- CheckMates
- :
- Products
- :
- General Topics
- :
- Are you in an R77.30 Upgrade Rush?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you in an R77.30 Upgrade Rush?
A few months ago, the vast majority of Check Point firewalls out there were still running R77.30*. As the time progressed, we slowly saw people upgrading their firewalls to R80.10 and later. However, in the month of August, we saw a massive acceleration in upgrades**, in anticipation of the End of Support for R77.30 in September.
This raised a few questions:
1. Why are so many people waiting for the last minute to upgrade? Some may even go beyond the Sep 30th date.
2. What can be done to avoid this from happening again in the future?
---------------------------------
* Our data comes from Indeni Insight, which receives non-confidential data about the devices in use by our customers. These are mostly large enterprises in North America, with deployments of at least 100 firewalls.
** Massive acceleration: 40% of all upgrades to R80.20, up to Aug 15 2019, occurred in the first two weeks of August. Again, this is based on just our data.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No rush, as CP is not able to release R80.x version which is bug free. In my company, we have started with testing R80.x releases around 5 months ago. None of upgrade/fresh installation went without issues. Around 20 cases were opened so far, most of them closed as "will be solved in next release" 🙂
So we will run on beloved and super stable R77.30 with extended support from CP till testing of R80.x isnt without issues on our end.
PS: Eagerly waiting for R80.40 EA and FINALLY official support for cluster manipulation over API...
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@JozkoMrkvicka which version you are talking about, specifically? This sounds like R80.20. Quite _a_few_ issues are actually resolved in R80.30, which had recommended status now
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Now we are planning the migration of the rest in 1 big bang migration.
However that is so far only management, them we still need to do a migration of around 250 gateways, where possible. Pretty sure this will take many more months.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is currently still not supported. Needed to move 5 Domains onto a separate MDS server to be able to migrate the rest.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is Checkpoint extending support past 9/30/19??? I keep asking, but no real answers..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have extended support to specific use cases and customers where this is required (one valid example exist on this thread)
The general end of support is Sep 2019.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Log Servers on Domain Management Server level are not yet supported in R80.30. We aim to support this feature soon. See sk117159 for details.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you using Multi-Domain Management where you have logserver for CMAs ?
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Upgrade of appliancies on small deployments went fine to upgrade to r80.20 with CDT, but on critical systems, which are on open servers we failed to upgrade (gateways,VSX) without issues and had to roll back.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. Open servers are better served w R80.30 plus 3.10 linux where we have jumbo support across both linux kernels. You are welcome to try it as its much more mature.
2. To the log server message... there is indeed missing item called dedicated log server (Pre upgrade verifier detect it) and is specific scenario used by small but important part of the install base - its in development and should be released this year. We are in communication with those customers that are waiting for this and they have received extended support.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@JozkoMrkvicka We ran into this issue and no you just cannot upgrade the CMA when a logserver is part of the CMA.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Indeed.
You can see it working in your lab next month. It will be released in Q4 2019.
If needed we will extend support in such cases but to put this into proportion, this is small part of our customers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yep, I just tried it and you were right:
Jozko Mrkvicka
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will Checkpoint be offering extended support for us customers having problems upgrading?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you have concrete problems, work w the support team on realistic plan and you will be supported all thru implementation plan (and yes, if it means extended support).
