- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi gents,
Based on practical experience and leaving aside the R81.20 release notes, would you recommend R81.20 on centrally-managed 3200 appliances or should I stick to R81.10?
I have tried R81.20 on a standalone (locally-managed) 3200 appliance and it almost brought it to its knees, SmartConsole was mostly unresponsive and the appliance itself was very much struggling.
I'm worried that R81.20 might be too heavy for the 3200 even if it's centrally-managed?
Thanks,
Daniel
For context how much traffic is the appliance expected to see and what blades are you planning to enabled?
It's running Firewall, IPSec, APPCTRL, IA and IPS
Below load is in off-hours, I didn't get the chance to check it during the day:
CPU User Time (%): 2
CPU System Time (%): 11
CPU Idle Time (%): 87
CPU Usage (%): 13
CPU Queue Length: -
CPU Interrupts/Sec: 6691
CPUs Number: 4
In general, it should work but please allow me to rephrase. What is the expected throughput?
Note HCP will help to identify any gotchas with the current configuration.
Also run a cpsizeme (sk88160), it gives a good performance overview (send to your SE)
Thank you, I'll give that a go and evaluate it.
On a first attempt, it seems to have failed; CPUSE gives me following error without any other information:
<b>Upgrade of package Check_Point_R81.20_T631_Fresh_Install_and_Upgrade.tgz Failed</b><br><br>Failed during export process.<br><br>Contact Check Point Technical Services for further assistance.
It can run on the 3200 with R81.20 but this is according to load / enabled blades. As Engineering support ends next December i would rather trade them in 😉
Noted, replacements will for sure be purchaset at a later time; for now I need these 3200 appliances upgraded asap.
If R81.10 + Rec JT works as expected i would just stay - but that is a personal decision. NCARS 😉
Might indeed be the way to go, I was optimistic and hoping to have it on R81.20 🙂
Now this is new to me.. if it would have somewhat made sense on R81.20, but for R81.10 it comes as a surprise.
Please open a support call with TAC for this.
Already on it, managet to get an SR registered for this. Thanks 🙂
What is the reason, low disk space ?
What is the current source version & Jumbo that you are upgrading from?
How much disk space is free and is the Deployment Agent up to date?
Upgrading from R80.40 JHF 196; doesn't look like a free disk space issue to me at least (see image shared above).
Agent: Enabled
Build number: 2337 (agent build is up to date)
Network connection: connected
Update from cloud: Last updated on Tue Nov 7 10:49:27 2023
License: Valid
Thanks as Val suggests please contact TAC who can assist in reviewing the logs for the upgrade failure/s.
A fast update on this issue - Checkpoint TAC didn't manage to pinpoint the root cause for this upgrade failure. A lot of hours got used on this issue and I was forced to move on, so a R81.10 fresh install was done for the appliance.
Without a root cause, there's not much to learn from this fault unfortunately, except for the fact that one can be lucky or unlucky with TAC depending on the skills of the enginner assigned for the SR.
You can always ask for the case to be escalated if you stall out. Whenever you are doing upgrades, let your SE know ahead of time (we hate getting calls for something we didn't know was happening), and you can also open a proactive case and pre-load it with all the information about what you are doing.
*** ALWAYS include the following when opening an SR ***
cpinfo from management and all devices involved. ***This is always going to be asked for***
A "show configuration" from all devices involved.
A "migrate export" of the manager.
I will normally open the ticket online, add the above, then call into TAC.
Hi!
Tried today to install latest R81.20 Blink + JHF T41 to 3200 cluster.
Installed to standby member. Installation took about one and half hours!!!
After done, it keeped eating one cpu core about 100% (fw_full) even being standby member, didn't find reason. Reverted back...and never installed another member...
-A
Yeah, it very much depends on how many blades you have active. I for one decided to stick to R81.10 and will keep patching for as long as it will be supported, the 3200 will anyways be end of life roughly the same time as R81.10 (end of engineering support June 2024, end of support December 2025 for the appliance, end of support July 2025 for R81.10).
Support Life Cycle Policy - Check Point Software
/Daniel
Actually installed 81.10 today to same environment. Same results. Waited for 45 minutes and cpu calmed down.
Also found reason: System is just so slow (slow hdd). For example fw load_sigs took very long time.
Sticked to R81.10, because those are going to replaced before end of support.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
12 | |
8 | |
7 | |
6 | |
6 | |
6 | |
4 | |
4 | |
3 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY