Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
abihsot__
Advisor
Jump to solution

Upgrading Cloudguard gateways fails for GWLB setup

Hello,

I am trying to upgrade Cloudguard Network Security gateways and we aer running "GWLB security VPC for Transit GW" setup.

 

I am following documentation (CGNS for GWLB ) for updating launch templates with new AMI image. So I picked up R81.10-335.1383, finish the config and tried to spin up an EC2, however CME is stuck with message:

ERROR Failed to initialize SIC with gateway instance GW-NAME - SIC port is closed. Refer to the Troubleshooting section in the CME Administration Guide.

 

I try to login to see the state of recently provisioned gateway and I get this message:

login as: admin
Your cloud-init configuration is corrupt or contains error:
Provided YAML file contains one or more errors:
Error in function _validate_parameters:
The parameter 'sim_geneve_enabled' doesn't supported for simkern.

In order to configure your system, please access the Web UI and finish the First Time Wizard.

 

Here are the relevant lines from "user data" and I verified they are exactly the same as in old launch template so I don't know why this fails. Did something changed with these parameters starting from R81.10?

kernel_parameters:
  sim:
    - sim_geneve_enabled=1
    - sim_geneve_br_dev=br0

 

0 Kudos
1 Solution

Accepted Solutions
samirshah1
Employee Employee
Employee

CloudGuard Network Security for AWS Gateway Load Balancer only supports R80.40 and R81.20. Upgrading to R81.10 is not possible due to lack of GENEVE support.

https://support.checkpoint.com/results/sk/sk174447

 

View solution in original post

0 Kudos
2 Replies
samirshah1
Employee Employee
Employee

CloudGuard Network Security for AWS Gateway Load Balancer only supports R80.40 and R81.20. Upgrading to R81.10 is not possible due to lack of GENEVE support.

https://support.checkpoint.com/results/sk/sk174447

 

0 Kudos
abihsot__
Advisor

Oh, that explains. Thanks for a quick reply!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.