- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
When upgrading Management HA from R77.30 to R80.20, after SIC reset of the Secondary Management Server we are prompted to install the policy before proceeding.
Yet in the Upgrade Guide, the steps in section 5 do not address this issue:
Make sure SIC communication works correctly with the Secondary Security Management Server:
Click OK.
Can someone clarify if we do need to install the policy or databases after resetting SIC of the Secondary Management Server, or is it safe to Initialize it and then install the database and policy?
Thank you,
Vladimir
Hi Vladimir,
The procedure to upgrade a management server is simple. You start with upgrade on your primary management server using CPUSE or advanced method according target version. When you upgraded the primary management server, open SmartConsole and push a install database only primary management server and you must to install policy on gateways to validate and reestablish connectivity between gateways and primary management server on TCP/257 port (Log).
Once a completed the steps above, you must perform a fresh install of secondary management server using .iso image or CPUSE package and when completed the "First Wizard", reestablish SIC with primary management server. Then, perform a install database on both management servers.
When you started the installation of database on both machines, a full sync process will be initiate to "copy" objects from primary management server to secondary management server.
Ah, don't forget validate logs! (:
I hope I helped you.
Alisson Lima
Alisson,
Please re-read my question again
The overall process works as you have described, but at the point when you click "Reset" on the SIC properties of your Secondary Management Server, the pop-up window states that you MUST install policy at this point, PRIOR to re-initialization of SIC with same server.
This step is not reflected in the Upgrade Guide and this exact issue I am trying to get a clarification for.
Do we have to close the properties of the Secondary Management server and install the policy as the pop-up requests we do, or do we initialize SIC and THEN install policy?
Thank you,
Vladimir
Vladimir,
Did you install policy through primary management server before perform reset SIC on secondary management server? If no, please try to install the policy and let me know if you can estabilish SIC with secondary management normally.
Thank you.
Alisson Lima
Alisson,
I have completed the upgrade before posting this question.
I have chosen to install database after seeing the popup requesting policy install after SIC reset action.
The problem is that this step is not documented and all I am trying to do is to get some clarity on:
1. Is it required to install policy after "reset" and before "initialize"?
2. Is it safe to complete the initialization and then install the policy?
Good question.
But as my experience upgrading R77.20 to R80.10,I didn't see the pop-up states.
Reset SIC and wait for the full sync ,that's all.
Are there any changes in R80.20?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY