Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JoSec
Collaborator

Hardware Migration Procedure

We are migrating to a clustered pair of 15600 appliances with R81.10 to a clustered pair of 19100 appliances with R81.20. We followed a procedure of setting up the 19100s in a lab with an SMS server that had the production SMS database imported and we configure the appliances, pushed policy, did extensive testing such as failover, mock traffic to test internal and external access to make sure the config was correct and then did a cutover from the old to new appliances. On the night of the cutover, we ran into an issue for the first time ever following the above procedure which was that some updateable objects used in our policy were not processing traffic and management wants us to follow a different procedure since we had to fall back and they do not want this issue to happen again.

 

New Procedure (The appliances will be reset and configured)

  • Shutdown standby 15600 appliance.
  • Power 19100 standby appliance with the same config as the standby member that was powered off. Gaia preconfigured with routes, DNS, etc., CPUSE updated manually and patched manually.
  • Establish SIC, change cluster version in management , get cluster topology and push policy to 19100 gateways.
  • Test connectivity from standby by following the procedures below.
  • Verify logging to management
  • Ping external and internal hosts.
  • Verify updates to blades.
  • Verify license status has been updated.
  • Verify updateable object database is up to date.
  • Follow the above procedure for the second 19100. See questions below.

Any issues with the above procedure or anything to add or change? I would like to the failover to the standby 19100, run our complete connectivity tests before I power down the last 15600 and bring up the second 19100. Would I just run cphastop, cpstop or clusuterXL_admin down on the active 15600? Also, I will do a "get interfaces without topology" but will I run into an issue with different appliances defined in the same cluster? Thanks

3 Replies
the_rock
MVP Platinum
MVP Platinum

This is process I followed many times, never had an issue.

https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216

Best,
Andy
JoSec
Collaborator

In regard to failover from the old primary appliance to the new appliance, there may be a preference for not powering it down until we validate the new appliance with extensive testing after the failover. Therefore, should I do a cpstop or will cphastop work to force new appliance from standby to primary instead of shutting down the old appliance.

0 Kudos
Vincent_Bacher

You may shutdown the switch ports.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events