I want to upgrade my pair of 6200s. They are currently running 81.10 and I want to upgrade to 81.20.
I have completed upgrades before but only upgrading the HF version. Previously my steps for upgrading HF version were in summary:
• Upgrade Node2 standby node using CPUSE and reboot
• Failover traffic to Node2 standby node (now upgraded) to make it active. (Using clusterXL_admin down down on primary node)
• Let the Node2 firewall process traffic for a while. Once happy proceed
• Upgrade Node1 using CPUSE and reboot
• Fail traffic back to Node 1
My understanding is that when you upgrade a major version e.g. 81.10 to 81.20, the firewall will come up with a default policy after the upgrade. Is that correct? If so, I would adjust my steps accordingly as follows:
• Upgrade Node2 standby node using CPUSE and reboot
• Push policy to both firewalls in the cluster [New step]
• Failover traffic to Node2 standby node (now upgraded) to make it active. (Using clusterXL_admin down down on primary node)
• Let the Node2 firewall process traffic for a while. Once happy proceed
• Upgrade Node1 using CPUSE and reboot
• Push policy to both firewalls in the cluster [New step]
• Fail traffic back to Node 1
Thanks