- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Apart from having "fresh slate" and removing old gremlins, are there any other possible reasons to chose fresh install + vsx_util reconfigure over straight CPUSE upgrade on VSX? File system remains the same.. I would prefer simpler approach (CPUSE) unless someone can provide convincing arguments against it 🙂
I would use cdt 1.6. for upgrading VSX
https://sc1.checkpoint.com/documents/CDT/v1.6/html_frameset.htm
Thanks Martin but we're not that big to run centralised upgrades 🙂 three clusters...
You don't need to do it in bulk, you can upgrade just one vsx cluster..at time, i just take care about 99 % of things which you need to do manually 😉
Hi Martin
Which 1% does CDT not take care of?
BR,
Kaspars,
I did an upgrade like this less than a month ago, you read all about it in this post 12600 with VSX low on memory.
One is now with CPUSE and one is clean install, first thing I ran into is that the upgraded machine has an issue with the cluster state of the management interface. Second issue I found was that CCP was set to broadcast on the upgraded system but was set to auto on the clean install, ending up in broadcast/unicast setting.
VS0 is acting up due to the Cluster interface mis-configuration, state is active/down.
Identity Awareness is not working from a VS when it is running on the clean install system, the AD account gets locked within minutes. Move the IA using VS to the upgraded system and reset the lock and IA works just fine.
My customer is not really happy to execute the recommendation from TAC, to do a clean install (for the interface issues) on the other machine as well, as they fear that IA won't work at all anymore.
So it really depends, a clean install will set all R80.20 defaults, that are done below the VSX reconfiguration levels. An upgrade will keep the system as is, which in some cases is what you want/need.
I used CPUSE from R77.30 to R80.20 without any issues for VSX, as you say the FS remains the same on gateways. I thought of fresh install but time and logistical constraints made me go first to try the in-place upgrade and if it failed anyway I would have spent the rest of the day running around DC's imaging appliances.
So as much I like clean installs between major versions, I can't say I found relics or unexpected behaviors other than linked to the new OS itself, solved with the latest hotfix. 🙂
I had less joy with R80.30 where all VS disappeared when running commands in expert mode (vsx stat and the like) but would still show up in CLISH. Upon restoring them by the means of multiple reboots and VS push from the I had to push a policy on every single machine to restore HA.
In-place upgrade of R80.20 to R80.30 for an SMS also failed, upon reboot, everything was gone and I had to resort to a new install with migrate export/import.
TL;DR: All good with R80.20.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY