- Products
- Learn
- Local User Groups
- Partners
- More
Maestro Masters
Round Table session with Maestro experts
Hi Maestro Masters,
I have a question regarding Security Group upgrades: when doing standard Cluster upgrades, I would usually upgrade the Standby Member to the latest version and then install the recommended Jumbo for that version right away before doing a failover to the upgraded Cluster Member. I consider this best practice because I do not want a Cluster Member with a base image (no Jumbo) to handle production traffic.
With Maestro, this does not seem to be best practice. According to the Admin Guide, there is the possibility to "install the required critical Hotfix on the Security Group Members" but this step applies only if "Check Point Support or R&D explicitly instructed you to install a specific Hotfix on your specific Security Group in the middle of the upgrade".
The standard upgrade procedure would therefore be the following:
How is your approach to this? I personally do not like the idea of SGMs handling traffic when they have no Jumbo applied yet.
Thanks!
Kilian
Hi the upgrade should be under maintenance windows, where traffic might be affected total or partially.
During window you can upgrade both members and start with hotfixes. the impact on traffic should be minimum
The upgrade process isn't re-QA'd with each JHF, so we can't say whether there's any degradation in the procedure if the JHF is installed halfway through the upgrade procedure. Hence we have that requirement in the procedure. For a regular cluster I agree and do the same thing as you, but for Maestro the procedure is a little more involved.
The upgrade to R82 is planned to be smoother, without all the sp_upgrade script stuff. I don't know if we will remove the requirement to avoid the JHF or if we will support blink images out of the gate though.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
7 | |
5 | |
4 | |
3 | |
2 | |
2 | |
1 | |
1 | |
1 |
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY