Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Peter-Kyn
Participant
Jump to solution

Update VSX with JumboHotfix

Hello,

I have worked in the past with physical appliances only, but now I got (in a project) an existing VSX cluster too and I have to update it with recommended Hotfix. It's the following environment:

2*5100 appliances with ClusterXL in HA-mode (which I already updated to R81.20 Take 98)

2*5100 appliances with CP VSX Cluster in HA-mode and two VS instances + VSW (also on R81.20 but old Hotfix)

As all nodes have no Internet access (and I had some issues with access to WebUI, but different topic), I made all updates (on physical Cluster) via CLI:

Task 1provide Image to machines

  • Download required Image from Internet to PC
  • Create directory on machines (like /var/log/Upg-prep)
  • Copy downloaded image to created directory on machines

Task 2 - create Snapshot/Backup/CPinfo, save config

  •  (Clish) add snapshot-onetime name <name> description “<desc>”
  •  (Clish) add backup local interactive
  •  (Clish) save configuration <filename>
  •  cpinfo

copy the created files to a save place

Task 3 – update Deployment Agent

  • (Clish) installer agent install /var/log/Upg-prep/DeploymentAgent_<version>.tgz
  • (Clish) show installer status

Task 4 – import downloaded package and install on node B (Backup/standby)

  • (Clish) show installer packages
  • (Clish) installer import local /var/log/Upg-prep/Check_P…
  • (Clish) installer verify <Package #>
  • (Clish) installer install <Package #>
  • check version with cpinfo -y fw1

Task 5– import downloaded package and install on node A (Primary/now standby)

  • (Clish) show installer packages
  • (Clish) installer import local /var/log/Upg-prep/Check_P…
  • (Clish) installer verify <Package #>
  • (Clish) installer install <Package #>
  • check version with cpinfo -y fw1

 Now my question is: can I do the update on VSX Cluster in the same way or do I have to add some more commands?

Could you please advise (as we don't have a test environment...).

 

Thanks in advance

Peter

 

0 Kudos
1 Solution

Accepted Solutions
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

You can use exactly the same process, the VSX gateway is updated as a whole unit, there's no per VS configuration or updating required.

View solution in original post

8 Replies
Lesley
MVP Gold
MVP Gold

Best tip I can give you, in higher takes in R81.20 you now also can update VSX via the web interface like a normal gateway.

This saves a lot of effort figuring out all commands etc. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
genisis__
MVP Silver
MVP Silver

What tend to do:

- Update CPUse agent if required (in most cases there would be an internet connection so it would automatically update)

- Upload new Jumbo image file to the repository (installer import local <directory path>/filename)

- Snapshot both nodes

- Uninstall the old jumbo on the standby node (installer uninstall package) - This will reboot the node.

- Install the new Jumbo (installer install) - reboot

- Once its back up delete the old package file.

- failover your VS's (VSX_Util command)

- Test 

- repeat above on remaining node and failback.

 

0 Kudos
Peter-Kyn
Participant

Do I really need to uninstall old Jumbo's? Is it because of space limitations?

In the past I just installed the Jumbo on top of the currently installed one's...

  > - failover your VS's (VSX_Util command)

As we use HA (so active/standby) and not Loadsharing I do not have to do it manually, as the cluster will do the failover on it's own during Update, right?

0 Kudos
genisis__
MVP Silver
MVP Silver

You don't have to, but I choose to do this, because I know diskspace slowly gets eaten.

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

I'm told that Deployment Agent is better / will be better about disk space management so this should be less necessary than it used to be.

0 Kudos
Lesley
MVP Gold
MVP Gold

I have never uninstalled the jumbo before installing a new one. This could give more issues then it solves. You will go back to the default R81.20 image without ANY fixes. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
genisis__
MVP Silver
MVP Silver

Only time I've seen an issue is with one gateway where you can no longer access the device using SSH, but once the new Jumbo is installed all worked.
Other then that, I've never since an issue, keep in mind your doing this on the Standby first so by the time you cutover to it the new jumbo has been applied.

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

You can use exactly the same process, the VSX gateway is updated as a whole unit, there's no per VS configuration or updating required.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events