- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: R80.30 to R81 Upgrade
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.30 to R81 Upgrade
Hi all,
I'm planning to upgrade my 2 5200 SG to R81.
Actually, here is my structure :
- 1 SmartCenter and 1 SmartEvent (VmWare) running R81 for about 1 year
- 2 5200 SG appliances running R80.30, in a ClusterXL HA mode
- Blades : FW, App Ctl, Identity Awarness, QoS, IPS
Both Mgmt servers are in kernel 3.10.0-957.21.3cpx86_64 (with xfs), but not the SG (kernel 2.6.18-92cpx86_64).
What would you advise me to do ?
One point is that both SG are quite far away from my desk, in our DataCenter, so i can't loose connection to them ...
Thanks !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please review the documentation and the upgrade Wizard per:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowupgradewizard
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RN/Default.htm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just my personal experience...I had cases before when people would say "O, not a big issue, firewalls are remote, what can happen, its a cluster"...well, you'd be surprised. I do NOT recommend doing the upgrade if you dont have physical access to the boxes. I had a scenario happen where one box does not come up after upgrade/reboot and then clustering is totally broken and someone has to go to the location at the end of the day.
I recommend zero downtime method (I find works the best). By the way, make sure you do management upgrade first, as thats always recommended, since version on mgmt has to be same or higher. Links Chris gave you are good starting point.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi guys, thanks for your replies.
I think i will bring one SG back to the office, upgrade it, and then process with the other.
Downloaded the Check_Point_R81_T392_Fresh_Install_and_Upgrade_v1.tgz, that seems correct to proceed with ?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That shouldn't be necessary in most cases.
I gather the units don't have LOM cards installed?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, no LOM card ...
Finally, i'm going to start the Clean Install on the Standby node (ClusterXl_admin down before).
If something goes wrong, i will go to our datacenter.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi all,
Well, this has been quite a stuff 😤
Finally, active member upgraded, but some things didn't went as expected :
cloning group has disapeared, had to recreate on both membres,
IPS licence on trial mode (positive false ?), all other licences synch'd well
So now, eveything is working good, thanks again for your advices !
