- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hey guys,
Credit for this 100% goes to @yukaia . I wanted to share it, as Im sure a lot of people may never heard about it (I certainly never have) and would always reboot, go into maintenance mode and run lvm_manager and then extend, reboot again.
Examples that can be done and works on vm, physical box, regardless of the version/jumbo hotfix:
lvresize -L55G vg_splat/lv_log
xfs_growfs /var/log
Run df -h to verify!
WARNING: As @emmap had indicated, this would prevent you from doing major upgrades (jumbos would work on same version), and I even confirmed with R&D that there is NO WAY to bypass this requirement, since OS needs to have enough unallocated space to generate snapshot during the upgrade.
Andy
Hi, you're all adults so I'm not going to tell you what not to do with your stuff, but:
This sort of thing can remove the ability to perform in-place upgrades via CPUSE due to lack of unpartitioned space. It can also remove the ability to take snapshots for the same reason. As such it is not supported to do this on CP appliances outside of an explicit recommendation from TAC with accompanying SR/guidance.
That said, here is the SK about adding a disk to a VM or open server that also utilises these commands:
https://support.checkpoint.com/results/sk/sk165122
Thank you Emma, I totally get your point, definitely something to consider. I was able to upgrade one of my lab fws today to R82, did not complain about anything.
Andy
You are 100% correct. I tested 2 lab devices today and snapshot failed, as well as cpuse verification upgrade. Just wondering, is there any way to get around that?
Andy
You can't shrink an xfs partition, so the only way to fix it would be to add more disk space if it's a VM.
I think so, yea...I went intomaintenance mode, but does not let me modify anything with unpartitioned space.
Andy
Unless there is another command to do it without rebooting, but I doubt it...
Andy
Yeah, it's a limitation of xfs.
K, fair enough. t least I extended partitions in my labs, so im happy with that 🙂
Andy
With VMs you can add more virtual disks with the SK I linked to up there, but if it's an appliance and you've expanded partitions and removed all the unpartitioned space, the only way to recover is to reinstall (and re-partition) from USB. Hence why it's unsupported and not recommended to do it.
Gotcha...just curious though, since its my labs, though I dont want to rebuild it, but even if I have to, not a big deal, but is there any workaround to get cpuse work after running those commands I linked in the post? Im using EVE-NG, though not sure if that makes much difference.
Andy
If the failure is disk space related then no, there's no workaround that I'm aware of.
The 'autosnap' part of the process isn't something that can be skipped - as I understand it, the upgrade procedure creates a new root partition with a clean install of the new version, and then copies data from the old root over to the new one. The 'autosnap' snapshot that remains available as a rollback point is that old root partition, it's not a fresh snapshot like a manually taken one would be. So the requirement to have enough unpartitioned space isn't something that can be bypassed.
Thanks as always, amazing help from you!
Andy
We still have to grapple with larger images as time goes by, for instance the latest Blink for R81.20 is 10Gb, R82T12 is already 8GB and just getting started.
We're at a point where the only way forward to upgrade some versions is to clean install as appliances don't scale with multiple upgrades, even for the next JHF.
Deleting older folders still containing R80.x repositories in CPda and/or messing with partitions isn't the greatest feeling either, so either we get appliances shipped with TB of disk space or and advanced CPUSE which keeps the file system up to date for continuous upgrades.
@Alex- I agree 100% with all you had said. Btw, I had a call maybe about a month ago with genetleman from Israel office (cant recall his name now, super nice guy), we discussed things about upgrades and he told me they are working on developing a script that would clean up unnecessary files/packages after the upgrade or even before major one.
Brilliant idea.
Andy
Absolutely, it's particularly painful that the Maestro Orchestrators only come with 120gb SSDs in them.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
11 | |
7 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
4 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY