Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
velo
Collaborator
Jump to solution

Upgrade Cluster

I want to upgrade my pair of 6200s. They are currently running 81.10 and I want to upgrade to 81.20.

I have completed upgrades before but only upgrading the HF version. Previously my steps for upgrading HF version were in summary:

• Upgrade Node2 standby node using CPUSE and reboot
• Failover traffic to Node2 standby node (now upgraded) to make it active. (Using clusterXL_admin down down on primary node)
• Let the Node2 firewall process traffic for a while. Once happy proceed
• Upgrade Node1 using CPUSE and reboot
• Fail traffic back to Node 1
 
My understanding is that when you upgrade a major version e.g. 81.10 to 81.20, the firewall will come up with a default policy after the upgrade. Is that correct? If so, I would adjust my steps accordingly as follows:
 
• Upgrade Node2 standby node using CPUSE and reboot
• Push policy to both firewalls in the cluster  [New step]
• Failover traffic to Node2 standby node (now upgraded) to make it active. (Using clusterXL_admin down down on primary node)
• Let the Node2 firewall process traffic for a while. Once happy proceed
• Upgrade Node1 using CPUSE and reboot
• Push policy to both firewalls in the cluster  [New step]
• Fail traffic back to Node 1
 
Thanks

 

0 Kudos
37 Replies
the_rock
Legend
Legend

I would absolutely try CDT, from my experience, works well with minor upgrades.

Andy

0 Kudos
velo
Collaborator

Thanks Andy. FYI, I just did the upgrade with CDT in my lab and I have to say, it went very smoothly. It's a bit hard to know if it's hung so I just did a tail on /var/log/messages and it gives you a good indication of what's going on.

It's good I have tested both options. I think for this jump I might use CDT and for more major upgrades I will use the other method Andy.

Thanks both for your good insights. 

the_rock
Legend
Legend

No problem man, we are always here to help people. Yes, thats what I would stick with, exactly how you described it. Anyway, if you get stuck when doing it, just message me.

Andy

0 Kudos
velo
Collaborator

Hi Bob and Andy.

I've been looking at this article:
https://support.checkpoint.com/results/sk/sk111158

I checked and my CDT is version 1.9.2

Do I need to download and install version 2 as per the article?

 

 

CDT package

  1. Download the above CDT package to your computer.
  2. Transfer the CDT package from your computer to your Management Server (into some directory, e.g., /some_path_to_CDT/).
  3. Connect to the command line on the Management Server.
  4. Log in to the Expert mode.
  5. Unpack the CDT package:
    [Expert@HostName:0]# cd /some_path_to_CDT/
    [Expert@HostName:0]# tar -zxvf <Name_of_CDT_Package>.tgz
  6. Install the CDT rpm:
    [Expert@HostName:0]# rpm -Uhv --force CPcdt-00-00.i386.rpm

 

0 Kudos
the_rock
Legend
Legend

You can, but I never bother, and works fine. Though, honestly, it would not hurt if you did it.

Andy

0 Kudos
the_rock
Legend
Legend

Hey @velo 

Just to help you further, I checked my cdt version and shows 1.9.5, did uprade with cdt method, no issues (just a jumbo install). Then, updated cdt to 2.0, did same type of upgrade, worked fine.

So, definitely can make it better if you install latest version, so I would do it, for sure. I know I said I would not bother in my last post, but its prudent to be on latest code for these things.

Andy

velo
Collaborator

That's great, thanks Andy 🙂

I also did it in my lab and it worked well. 

Thanks for also testing.

the_rock
Legend
Legend

Awesome man!

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events