Here is my suggestion as a guide:
Pre-Req:
Manager must be running R80.30 or Above with latest GA release, ideally manager should be running R80.40 or R81
Manager should have access to the internet.
Ensure you have a local resource to support the activity.
Any customised files should be copied offline and modifications restore on newly built gateway if required (Optional)
- Create snapshot of all appliances and store image offline
- save GAIA configuration and save offline
- Using ISOMorphic tool create a USB image.
https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/m...
https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/m...
- Detach the existing gateway license via SmartUpdate and export this offline, then delete it.
- Do a clean installation of the standby 4600 (assumed you have 4600 and not 4400, but I don't believe the image file would change) appliance and put the GAIA configuration back on.
- Install latest CPUSE agent
https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/m...
- Complete configuration wizard via https
- upload and install latest GA Jumbo release for R80.40 (Take_118)
https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/m...
- Re-Sic/Push Policy.
- If manager has access to the internet and your running R80.40 or above the license should get installed to the gateway via the manager automatically, if not then of course add the license back in and then push to the Gateway.
- Check HA stat using 'cphaprob state', it should be Active/Ready I believe.
- via clish enter:
'set cluster member mvc on'
'save config'
- Check HA stat using 'cphaprob state', it should be Active/Standby.
failover to the new node and test.
- Once you are happy with everything on the new node, the repeat this process for the remaining member.
- When the remain member is running R80.40 you can turn of mvc "set cluster member mvc off".
Note:
Yes - you could do an in-place upgrade, but I believe it is better (and actually the recommendation from TAC) to do a clean build.