- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I have a pair of 5800 gateway appliance running R81.20 in HA mode. These devices go end of hardware support today (30 Sep 25) and I have a pair of new 9400 appliances due to be delivered in the next few days.
I anticipated that the new devices will come with R82 and so I have pre-upgraded our management from R81.20 to R82 already.
I know that R82 and R81.20 appliances cannot sit in the same cluster and obviously cannot have the same HA or IP addresses as the existing devices, but what I cannot find is any documentation showing the best way to replace them.
This is how I am planning to approach this:
1. Build / Install the R82 gateways with a new management address (and adding them to firewall rules).
2. Configure interfaces and IP addresses the same as R81.20 counterparts, leaving them disabled.
3. Add routing tables and Proxy ARP the same as R81.20 counterparts.
4. Failover 81.20 to the Secondary
5. Shut down the R81.20 Primary
6. Reset SIC on the Primary host in the cluster object
7. Enable interfaces on R82 Primary.
8. Upgrade cluster object to R82 and rest/initialise SIC for Primary host.
9. Push policy to individual gateways (Should work on R82 and Fail on R81.20)
10. Failover to R82 Primary
11. Repeat steps 5, 6, 7 for Secondary appliance
12. Push policy to gateways
I don't know what will happen in step 7-9 when I bring the R82 primary online. Will there be two devices trying to become ACTIVE?
In step 10 will I have to shut down R81.20 Secondary to get the failover to work properly?
I would like to hear your comments and advice on this.
(Thanks in advance)
I would just follow below process, had done it many times, never had an issue.
Andy
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216
I would just follow below process, had done it many times, never had an issue.
Andy
https://community.checkpoint.com/t5/Security-Gateways/Replace-Upgrade-Cluster/td-p/69216
Thanks, this is fairly similar to the approach I was planning... will report back when completed.
Exactly! The best part is you dont need to worry about MVC feature, since its automatically enabled since R80.40
Andy
What a timely post! I am doing the exact same thing with the same old and new hardware as you in about a month.
I had to change some interface names because we are using more 10 gig interfaces and the old fw we used none.
Good luck to us both!
I found same process I linked worked well even for R82.
Andy
I don't have a delivery date for our replacement yet, but hope yours goes well...
We are moving up to 10G interfaces from 1G too, but in our case we bond them and add VLAN subinterfaces so the bond and the subinterface names will remain the same; only the bond members will be changing.
Just make sure if say sync interface would be different link/speed, something to keep in mind, as thats important.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 19 | |
| 16 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY