- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hey guys,
Im no VSX expert by any means, but figured would share this in case anyone is stuck on it. I never realized when I installed R82 vsnext in the lab that web UI does not give an option to install new jumbo or upgrade, so took me a while to figure out best way to install jumbo 14 on it.
First, I tried to upgrade package from cloud with installer import clish command, and though it worked, when I verified, passed fine, but then installing kept giving generic message saying to contact CP support for assistance.
I then downloaded .tar package from below link and ran below in clish -> [WARNING! Local Member] vsx-test-lab-s01-01:0> installer import local /var/log/jumbo/Check_Point_R82_JUMBO_HF_MAIN_Bundle_T14_FULL.tar
https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/R82_Downloads.htm
https://support.checkpoint.com/results/download/137326
After it imported, ran below:
WARNING! Local Member] vsx-test-lab-s01-01:0> installer in
[WARNING! Local Member] vsx-test-lab-s01-01:0> installer install
** ************************************************************************* **
** Hotfixes **
** ************************************************************************* **
Num Display name Type
1 R82 Jumbo Hotfix Accumulator Take 14
Info: Initiating install of Check_Point_R82_JUMBO_HF_MAIN_Bundle_T14_FULL.tgz...
Interactive mode is enabled. Press CTRL + C to exit (this will not stop the operation)
Result: Package R82 Jumbo Hotfix Accumulator Take 14 was installed successfully.
[WARNING! Local Member] vsx-test-lab-s01-01:0>
Broadcast message from admin@vsx-test-lab-s01-01 (Sat Apr 26 14:26:17 2025):
The system is going down for reboot NOW!
Anyway, hope it helps anyone who may find themselves in similar situation.
Best,
Andy
OK, so:
Scalable Platforms do not support installing patches from WebUI. This is because installation process accommodate all the SGMs in the group, and the WebUI doesn't allow for that. So you need to do it from gclish
What's gclish? It's global clish, You see in your output there a huge 'WARNING! Local Member' tag there. That's there because you shouldn't be configuring or patching anything in local clish when using a scalable platform. You should be in 'gclish' (it'll say 'Global' in the hostname) when doing pretty much anything.
The normal 'installer' commands should work from gclish, so if you did an 'installer download etc' command from gclish, it will initiate the download of the patch on all active SGMs. If you download the patch and upload it to SGM1, and then in gclish on SGM1 do an 'installer import local etc' command, it will copy it to all active SGMs and then do the import. Now that the patch is imported on to all active SGMs, you can run the install from gclish, specifying which SGMs to install the patch on - do half at a time to avoid outages. I recommend you do the 'top' half first as it's a nicer workflow. So, 'installer install 1 member_ids 1_2' to install it on SGM2, then once it's patched and rebooted and active do it on SGM1.
I do have a vsx question for true vsx experts out there and please forgive me if this sounds like a DUMB question, but I cant seem to figure it out for the life of me : - )
I dont see an option in smart console when you create vsnext object to change web UI port to custom one, and when I do it from clish with set web ssl-port command to 4434 and save config, every time I reboot the box, it defaults back to 443...any idea if there is a way to keep the custom port?
@Lesley @Timothy_Hall @Chris_Atkinson
Best,
Andy
I've yet to build a LAB (unless someone can tellme how to get this working in VMWare Workstation).
But I wondering it it may be 'g_' command.
I'm also curious to see how a SMO object works for managing different VSs.
Also surprise that jumbo can only only be installed in the traditional why for VSX. I thought everything was done in the WEBUI now, and I guess for Jumbos in VS0, also if I'm correct you only should need to do this on the active now (if running ElasticXL).
What I don't know is if the old jumbo is uninstalled first then the new one is installed as I do this to ensure space is not lost over time.
FWIW, I even changed to port 4434 instead of 443 in /web/conf/httpd2.conf, set ssp port in clish to 4434, rebooted, but it defaulted again to 443. I really believe thats how it is for VSX...but not 100% positive, just my logical assumption.
Andy
In old VSX there was never a web portal available to virtual systems, so the option to configure the port didn't exist. Seems it hasn't been added to VSNext configuration but there's a default '443' value in the policy so your manual config gets reverted when the policy is installed on reboot.
So is there any way to keep custom port for web ui that would survive the reboot?
Please submit feedback on the applicable documentation if it is unclear for you, see:
Thanks Chris. I checked that doc yesterday as well, but cant find anything on eithewr web UI custom port or installing jumbo from web UI, so I can only logically assume its either not possible or not supported, or both : - )
Andy
OK, so:
Scalable Platforms do not support installing patches from WebUI. This is because installation process accommodate all the SGMs in the group, and the WebUI doesn't allow for that. So you need to do it from gclish
What's gclish? It's global clish, You see in your output there a huge 'WARNING! Local Member' tag there. That's there because you shouldn't be configuring or patching anything in local clish when using a scalable platform. You should be in 'gclish' (it'll say 'Global' in the hostname) when doing pretty much anything.
The normal 'installer' commands should work from gclish, so if you did an 'installer download etc' command from gclish, it will initiate the download of the patch on all active SGMs. If you download the patch and upload it to SGM1, and then in gclish on SGM1 do an 'installer import local etc' command, it will copy it to all active SGMs and then do the import. Now that the patch is imported on to all active SGMs, you can run the install from gclish, specifying which SGMs to install the patch on - do half at a time to avoid outages. I recommend you do the 'top' half first as it's a nicer workflow. So, 'installer install 1 member_ids 1_2' to install it on SGM2, then once it's patched and rebooted and active do it on SGM1.
Thank you!
Thanks Emma for amazing explanation, that was super helpful.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
8 | |
7 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 | |
4 | |
4 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY