- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hey guys,
Had client ask me this yesterday and quite frankly, was not sure what to even make of it. They essentially wanted to know if there was any way to install jumbo hotfix on their R81.20 cluster once take is recommended say at 1 am on specic day of the week.
I reckon cron job might be one option for it, but since we would not know when jumbo would become recommended, not even sure how that would work.
Thoughts?
Thanks as always for your support, I truly appreciate it.
Technically speaking, this might be feasible with a script started by cron that repeatedly checks whether there is anything new e.g. using “show installer packages” and, if so, gets started.
But.
For my part, however, I would definitely not consider something like this, and if I were still working for service providers, I would talk the customer out of such a crazy idea.
But everyone can see it as they wish.
Technically speaking, this might be feasible with a script started by cron that repeatedly checks whether there is anything new e.g. using “show installer packages” and, if so, gets started.
But.
For my part, however, I would definitely not consider something like this, and if I were still working for service providers, I would talk the customer out of such a crazy idea.
But everyone can see it as they wish.
Yea, I get what you mean Vince. I dont even think they were truly considering this, more just as an idea.
Cronjob can start an update for sure but how would it know when to perform failover to the other member when it is ready. Unit will reboot after jumbo update. With a script you can do a lot also some checks if the other member is ready. But in general I would advise against it to many factors that could go wrong.
Im with you 100%, Lesley. Thats exactly the thought I had as well when they described it to me.
A script could be used on the management and once a new jumbo is available use cdt which does the needful for a cluster including creating the deployment plan and so on.
If there is a way using SmartConsole…no clue.
But I would advise against that too.
Thanks guys for your great help, as always! I told them even yesterday that this was not the best idea, but they still wanted to know if it was possible, hence my question. Since mgmt is S1C, cdt method can also be used, so thats most likely what we will go with for the next recommended jumbo take.
correct with cdt there is more automation possible even for clusters
https://sc1.checkpoint.com/documents/CDT/Unified/Topics/Package-Installation-in-Clusters.htm
Maybe this is better answer for the customer then no 😉
This dude is super chill, so Im sure they would not be disappointed either way : - )
The jumbo page claims there's an RSS feed, but it doesn't seem to actually work. It just has a single item, which is a link to the documentation page. No information about what jumbos exist, let alone which are recommended. Right now, I think the only option is scraping the site and processing the HTML.
I've asked for a few years, now, for a machine-readable list of jumbos so I could build a system like this. ElasticXL clusters have several ways to accidentally update all of the members at once (thereby causing a hard outage), so I'm working on a tool to install jumbos. I'd like to be able to fully automate it on some of my less-critical firewalls so I can hold them up as examples when it's time to update more sensitive systems.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 8 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY