Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Fabz
Contributor

Upgrade Management Appliance - Downtime required?

Hi Checkmates,

We are planning to upgrade Smart-1 600M from R81 to the latest version since this version will be out of support Oct 24.

On this appliance, we enable almost everything such as SmartEvent, Compliance, and also EPM for 200 users..

Any suggestion before we upgrade to the latest version? we already backup the configuration and waiting approval from C level.

 

however, a few unanswered issues that I should clarify:

  1. Does the FW and EP specifically encounter an issue during the upgrade process?
  2. If failed, would the appliance simply revert to the previous OS or would it become corrupt and require a reinstallation?
  3. How long is the estimated downtime, if any?

Thank you!

0 Kudos
6 Replies
the_rock
Legend
Legend

I had done this probably 100 times and never had a single issue. In some RARE cases, which I had never encountered in all my years doing this is that say if there isn a problem with mgmt and CRL does not work within 24 hours, thats only issue I ever heard of, but personally, I never had that problem and its probably less than 1% chance that would happen.

One thing I would be aware of is that if you have mgmt with lots of space, it could take 2-3 hours to do FULL upgrade, as once it reboots, it would tell you its re "importing" the database over, but thats totally normal.

Other than that, I cant think of anything else that would be an issue.

Best,

Andy

0 Kudos
G_W_Albrecht
Legend
Legend

If you do a In-Place upgrade, you will need much free partition space as a new partition with the new version is created, database is exported from the old and imported to the new version. If that fails, old version partition will boot again.

Usually you will use migrate_server export to export the database and migrate_server import to import it to the fresh new SMS.  Two points are important here:

- do you need the logs ? You have to export them without index using the -l option with migrate_server

- do you need the EP msi packages ? You have to use --include-uepm-msi-files with migrate_server

Details can be found here: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

I would do the migrate_server as a backup even when using In-Place upgrade...

 

CCSE CCTE CCSM SMB Specialist
the_rock
Legend
Legend

True, good points you made.

Andy

0 Kudos
genisis__
Leader Leader
Leader

Also, correct me if I'm wrong if an in-place upgrade is done then the manager cannot take advantage of the XFS filesystem, which is a good reason to clean build and import.

0 Kudos
the_rock
Legend
Legend

Was not aware of that, but doing a clean build and import is never a bad idea.

Best,

Andy

0 Kudos
G_W_Albrecht
Legend
Legend

Depends, see https://support.checkpoint.com/results/sk/sk141432 - a new file system (XFS) was introduced in Gaia OS with kernel 3.10 (R80.30 and higher versions). So check which FS is in use, see the SK.

 

CCSE CCTE CCSM SMB Specialist

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events