Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Magnus-Holmberg
MVP Silver
MVP Silver
Jump to solution

R82 - ElasticXL upgrade

Hi,

Currently there are missing instructions on how to upgrade HFA on R82 running ElasticXL.
When can we expect the documentation to be updated as its diff from when running ClusterXL.

https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Installation-Uninstall.htm?tocpath=_____6


Regards
Magnus

https://www.youtube.com/c/MagnusHolmberg-NetSec
1 Solution

Accepted Solutions
Sergei_Shir
Employee
Employee

The relevant procedure was updated - it now applies to Maestro and to ElasticXL

https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Conte...

Please provide your feedbacks directly in that topic - on the top toolbar, click the envelope icon.

Thank you.

View solution in original post

11 Replies
the_rock
MVP Diamond
MVP Diamond

I am pretty sure that same process in clish worked for me when I had elasticxl lab while ago, but I could be mistaken.

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Magnus-Holmberg
MVP Silver
MVP Silver

Its very similar, (if i remember correct its not the same commands) but there should still be documentation about it 🙂

https://www.youtube.com/c/MagnusHolmberg-NetSec
0 Kudos
_Val_
Admin
Admin

All, thanks for your feedback. We notified the relevant teams internally, we are fixing this.

0 Kudos
Magnus-Holmberg
MVP Silver
MVP Silver

Thanks, i think the biggest thing is that there is no CPUSE within Gaia portal, so that really need to be highlighted.

https://www.youtube.com/c/MagnusHolmberg-NetSec
(1)
the_rock
MVP Diamond
MVP Diamond

Agree with that, it definitely should be noted.

Andy

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Sergei_Shir
Employee
Employee

The relevant procedure was updated - it now applies to Maestro and to ElasticXL

https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Conte...

Please provide your feedbacks directly in that topic - on the top toolbar, click the envelope icon.

Thank you.

Magnus-Holmberg
MVP Silver
MVP Silver

Honestly based on that ElasticXL is planned to be the new ClusterXL.
I would write in the headline 
https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Installation-Uninstall.htm?tocpath=_____6


"Installation and Uninstall Instructions for Scalable Platforms"

To be changed to

"Installation and Uninstall Instructions for Scalable Platforms, ElasticXL"


Secondly it need to be updated in the smart console to not permit "central deployment from smartconsole" on elasticXL Clusters.
Because the feature itself says it works and it will upgrade the SMO within the ElasticXL Cluster, and it will say its successfull even that the rest of the members are not updated.

https://www.youtube.com/c/MagnusHolmberg-NetSec
0 Kudos
JacWev
Participant

Hi Magnus, 

We want to upgrade ElasticXL R82 to R82.10. The SMS is Smart-1 Cloud. Do you know if there is a correct procedure. Because when we change the Firewall object to R82.10. We getting a failure during the installation.  due to installation failed, Reason TCP connectivity failure Port 18191. And we followed the correct URL. 

Jaco Wevers Security Engineer. 

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

There are two separate upgrade procedures to upgrade an ElasticXL cluster from R82 to R82.10, depending on whether it's running as a normal firewall or in VSNext mode.

0 Kudos
JacWev
Participant

Hi Bob, 

That's correct, we have a Smart-1 Cloud management environment with an ElasticXL cluster across two sites, with one gateway per site. If we want to upgrade this environment and follow the steps, there is a step where you need to set the gateway to R82.10. Because the SMO connects to Smart-1 Cloud, you can't manage to install a policy on just one gateway. If you'd like to know more, I can explain further.

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

That's not specific to Smart-1 Cloud. An ElasticXL cluster object can only have one version on any management server.

For non-VSNext, check out step 8. For VSNext, you have to do something similar, but for every VS on the box individually.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events