- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Users can follow the below procedure, in order to upgrade their VSX cluster from R77.XX to R80.20 (VSLS | In-place upgrade with Zero-downtime)
Things to discuss
A) Management Server
i) Pre-Start Tasks
ii) Operation vsx_util upgrade
B) VSX Upgrade Stand By Member
i) Pre-Start Tasks
ii) Upgrade (& Install JHF - optional)
iii) Verification
iv) Connectivity Upgrade
C) VSX Upgrade Active Member
i) Pre-Start Tasks
ii) Upgrade (& Install JHF - optional)
iii) Verification
D) Recovery Plan
A) Management Server
i) Pre-Start Tasks
1) Ensure there are no locks on objects relevant to the VSX upgrade and to show the list of all the locked objects in an R80.20 database, let’s open PostgreSQL on MDS cmd line:
# $MDS_TEMPLATE/bin/psql_client cpm postgres
2) To see current locks, run:
# select objid, name, dlesession, cpmitable, subquery1.lockingsessionid, subquery1.operation FROM dleobjectderef_data, (SELECT lockedobjid, lockingsessionid, operation FROM locknonos) subquery1 WHERE subquery1.lockedobjid = objid and not deleted and dlesession >=0;
3) To exit out of PostgreSQL: (mandatory!)
# \q
4) To remove current locks from Smart Console, go to Manage and Settings, view Sessions, locate the columns where "Locks" and "Changes" are not 0, and publish or discard session as required
5) **Take MDS and Firewalls – Snapshot & Backups before proceeding with the operation below.
6) Ensure Serial Console and/or LOM access is available to cluster members during operations.
ii) Operation vsx_util Upgrade
1) SSH to Primary MDS > elevate to expert mode
2) mdsenv x.x.x.x (switch to the context of VSX-Master Domain Server)
3) # vsx_util upgrade > enter x.x.x.x for Management Server IP Address , enter admin credentials when prompted!
4) Select Desired VSX Cluster Object Name in numerical list to upgrade
5) Select yes and the desired version to upgrade to and wait for operations to complete on management (all associated virtual objects will be updated in all associated Domains managing virtual objects tied to this VSX cluster)
B) VSX Upgrade Stand By Member
i) Pre-start Tasks (along with installing a Jumbo Hotfix)
1) Make sure the CPUSE build is up to date, see: sk92449
2) Upload the image to folder /var/log/tmp
3) Upload the Jumbo Hotfix Take_xx on a same/different directory.
4) Compare the MD5sum of packages
5) To import the file to CPUSE repository:
6) Ensure that the vsls status reflect all VSs in standby state before proceeding with the standby member upgrade (# vsx_util vsls)
ii) Upgrade
1) Run cphaprob state to ensure this member is standby and the peer is active
2) On the ssh session to Standby Member
Jumbo Install (optional)
iii) Verification
iv) Commence Connectivity Upgrade Script (Will sync connections for all VSs)
Turn off SecureXL
C) VSX Upgrade Active Member
i) Pre-start Tasks
1) Make sure the CPUSE build is up to date, see: sk92449
2) Upload the image to folder /var/log/tmp
3) Upload the Jumbo Hotfix Take_xx on the same directory.
4) Compare the MD5sum of packages
5) To import the file to CPUSE repository:
6) Ensure that the vsls status reflect all VSs in Active state before proceeding with the active member upgrade (# vsx_util vsls)
ii) Upgrade
1) Turn off SecureXL
Run fwaccel stat -a (to verify SecureXL is disabled)
2) Failover connections to Standby Upgraded Member – R80.20
3) On the ssh session to Primary Member
4) Jumbo install (optional)
iii) Verification
D) Recovery Plan
1) Restore the snapshots on all servers in question.
Alternatively,
2) Management Server: Run mds_restore
3) VSX Servers:
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY