- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
I am upgrading my FWs tomorrow. I am planning to upgrade the Management, then the log servers, then the Gateways. Someone told me at work that I can't upgrade the Mgmt server or log servers without disconnecting clients. Can anyone verify? I think I have upgraded the mgmt servers in the past without disconnecting users from the Gateways.
100% you can. Clients dont vpn into log or mgmt server, but the gateways.
Best,
Andy
100% you can. Clients dont vpn into log or mgmt server, but the gateways.
Best,
Andy
That is exactly what I thought....but, I was talking to their their tech support about something else...on chat... and the tech told me to call in to verify because clients WILL get disconnected from the security gateway if I upgrade the management server. So frustrating. So...now I'm calling in to verify that it won't impact clients.
Not sure why he would tell you that. In 16 years dealing with CP I must have done 100+ upgrades, at least, NEVER had an issue where upgrading mgmt server would have caused this problem.
Best,
Andy
SmartConsole users will need to be disconnected from Mgmt prior. Which type of clients do you have connecting?
Note you can temporarily disable CRL checks if the Management is planned to be offline for an extended period.
The only clients connecting are those connecting via VPN to the Gateways. I'm thinking their Chat Tech is giving me the wrong info. I should be able to upgrade the Mgmt and Log servers without effecting User client connections to the GWs
100% he is giving you the WRONG info
Best,
Andy
Thanks man. Lots of boxes to check on this and the right info is pretty key. Happy Holidays to .
Here comes my corny joke, last time for 2023 lol
For you mate, no charge...EXCEPT Iphone charge. You dont need to laugh -:)
Best,
Andy
In case you will upgrade management: Clients will be disconnected from MANAGEMENT ONLY, NOT from the gateways.
In case you will upgrade gateways: depending on gateway's current version, it might be possible that clients will be disconnected from upgraded GATEWAY. If management is connected behind same affected gateway, then also clients from management will be disconnected.
Please double-check drawings/topology what is in place to avoid surpises. Proper and up-to-date documentation is a key 😉
Note the MVC failover limitations:
Not only that it won't disconnect (users, if admins have a session open to a server that is going upgrade naturally it will be disconnected ongoing session), if you have more than 1 log server you can totally avoid local logging on GW.
your statement about local logging in not correct. If one of configured log server is down, gateway starts to log locally even second log server is up and logs are sending there.
If you used the "Distribute Logs" check box in the log servers configuration page on the gateway / cluster editor, the logs will simply be sent to the available log server when one goes down, without logging locally.
This is a feature from R81 and very useful for better load handling of logs, and log resiliency.
100% true, had customer scenario as such recently.
Best,
Andy
That is very interesting. That SK says it is "expected behavior" and they are going to change it in the future but it seems more like a bug to me. Certainly not what I would expect/not intuitive that it would behave that way.
My assumption is that they "fixed" it by the "Dynamic log distribution" feature which Tomer mentioned above, but forgot to update SK.
The relevant article about local logging has been updated 🙂 Now it is crystal clear when the gateway starts to log locally.
@Amir_Senn 🤣🤣🤣🤣
serenity now!! 😆😆
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 21 | |
| 17 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | 
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY