- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi All,
Planning to upgrade CheckPoint standalone SMS from R81.20 to R82 .
What is the best way to do it ?
Upgrade directly from the GUI or do an advanced upgrade ?
We are managing Maestro + SGW running VSX as well one standalone oepn server.
and also for backup system backup and snapshot I believe should be more than enough ?
Thank You !
Hi
When you use the term "Standalone SMS" are you referring to a machine that is just a single Security Management Server? Reason I am asking is that the term Standalone also refers to a machine running a Management and a Gateway.
I would start by going over the R82 SK:
https://support.checkpoint.com/results/sk/sk181127
Go to - Downloads and Installation section
I would also follow all the best practices in R82 Installation and Upgrade Guide:
It is standalone management server
Also one more thing
Thank you Vincent for replying back. I was told by a PS to do as an advanced upgrade.
Since the new server needs an IP for SSH and file transfer, should I:
- Build it with a temporary IP, perform the import, and then switch to the production IP during cutover?
- Or should the old management server be disconnected from the network from the beginning so I can use the same IP?
What is the recommended approach/best practice?
Thanks in advance.
Hello
I spoken with some Check Point PS in the past, and some of them prefer the advanced upgrade; so you'll use migrate export to export all the configuration and database, perform a fresh install of a new management server in R82 and the import everything exported.
But using the CPUSE is more or less the same, because even during the upgrade with CPUSE, a migrate export is performed; in this case you don't have to create a new management server but everything happens in place.
As I told you, some PS prefer Advanced Upgrade; I usually performed upgrade using CPUSE (because in my case, I'm not free to create new VMs to install R82 from scratch) ... If, in your case, is easy to create a new management server in R82 with fresh install then you could follow the Advanced Upgrade procedure (in any case ii could be a good exercise).
@simonemantovani Have you compared the downtime and rollback options between the Advanced Upgrade and CPUSE methods to determine which approach minimizes risk for your environment?
Honestly I never compared the downtime between the two methods; with CPUSE method, if it fails it revert to the previous version (R81.20).
Every time I performed an upgrade, I always performed a VMware snapshot of the management (because it was a virtual server), just to quickly rollback.
In the past I performed an upgrade using CPUSE for an MDS with 17 domains and several thousands of objects and it took about 5 hours to complete the whole procedure (migrate export, upgrade, migrate import).
Thank You for replying
Since the new server needs an IP for SSH and file transfer, should I:
- Build it with a temporary IP, perform the import, and then switch to the production IP during cutover?
- Or should the old management server be disconnected from the network from the beginning so I can use the same IP?
What is the recommended approach/best practice?
It's safe to perform the import on a system with a different IP.
Nothing will change on gateways until policy is pushed.
I usually do it from web UI, just make sure to expect database transfer to take some time.
Hi,
Make sure you are using the latest version of the Deployment Agent and migration tools.
I always perform a verify of the database so I can fix any issues before upgrading.
I would perform an advanced upgrade when the SmartCenter has gone through a lot of upgrades and hotfix installations.
If this is a fresh R81.20 installation with some hotfixes, you can choose to do a CPUSE upgrade.
Martijn
I would always and without exception opt for the Advanced Upgrade (using export and import to a new VM created from scratch) and wouldn’t recommend anything else. Especially if you’re running a management system on VMware, it’s the only option in my view.
Thank you Vincent for replying back. I was told by a PS to do as an advanced upgrade.
Since the new server needs an IP for SSH and file transfer, should I:
- Build it with a temporary IP, perform the import, and then switch to the production IP during cutover?
- Or should the old management server be disconnected from the network from the beginning so I can use the same IP?
What is the recommended approach/best practice?
Thanks in advance.
This is the procedure I've used reliably across multiple customer environments during my history at solution providers. It keeps your production environment untouched until the very last step.
Tip: The beauty of this approach is that you build and validate everything in an isolated environment first. Production stays untouched until step 12, and your rollback is simply powering the old management back on.
I hope that helps, and I hope my memory hasn’t let me down, because at my current workplace, a colleague always does this in collaboration with Check Point PS, and I haven’t done it myself for a while.
I think, that is the best way to do it.
But if you do not want to build a twin VLAN, this is what I would do:
Get 2 additional IPs (IPb and IPc) in the SMS LAN with actual SMS (IP: IPa).
Exactly. But setting up a new VLAN/Switch in vCenter is just a matter of a few clicks. It doesn’t need to be accessible from the outside, so there’s nothing else to do. You just use the VMs via the VMware console. 😊
But of course, your to-do list is spot on. 👍
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 11 | |
| 11 | |
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 6 | |
| 5 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceTue 19 May 2026 @ 06:00 PM (IDT)
AI Security Masters E8 - Claude Mythos: New Era in Cyber SecurityAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY