Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Arskazv
Participant

3900 series with R82.10:jumbo hotfix Take19 does not install properly and breaks firewall

Hi!

Just to warn:

We have broken now 2 3900 series appliances. Be careful out there! Take snapshot before trying 😉

 

CLI access is partially functioning, but...needs reinstallation.

0 Kudos
13 Replies
PhoneBoy
Admin
Admin

What specific symptoms?
I assume you have opened a TAC case already?

0 Kudos
Alex-
MVP Silver
MVP Silver

Arskazv
Participant

Yes, we have TAC case opened.

0 Kudos
guygam
Employee
Employee

Hi Arskazv,

Can you share the SR? so we can monitor it as well

 

Thanks

0 Kudos
Alex-
MVP Silver
MVP Silver

We've seen this with 3920 series at least.

ElastricXL completely breaks. CLI access becomes broken.

We're asked logs we can't even provide because of this.

0 Kudos
Arskazv
Participant

6-0004621423

 

Actually it seems, that the incompatible JHF packages were marked "no installation allowed" last week  at CPUSE package list.

0 Kudos
Duane_Toler
MVP Silver
MVP Silver

Curious... in what way is ElasticXL broken?  There's a new JHF 24 released earlier this morning that includes a CPD communication error via SIC.  This might not be your issue, tho.  Just curious.

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos
Alex-
MVP Silver
MVP Silver

When FTW'ing the first system as ElasticXL with build 467, Eth9 disappears into bond1024. The other system appears as candidate and can join. Single site or dual site.

After any JHF installation, be it Take 6 or Take 19, the systems show again eth9 as discrete interface in admin down state, clish is half-broken with error codes and asg stat reports 1/2 systems for the SMO and 0/2 systems on the other unit. Nothing works to restore the cluster short of ISOMorphic since the clish commands to FCD the systems are broken. Tried 4 times, each time same result.

0 Kudos
Duane_Toler
MVP Silver
MVP Silver

oh wow! Yeah that is a special kind of failure there.  😞  I've also seen issues with CLISH that can't restore a snapshot because of a name parsing error (whyyyyyyy a limit of 15 characters and arbitrary, and incorrect, character class? this is not 1998 and it's not NetBIOS anymore).

Have you been able to do an ISOmorphic install of a Blink+JHF image by chance?  Either JHF 19, or now 24?

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos
Alex-
MVP Silver
MVP Silver

I'd love to but ISOMorphic doesn't propose ElasticXL and we need it for that setup. 😀

 

Edit: Blink

0 Kudos
Duane_Toler
MVP Silver
MVP Silver

Ah, I see the ISOmorphic release notes now.  Yeah, there's no option for installing a Jumbo HFA with an ElasticXL configuration (yet).  You have found quite a spectacular issue!  (congrats?... i guess?).

Best wishes for the TAC case on it.  Let us know how it goes, tho!  I'm sure others would benefit from the results.

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos
Alex-
MVP Silver
MVP Silver

I had a lengthy session with TAC and we went though the whole process of creating an ElasticXL cluster from the base R82.10 build467 image, which worked, then installing any hotfix (from 6 to 24), which broke the system, and collect a bunch of output.

The SR is now at R&D. From what I gather, this is linked to ElasticXL on that 3920 platform.

We have been able to patch ElasticXL clusters without apparent issues on 3970/80 platforms and other implementations of 3920 running ClusterXL can be patched as well. Those customers were running the GA1 of R82.10 for ARM and could be updated with Blink to the GA2 without issues. Since GA1 did not support ElasticXL, they were using ClusterXL and upgraded in-place to GA2.

Steffen_Appel
Advisor

Just got an update, taht tehy are still working on a patch

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events