- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Re: Check point in Azure Virtual WAN upgrade
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check point in Azure Virtual WAN upgrade
Hello.
We have deployed the Check point in Virtual Wan managed application in Azure. This has deployed 2 NVAs with version R2. There is no way to configure the SKU, just the scale set number. So no way to configure the disk size.
By default the partition layout provides 49gb and these are split between logs and root with 16gb unallocated. The logs partition is 10gb and 85% used.
So how do we install hot fixes or patch upgrades on a system with not enough space out of a the box?
Do we need to deploy new Managed application with side by side on a newer version and change routing intent to use it?
Microsoft have no access to the Managed Application. I have no access to see the NVAs in Azure so can't add disk space and boot into maintenance mode etc to increase the disk size.
A bit stuck. Please help.
Thanks in advance
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Understood — so just to confirm, it was Microsoft who approved the deployment of the Check Point image as a Managed Application in vWAN, despite the small disk size and the fact that neither the customer, Check Point, nor Microsoft has the ability to modify it to increase the disk size?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Shay_Levin can you please advise?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe you need to trigger a scale out, then it will automatically scale in a new firewall with the latest version.
I believe its not recommended to do jhf upgrades on scalesets like you do on physical appliances or other deployment types.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thanks for you reply.
So I have a few questions then please
1. How do we trigger a scale out, there doesn't seem to be a setting within Azure to perform this?
2. Even if we scale out how will the image be any different to what we have, we are already on R82
3. There is a reimage button in Azure Portal but I how do we know which image it will use, I presume it will be the same as what is already configured.
Our issue here is not so much the Major releases but the version upgrades. We can't operate our firewalls in BAU without performing these hotfixes on a regular basis and with the current image provided by the Azure Marketplace we are unable to do this.
Any further information how this is meant to work would be appreciated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
You need to perform side by side upgrade:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Amir for your response.
I have read that link before and yes I understand that to roll out a major release we would need to do it side by side and change routing intent however does the same apply to Hot fixes?
We are currently on R82 so there is no need to upgrade the version but we need a Jumbo Hotfix to comply with our security team and there is no space in /var/log to do this.
These hotfixes come out every few months so how can we remain compliant on these patch versions?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
At the moment this is due to limitations from Microsoft.
Once this will be solved we'll be working on it. I believe we'll have this in the future.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Amir,
Sorry but how is it a Microsoft limitation? The issue is the Image which is too small, or am I missing something?
If the image was big enough out of the gate, we would have enough space to deploy hotfixes.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Cortez009 , I am checking with RnD on this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unlike other solution, this is managed by Azure. If this was solely by CP I would say that you can use SK for adding more storage.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Understood — so just to confirm, it was Microsoft who approved the deployment of the Check Point image as a Managed Application in vWAN, despite the small disk size and the fact that neither the customer, Check Point, nor Microsoft has the ability to modify it to increase the disk size?
