- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello,
I have worked in the past with physical appliances only, but now I got (in a project) an existing VSX cluster too and I have to update it with recommended Hotfix. It's the following environment:
2*5100 appliances with ClusterXL in HA-mode (which I already updated to R81.20 Take 98)
2*5100 appliances with CP VSX Cluster in HA-mode and two VS instances + VSW (also on R81.20 but old Hotfix)
As all nodes have no Internet access (and I had some issues with access to WebUI, but different topic), I made all updates (on physical Cluster) via CLI:
Task 1 – provide Image to machines
Task 2 - create Snapshot/Backup/CPinfo, save config
copy the created files to a save place
Task 3 – update Deployment Agent
Task 4 – import downloaded package and install on node B (Backup/standby)
Task 5– import downloaded package and install on node A (Primary/now standby)
Now my question is: can I do the update on VSX Cluster in the same way or do I have to add some more commands?
Could you please advise (as we don't have a test environment...).
Thanks in advance
Peter
You can use exactly the same process, the VSX gateway is updated as a whole unit, there's no per VS configuration or updating required.
Best tip I can give you, in higher takes in R81.20 you now also can update VSX via the web interface like a normal gateway.
This saves a lot of effort figuring out all commands etc.
What tend to do:
- Update CPUse agent if required (in most cases there would be an internet connection so it would automatically update)
- Upload new Jumbo image file to the repository (installer import local <directory path>/filename)
- Snapshot both nodes
- Uninstall the old jumbo on the standby node (installer uninstall package) - This will reboot the node.
- Install the new Jumbo (installer install) - reboot
- Once its back up delete the old package file.
- failover your VS's (VSX_Util command)
- Test
- repeat above on remaining node and failback.
Do I really need to uninstall old Jumbo's? Is it because of space limitations?
In the past I just installed the Jumbo on top of the currently installed one's...
> - failover your VS's (VSX_Util command)
As we use HA (so active/standby) and not Loadsharing I do not have to do it manually, as the cluster will do the failover on it's own during Update, right?
You don't have to, but I choose to do this, because I know diskspace slowly gets eaten.
I'm told that Deployment Agent is better / will be better about disk space management so this should be less necessary than it used to be.
I have never uninstalled the jumbo before installing a new one. This could give more issues then it solves. You will go back to the default R81.20 image without ANY fixes.
Only time I've seen an issue is with one gateway where you can no longer access the device using SSH, but once the new Jumbo is installed all worked.
Other then that, I've never since an issue, keep in mind your doing this on the Standby first so by the time you cutover to it the new jumbo has been applied.
You can use exactly the same process, the VSX gateway is updated as a whole unit, there's no per VS configuration or updating required.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 9 | |
| 8 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 3 | |
| 3 |
Tue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY