Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
WiliRGasparetto
MVP Diamond
MVP Diamond

Jumbo Hotfix Installation on an single firewall or  HA Cluster r80.xx r81.XX

Jumbo Hotfix Installation on an single firewall or  HA Cluster

Prerequisites

• Access the Gaia Portal of each cluster member:

https://<member_IP>

 
 
 

1.png

• Download the Jumbo Hotfix package to your computer in .tgz format from the official Check Point portal.

For R81.10:

https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/R81.10_Downloads.htm

For R81.20:

https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20_Downloads.htm

Step-by-Step Procedure

1. Access the Gaia Portal

• From your browser, access the Gaia Portal of each cluster member using its management IP address.

 
 

1.png

 

2. Upload the Jumbo Hotfix Package

• From the left-side menu, navigate to:

Upgrades (CPUSE) > Status & Actions

2.png

• Click Import Package.

3.png

• Select the Jumbo Hotfix .tgz file saved on your computer.

• Click Import.
4.png

• Wait for the upload process to complete.

• Go to Show All Packages and click All.

5.png

3. Install the Jumbo Hotfix

• After the upload is completed, the package will appear in the list of available packages.

• Click Verify next to the Jumbo Hotfix package.

• After the package has been successfully verified, click Install.

 

 

• Follow the instructions displayed on the screen. The system may require the cluster member to be rebooted after the installation.

4. HA Cluster Procedure

5. Start with the Secondary Member — Standby

o Install the package by following the procedure described above.

o Reboot the member if required.

o Wait until the member rejoins the cluster.

o Verify its status through the Gaia Portal under ClusterXL.

6. Perform a Manual Failover — Optional

o Through the Gaia Portal, make the updated member Active, if required, using the available cluster options.

7. Repeat the Process on the Other Member

o Install the package on the cluster member that has not yet been updated.

o Reboot the member if required.

8. Validation

• After updating both members, verify the cluster status through the Gaia Portal.

• Confirm that both members are operational and properly synchronized.

• Verify the installed Jumbo Hotfix version under:

Upgrades (CPUSE) > Status & Actions

 

Important Notes

• The entire procedure can be performed through a web browser using the Gaia Portal.

• For clusters with multiple members, repeat the procedure on each member, updating one member at a time.

• Before proceeding to the next member, confirm that the updated member has successfully rejoined the cluster and that synchronization has been restored.

• Always validate the cluster state and traffic processing before and after performing a failover.

(1)
10 Replies
Bob_Zimmerman
MVP Gold
MVP Gold

You can also do this by right-clicking the firewall in SmartConsole and picking Actions > Install Hotfix/Jumbo. It handles updating CPUSE, distributing the jumbo, and installing it. If the firewall is a normal cluster, it will also handle failing over and updating the other member(s).

WARNING: If you update an ElasticXL cluster using the SmartConsole method, it updates all members at the same time, causing a hard outage. I expect Maestro would behave the same.

simonemantovani
MVP Diamond
MVP Diamond

Hello

my suggestion, even when installing JHF is to create a snapshot before proceeding (to be safe).

For Maestro, you install the JHF manuale on every single member (important things to do is to diaable the clone feature)

WiliRGasparetto
MVP Diamond
MVP Diamond

A genuine question: why has installing them one by one caused problems with cloning?

PhoneBoy
Admin
Admin

It's the cloning that causes an issue in this case, thus why it should be disabled when installing JHF on Maestro/ElasticXL members.

WiliRGasparetto
MVP Diamond
MVP Diamond

That’s interesting I hadn't encountered this issue yet, but it’s good to pass along to our team here.

Bob_Zimmerman
MVP Gold
MVP Gold

It's fascinating to me how Maestro is pitched as this automation-centric system, but tasks as simple and common as patching turn into this cumbersome manual process. I'm not sure about everybody else, but I patch a cluster at least four times more often than I manipulate interfaces, and at least 20 times more often than I add cluster members.

I'm trying to write a script to do a rolling update without all the manual interaction, but I don't have enough members to thoroughly test it.

WiliRGasparetto
MVP Diamond
MVP Diamond

In Check Point versions R81 and R80, the installation of hotfixes (specific patches) is not performed directly via SmartConsole.

I still have to do it for version R82; the Web UI changes from one version to the other.

Bob_Zimmerman
MVP Gold
MVP Gold

The ability to install jumbos via SmartConsole was added in R80.30, I think. All R81 versions can definitely do it and can distribute major version upgrades the same way. My team does almost all of our jumbos this way, since it handles the whole cluster in one administrative action. For that matter, you can select multiple firewalls and update all of them together in a single action.

I just recently updated four R82 clusters at once from jumbo 60 to jumbo 107. Select all four, right-click one, Actions > Install Hotfix/Jumbo, pick the jumbo, hit Install, and let it cook. An hour later, out pop four updated clusters. It handled everything on all of the members. Terrific feature.

Alex-
MVP Silver
MVP Silver

Nice tip about the the multiple selection, thanks. I agree that installing from the SC is that simple and handles the whole process rather neatly.

WiliRGasparetto
MVP Diamond
MVP Diamond

exactly

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events