Thank you very much for your response,
this was the biggest confusion on that which method i should go for, customer do not want any downtime at all but checkpoint TAC support suggested "zero downtime" method.
when it says, VPN and mobile access are not supported, should i expect that VPN will go totally down and/or i will have to re-build them after the upgrade?
again, TAC told me that, VPN should survive as at least one cluster member will always be UP.
a lot of confusion on TAC's advice vs user guide.
please suggest.