Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JDCasCruz
Contributor

Recommended way to update Firewall 3920

Hi, everyone,

 

For the past few months, I’ve been in charge of maintaining a clusterXL with two 3920 devices. We want to upgrade the cluster, which is currently running version R82.10 without JHF.

I’ve been looking for information in the technical documents (SKs), but at this point, I’m not sure if I can install JHF Take 24which is currently recommendedor if I should install the specific JHF Take 22 version.

So if anyone can help me figure out the best way to update JHF on these devices, I’d really appreciate it.

 

R82.10 Jumbo Hotfix Accumulator Downloads

sk183199 - Check Point Firewall 3900 Appliances

sk183557 - Hotfix for Check Point Firewall 3900 Appliances

Regards,

Juan Diego Castillo Cruz

0 Kudos
10 Replies
Alex-
MVP Silver
MVP Silver

If you have the GA1 build, you need to install Take 22, then you can use the Blink image to go directly to the GA2 with the latest hotfix.

 

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

Diamond and CFG told me we should be able to just use Blink to go from any version to the R82.10 final release with jumbo 24. I have an upcoming change to try it soon.

0 Kudos
Alex-
MVP Silver
MVP Silver

I believe that when I tried that on the GA1, I got an error message about missing Take 22.

It was not with Take 24 but Take 6 though.

0 Kudos
JDCasCruz
Contributor

I'm not quite sure—how can I check if the firmware versions are GA1 or GA2?

Here's the result for:

# cpinfo -y all
This is Check Point CPinfo Build 914000224 for GAIA
[CPshared]
No hotfixes..
[IDA]
No hotfixes..
[CPFC]
No hotfixes..
[MGMT]
No hotfixes..
[FW1]
HOTFIX_R82_10_MAAS_TUNNEL_AUTOUPDATE
HOTFIX_INEXT_NANO_EGG_AUTOUPDATE
HOTFIX_GOT_TPCONF_AUTOUPDATE
HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE

FW1 build number:
This is Check Point's software version R82.10 - Build 767
kernel: R82.10 - Build 768
[SecurePlatform]
No hotfixes..
[CPinfo]
No hotfixes..

And for the version:

> show version os build
OS build 464
> show version os edition
OS edition aarch64
> show version os kernel
OS kernel version 5.14.0-427.13.1cpaarch64

But, how can I be sure?

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

If the installer offers you jumbo 22, you're on GA1.

Alex-
MVP Silver
MVP Silver

I don't have machines in GA1 anymore to check, but you have build 464 which is, I believe, the GA2 without the leap year fix.

Build 467 includes the fix as part of the base image. So you can installe Take 24 and have all the fixes with your 464 baseline.

The GA1 is build 271.

Alex-
MVP Silver
MVP Silver

Also, make sure it's ClusterXL and not ElasticXL as clustering mode.

Installing an hotfix on 3920 in ElasticXL mode currently wrecks the clustering.

No issues with ClusterXL though.

emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Your 'show version os build' output gives us the answer - you are definitely on GA2. You should just install JHF take 24 directly on there same as any JHF install procedure. 

0 Kudos
jorgeluiznim
Advisor

Hi Juan,

I'm actually working on this exact upgrade right now for both 3920 and 3950 appliances.

The sequence that has been working perfectly for me is:

1. `DeploymentAgent_000002771_1.tgz`
2. `Check_Point_R82_10_jumbo_hf_t271_main_Bundle_aarch64_T22_FULL.tar`
3. `Check_Point_R82.10_T467_Gaia_Install_and_Upgrade_For_3900_Appliances.tar`
4. `Check_Point_R82_10_jumbo_hf_main_Bundle_aarch64_T24_FULL.tar`

This is the order I recommend following.

For some reason—which I'm still investigating by reviewing the documentation and SKs—if you skip the T22 (hf_t271) bundle and go directly to the T24 (hf_main_Bundle_aarch64_T24) bundle, something breaks during the upgrade process. I don't have a definitive explanation yet, so I'm still trying to understand the root cause.

However, based on my current experience, this exact sequence has been working flawlessly on both 3920 and 3950 appliances.

Once I have more concrete information from the documentation or the relevant SKs, I'll come back and update this thread.

For now, I'd recommend following the sequence above—it works very well. It's exactly what I'm using in production right now. 

If you follow this procedure and it works, please share your results here. It will definitely help others who run into the same situation.

Best regards,
Jorge Dias
Greetings from Brazil! 🇧🇷

jorgeluiznim
Advisor

Update:

I found the relevant documentation, and it confirms the upgrade path for Quantum Force 3900 appliances.

According to sk183199, if the appliance is running R82.10 Take 271, the recommended upgrade sequence is:

1. Install the 3900 Appliances Hotfix Take 22 (sk183557).
2. Upgrade to R82.10 Take 467 for 3900 appliances.
3. After that, you can continue with newer R82.10 Jumbo Hotfix Takes (such as Take 24).

This matches the sequence I shared earlier and also explains why going directly to the newer Jumbo package can cause issues. I've now successfully followed this procedure on both 3920 and 3950 appliances.

If you try this procedure, please share your results here—it will certainly help others facing the same situation.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events