- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi,
I have a cluster running R75.40 (yes I know... ^^). I have upgraded member2 to R80.10.
Basically I would like to perform the following steps :
- switch the traffic to member2 (newly upgraded to R80.10) (cphacu start no_dr + cpstop as per ClusterXL admin guide)
- perform pre-upgrade actions on member1 such as Download agent upgrade, etc. These actions include reboots. The actions to be performed are scripted so that our admins only have to run one script that manages the whole upgrade (pre-upgrade actions, CPUSE upgrade, JHF installation, customization...).
My problem is that due to different version numbers (member2 already upgraded) member1 will systematically be active after the reboots.
I have tried to deregister the pnote registered I guess due to version number mismatch : $FWDIR/bin/cphaprob -d admin_down unregister, and then register a new one with the "-p" : $FWDIR/bin/cphaprob -d admin_down -t 0 -s problem -p register but the failover does not occur and the persistant info is not taken into account, most probably due to different versions.
Is there a way to make a cpstop survive to a reboot? This is in order to avoid member1 to become active after pre-upgrade actions and reboot.
Maybe I missed something but I couldn't find anything that could help.
Thanks
cpconfig
This program will let you re-configure
your Check Point products configuration.
Configuration Options:
----------------------
(1) Licenses and contracts
(2) SNMP Extension
(3) PKCS#11 Token
(4) Random Pool
(5) Secure Internal Communication
(6) Disable cluster membership for this gateway
(7) Enable Check Point Per Virtual System State
(8) Enable Check Point ClusterXL for Bridge Active/Standby
(9) Disable Check Point SecureXL
(10) Check Point CoreXL
(11) Automatic start of Check Point Products
(12) Exit
Check option 11 should be what you are looking for
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY