Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
H1pp0o
Contributor

Upgrade from R77x to R80x

Dear Community,

 

I would like to ask you or maybe confirm if the approach of migration will work.

 

We have an old environment running R77.30 ( Mgmt and GW ). Unfortunately we cannot proceed with migrate export process on the SMS. We rebuild the whole policy and objects ( dumping object and rules file with odumper into csv ) on R8.40 SMS. Next step is to swap from old to new SMS. Plan is to disconnect old SMS and re-establish SIC connection with new SMS.

 

Question. If this will work or can we expect some complications ? If so, what kind ?

0 Kudos
9 Replies
the_rock
Legend
Legend

That sounds right, just make sure routing is there, as obviously its needed for SIC to work with the gateway(s), unless its just one standalone machine.

Andy

H1pp0o
Contributor

yes, routing and connectivity both ways is open on all CPX required ports.

 

thanks 🙂

the_rock
Legend
Legend

Then you should be okay.

Andy

Tal_Paz-Fridman
Employee
Employee

Why are you not able to migrate export? Also what about directly upgrading the machine to R80.40 (and then even to a higher version like R81.20)?

 

If you do decide to use the newly built R80.40 Security Management Server consider doing it in stages. Establish SIC with just one Security Gateway and install policy. 

If it works properly (including logs and statuses) and you do not encounter and issue over a predetermined time frame, continue with the next Security Gateway and install policy - first on the newer one and then on both.

Continue until you have moved all the Security Gateways.

H1pp0o
Contributor

Migrate export crashed already one node from the SMS HA. So no further risk to make it once again on that remaining member. 

After we move the gateways under new SMS next upgrades to R81.x will be continued.

 

 

Thank you for your help !!

the_rock
Legend
Legend

Thats my thinking as well.

Andy

0 Kudos
the_rock
Legend
Legend

Personally, I would still try open TAC case if needed, because you are upgrading to supported version, so if you do get stuck, they should be able to help you out. I get its upgrading from unsupported version, but dont believe that should be a stopper.

Andy

0 Kudos
H1pp0o
Contributor

Sorry to say that - but even with a valid maintenance contract TAC did not helped in this case at all. 😞

0 Kudos
the_rock
Legend
Legend

Thats disappointing...maybe bring it up with your Sales person, see if they can push it further. I know any fw vendor will always help if you are going from unsupported to supported firmware/version.

Best,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events