- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
I can't find any documentation or posts that cover this. We are going from R77.30 on open server to R80.30 and would like to know the difference between these methods. I'm not concerned about keeping config, but would like the install to be as 'clean' as possible. Up until now have generally been using bootable DVD/USB and doing full format / install however for this gateway getting various traceback errors part way through so installing old version to do with one of these methods.
1) CPUSE > Major Versions > R80.30 Fresh Install and Upgrade for Security Gateway and Standalone
2) CPUSE > Blink Images > R80.30 Security Gateway
3) Copying blink image over to /var/log/ and running blink tool
Hi
Please see below for a short description of the installation methods
Will be glad to assist in any further questions.
Hi @Boaz_Orshav ,
Can you advise on the best approach for the following scenario:
7000 series gateways shipped with either R80.40 or R81 that must be deployed with R80.30.
My current inclination is to import the blink R80.30 and CPUSE > Blink Images > R80.30
Since I am doing it remotely, ISOmorphic is not a viable option.
Thank you,
Vladimir
Check Point 7000 appliance can't run GAiA R80.30. The CPU in the 7000-series requires 3.10 kernel and R80.30 only has 2.6 kernel. There is a special release of R80.30 with 3.10 kernel that can be used:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
But this is not a widely adopted or recommended release. These special 3.10 kernel releases of R80.20 and R80.30 got released because some newer appliances and open severs required 3.10 kernel because of their CPU's so Check Point had to come up with R80.20 and R80.30 releases with 3.10 kernel as the 3.10 kernel for gateways got pushed to R80.40.
It's R80.40 that is the first regular release of GAiA that features 3.10 kernel for gateways. I would recommend you to consider going with R80.40, R81 or R81.10 instead of going with the limited R80.30 3.10 release.
If you are doing it remotely, does that mean that you rely on ssh/webui? How do you access it? Does this mean that having the current configuration removed will result in you losing access? The gateway needs to have its IP address and default route in place for you to be able to reach it?
You can't use cpuse or blink package for R80.30 as the Check Point 7000 series does not support R80.30. If you have to use R80.30 and can't move to R80.40/R81/R81.10 you will have to grab the special R80.30 3.10 kernel release:
But please be aware that this is a limited release not widely deployed. It was released as a result of newer appliances and open servers requiring 3.10 kernel due to their CPU's not supporting the 2.6 kernel. R80.40 is the first regular release with 3.10 kernel for gateways and would be the recommended way of doing things instead of using the limited R80.30 3.10 release. Or you could of course go with R81 or R81.10.
These are the new appliances in a staging environment, so for the initial version adjustment, I am not concerned with interruption of functionality.
Thank you for the pointer about specific version for 7000s, although it'll be nice to know why those appliances require specific version to begin with.
Client has agreed to take the R80.40 upgrade route, but now we are facing the migration issues that must be dealt with.
Regards,
Vladimir
Note that in order to have the new filesystem, the only option is to install from ISO.
So if as you said you want to go "as 'clean' as possible", consider that option, it is the only one that formats your box.
In newer versions of Check Point GAiA there isn't much difference. Major upgrade packages are utilising blink for its deployment. Doesn't really matter if you use the cpuse package to do a clean install, or if you use the blink image for a clean install. The end result is basically the same.
A clean install is only cleaning the running gaia configuration. It will not reformat the hard drive. So the only way to actually do a full clean installation, and for you to get the XFS filesystem that was introduced with R80.40 for gateways is by doing a clean installation using isomorphic tools, iso and USB.
If you want a true clean install its either USB or using the LOM to install the ISO.
Blink is going to save you reboots by installing the latest patches associated with a given release.
Instead of, say, going R77.30->R80.30->R80.30 JHT XYZ using the old school tried-and true method you'd just go from R77.30->R80.30 JHT XYZ.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 16 | |
| 14 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY