- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Hi Team,
I need your advice:
I have a dual-site MAESTRO (2pcs MHP140, 4 pcs CP6500). The CP6500 are end-of-life soon.
The new SGMs are CP9300. I know the mix-and-match does not work between this types.
What would be the most effective process of the change from the downtime point of view?
Have somebody done such kind of changes already? If yes, what was the experience? Please share with me.
I have two scenario:
I don't want to do it without outage, because it is impossible, but I want to cause as short outage as is can.
Every answer would be very appreciated!
Akos
As long as everything is on the same version (so R81.20) the configuration will sync between your SGMs. You can't use auto-clone though as they are not the same hardware. So, add the new ones, let them sync config, remove the old ones, install JHF take on the new ones, check CXL config and reset if you need to (enable dynamic balancing, basically).
Hi @emmap ,
thanks for the valuable info.
We did the same steps but the results sere different.
If we created a new security group and did the steps that you mentioned -> the result was the new SGM came up to active and everything was fine.
but an upgraded SG (which was r81.10 before) the new SGM remained in detached state, the version was r81.20 as in the first step.
Did you expreienced this kind of behaviour?
And one more question:
if I put an SGM next to 2 SGMs its “number” will be 1_3. The member id remains this if remive the two old sgms?
akos
Not sure I properly follow. The existing MHOs and SGMs must be running R81.20 before you can add the 9300s in, as they are also running R81.20 (though you may have to re-image them to the Maestro R81.20 image if they are not already running that).
Yes when adding a new SGM, it will take the lowest available ID. So if you have 2 SGMs in the group and you add another one, it'll be 1_3. If you remove SGM 1_2 from the group, you'll have a group with 1_1 and 1_3 in it. If you then add another SGM it'll take the 1_2 ID.
Hi @emmap
A short summary of the chnage:
The arrange of the other three SGMs into Security Group were easy after this experience.
Cleaunup: we remoed all EVAL licenses from the SGM-s g_cplic del <signature>
Akos
Is it not better to install the Jumbo before makeing it a cluster?
If you have a default R81.20 image and mix it with other gateways the version difference is to big.
Also many issues solved in a jumbo so was maybe worth testing to build it with updated systems.
Of course no license does also not help 😉
Ok, but if I want to intall a jumbo hotfix onto an SGM, the SGM must be in Security Group.(admin guide)
So how? 😉
Hi Bako's,
I recently came across your thread and found it extremely insightful—thank you for sharing your experience.
I’m currently managing a Maestro setup with:
2 Maestro Orchestrators on R81.10
1 Security Group with 3x 6600 SGMs, all running R81.10 JHF 110
We are planning to replace the 6600 SGMs with 9300 appliances, which come preloaded with R81.20.
I have a couple of questions based on your experience:
Did you upgrade your Maestro Orchestrators and existing SGMs to R81.20 before introducing the new 9300 SGMs?
If all components (Maestro + existing SGMs + 9300) were already on R81.20, were you able to add the 9300 appliances directly into the Security Group without issues?
Any insights or best practices from your upgrade process would be greatly appreciated.
Mahesh
@Maheshreddy You are commenting on a post which over a year old.
I suggest opening a new discussion for your needs.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY