Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
vinceneil666
Advisor

R80.20SP -> R81 (Mastro) (edited:r81.10 -> R81)

Yo,

I am planning an uppgrade from R80.20SP til R81 for mye dual site, two security group, maestro enviroment. 

Read trough sk170696, and the 'surrounding' sk's 🙂 But I do not feel 100% comfortable, so - anyone done this before ? tips n tricks ? 

What I find a bit hard to wrap my head around is how to handle the interfaces on the orchestrator. Looking at the SK it pretty much tells me to establish the new sec.group with new interfaces (downlinks, I assume) Ste6 tells me to esablish SIC, but then step8 tells me to connect cables ? -- Will I even be able to SIC this with no downlinks available ? 

I have tons of interfaces in the old security groups, how do I bring those over ? they might be pulles from the config i put int the appliance in step4 ? 

 

Anyone had any 'hands on' here ? 🙂 

 

 

0 Kudos
2 Replies
Benedikt_Weissl
Advisor

I did this some time ago in my lab so take everything below with a grain of salt. The basic steps are:
1. Split up the old SG into a new and an old SG. Install the new SG with the target version (r81.10).

2. The new SG gets different interfaces on the Orchestrator, disconnect the management interface from the old SG, severing old SG and SMS. The management interface should be used to establish SIC.
3. Transfer all gaia settings from the old SG to the new SG. Change the version of the SMO on the SMS and install policy on the new SG.  Now you have 2 SG with the same settings but different versions, yet one isn't connected to the network yet.
4. This is where the downtime starts: Disconnect the cables from the old SG and connect them to the new SG.
5. Check if everything is working again, keep distribution modes in mind: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos
vinceneil666
Advisor

Thanks Benedikt,

Starting out with r80.20sp we had to do all the interfaces (all the vlan interfaces) in the orchestrator in addition to the sgm itself. After jumo sometinhsomething ofcoure we did not any longer have to do this - since it will be synched from the SGM.

So I would assume that using different interfaces for the downlinks between orchestrator and appliances is just part of a 'two step rocket' thing ?  What I am having a hard time wrapping my head around is why we would need to add new interfaces to the new SG - or if it is just a temporary thing ? 

0 Kudos