Yes, that's true, but it's already happened to me a couple of times that I kept different JHF versions for a few days and nothing ever happened. Maybe I just got lucky, haha!
- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
MVC is enable by deafult now? (FROM R81.20)
Just looking at the relevant administration guide it should be enabled manually. Perhaps someone else has different experience:
I'll rephrase the question, shouldn't it be disabled by default?
You always have to enable it on the member(s) using:
set cluster member mvc on
Why should it ? See the obstacles to policy install in sk177626 first ! Next limitation: Do not add, remove, or edit settings of cluster interfaces (IP addresses, Network Objectives, and so on) while in MVC, see https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Gui...
Idea of MVC is that You can upgrade to a newer version without a loss in connectivity (Zero Downtime Upgrade) and test the new version on some of the Cluster Members before you decide to upgrade the rest of the Cluster Members or revert the upgraded.
This also is not full HA clustering as failover will not fully work (depending on the version gap).
In R81.20 GA it is disabled. When you install any JHF take 14 and above it is enabled, so that you don't lose clustering during the JHF install process. This information is in the notes section of the JHF documentation.
In my R82 install it is disabled, I have not changed this configuration so I think this would be the default setting in R82.
Ok, you answered my question, so from JHF 14 onwards it is enabled by default, but I haven’t found where it says that in the JHF documentation.
Thank you very much, emmap
It's in the Critical Information section (used to be called Important Notes) - search for PRJ-44444 in there and you'll see the entry,
The Multi-Version Cluster feature is enabled by default to prevent traffic loss after a failover from a cluster member running a lower Jumbo Hotfix version. |
|
Take 14 |
|
PRJ-44444 |
Thank you very much emma
Based on what's written here:
The Multi-Version Cluster feature is enabled by default to prevent traffic loss after a failover from a cluster member running a lower Jumbo Hotfix version. |
it seems like it was enabled to solve issues related to Jumbo Hotfixes, but MVC isn’t designed for major versions... or am I missing something
It is designed for version upgrades primarily, but there was something in the code that was updated in that JHF take that also triggered essentially the same thing, ie no cluster sync when one box has the JHF and the other doesn't. I don't have any further details on what changed though.
Thank you very much for the explanation.
See ClusterXL Admin Guide: ClusterXL is supported only between identical Check Point software versions - all Cluster Members must be installed with identical Check Point software, including OS build and hotfixes.
Yes, that's true, but it's already happened to me a couple of times that I kept different JHF versions for a few days and nothing ever happened. Maybe I just got lucky, haha!
As long as MVC is used...
After JHF 14 yes
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
14 | |
12 | |
11 | |
9 | |
9 | |
7 | |
5 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY