very low as the reboot takes about 3mins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a HA config with clustered SMBs we could expect the update to be handled differently on actve and standby node. But f&lt;SPAN style="font-size: 11.0pt;"&gt;irmware is not synchronized, each member has to upgrade individually. &amp;nbsp;It is not possible to set a different time for the search for firmware updates on the nodes, so both will always have the same time for update and make that three minute gap inevitable. A possible workaround is to set the date on each member with ~5m difference.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;This a a CP statement from Mai 2015 - i just wonder if it is still working the same way, but i see no new feature that could help here. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;An alternative is not to schedule automatic firmware updates in WebGUI, but to trigger it by scripting - Embedded GAiA lets you activate immediate search and install of firmware updates usind CLI:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-size: 11pt;"&gt;set cloud-services-firmware-upgrade activate true frequency immediately-when-available&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;After a certain number of minutes, you can switch it off again:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-size: 11pt;"&gt;set cloud-services-firmware-upgrade activate false&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;This can either be perfomed using any GAiA devices System Management &amp;gt; Job Scheduler page or by activating the crond on the SMB unit, see my CheckMates article &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2617-perform-scheduled-scripted-tasks-on-smb-devices"&gt;Perform scheduled scripted tasks on SMB devices.&lt;/A&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Dieses Dokument wurde aus folgender Diskussion erzeugt:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/7843"&gt;SMB Cluster automatic firmware updates&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 13:50:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-automatic-firmware-updates/m-p/40063#M1640</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-05-24T13:50:01Z</dc:date>
    </item>
  </channel>
</rss>

