- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Upgrading CloudGuard IaaS Security Gateway in Azur...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Upgrading CloudGuard IaaS Security Gateway in Azure - What is your experience?
What is your experience with upgrading CGI Security Gateways in Azure?
I understand there are two options: -
1) Deploy new gateway with same IPs and migrate
- Deploy new gateway
- Stop the new GW in order to change the static IPs associated with the VM instance.
- Console on to the new GW to change the IPs in clish.
- Detach interfaces on old gateway.
- Attach interface on new gateway.
- Reset SIC
- Install policy
Advantages are that no changes in the routing in Azure is required but does require more downtime as you will need to detach the interfaces on the old GW before attached interfaces on the new GW.
2) Deploy new gateway with new IPs and update UDRs
- Deploy new gateway
- Create gateway object and set SIC
- Update policy with new gateway wherever old gateway is referenced
- Re-IP licence and re-attach to new gateway.
- Install policy
- Update all UDRs to reference new IP/VM
First of all, do the above steps look correct or if anyone can help identify any errors or omissions that would be great.
Secondly, if others have followed this to deploy new versions, how did it go? Any pitfalls, gotchas? What was the downtime?
Thanks
Scott
Advantage is that downtime is minimised as sessions will be interrupted but will then match the policy and connect. Disadvantage, significant more changes in preparation to migrate.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Thu 05 Oct 2023 @ 09:30 AM (IDT)
Simplifying & securing your hybrid WAN with Azure Virtual WAN & Check PointWed 11 Oct 2023 @ 06:00 PM (IDT)
Take Your Data Security Posture Management to the Next Level with CNAPPWed 11 Oct 2023 @ 06:00 PM (IDT)
Take Your Data Security Posture Management to the Next Level with CNAPP