- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hey everyone, hope you are all well.
Background for this query is we have a clustered Active/Passive pair of R0.30 firewalls currently Centrally managed for 4CPUs.
We have already been to CheckPoint and traded the 4 Core licenses in for replacement 8 Core licenses.
I now need to get round to adding the new licenses to the Manager and applying it cluster. I need to make sure the firewalls continue to process traffic when applying the new licenses.
I'm not clear whether any rebooting is required to get the firewalls to light up the new cores?
I am guessing that it will allow me to apply the 8 core licenses along side the 4 core licensed and then will just spawn some additional fw_workers straight away. I can then safely remove the old 4 core license?
But its only a guess!
Can anyone advise?
Many thanks
Tim
Adding the eval license changes nothing.
I found Graceful failover with CoreXL mismatch after a CoreXL license upgrade .
Looks like state sync is possible like the same procedure for upgrades with "cphacu". That's new for me, but interesting that a change like you do could be done without interruption.
Wolfgang
@Tim_Spencer you lost your connections, because state synchronization between the nodes does not work if they have a different count of cores. You can change add the new licenses, change the cores and then reboot one by one. But be aware of the small gap.
Cluster will be failover but no state synchronization.
Wolfgang
PS: regarding @PhoneBoy , yes he's someone with a really great knowledge about all CheckPoint things, but in contrast to god he is a real awesome person 😉
Adding the eval license changes nothing.
I found Graceful failover with CoreXL mismatch after a CoreXL license upgrade .
Looks like state sync is possible like the same procedure for upgrades with "cphacu". That's new for me, but interesting that a change like you do could be done without interruption.
Wolfgang
You can uncheck "Drop Out of State TCP" on the Stateful Inspection screen of Global Properties to help blunt the effects of a non-stateful failover. Be sure to recheck the box when all done!
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY