Hi Maestro Masters,
I have a question regarding Security Group upgrades: when doing standard Cluster upgrades, I would usually upgrade the Standby Member to the latest version and then install the recommended Jumbo for that version right away before doing a failover to the upgraded Cluster Member. I consider this best practice because I do not want a Cluster Member with a base image (no Jumbo) to handle production traffic.
With Maestro, this does not seem to be best practice. According to the Admin Guide, there is the possibility to "install the required critical Hotfix on the Security Group Members" but this step applies only if "Check Point Support or R&D explicitly instructed you to install a specific Hotfix on your specific Security Group in the middle of the upgrade".
The standard upgrade procedure would therefore be the following:
- Upgrade Security Group Members in Logical Group A to latest version
- Failover to Security Group Members in Logical Group A
- Upgrade Security Group Members in Logical Group B to latest version
- Install Jumbo on Security Group Members in Logical Group B
- Failover to Security Group Members in Logical Group B
- Install Jumbo on Security Group Members in Logical Group A
How is your approach to this? I personally do not like the idea of SGMs handling traffic when they have no Jumbo applied yet.
Thanks!
Kilian