Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
fjulianom
Advisor

Doubts about upgrading MDS and SmartEvent server

Hi community,

 

I am in the way of upgrading my customer's MDS and SmartEvent server and have some doubts. The following is said in the R81.20 upgrade guide:

mds_upgrade.PNG

a) After upgrading the MDS, in point 5 when upgrading the SmartEvent server with CPUSE, don't I need to select R81.20 version in the SmartEvent object in SmartConsole first?

b) After upgrading the SmartEvent server, in point 7 when it says "Select the applicable SmartLSM Security Profile objects", what does it mean? When I click on Install Policy, I only have the options to check the Access Control or Threat Prevention Policy, and the Policy Targets, but I don't see any SmartLSM Security Profile object to select.

c) After finishing point 7, will I see all the Domain Management Servers in R81.20?

d) In point 8, how can I be sure the managament database and configuration were upgraded correctly?

e) No Log Exporter reconfiguration is needed?

 

Regards,

Julián

0 Kudos
3 Replies
AkosBakos
Advisor

Hi @fjulianom 

Here is a link of an R81.20 upgrade guide.

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Gui...

First, check these steps. It seemed you read an older or other version of the upgrade guide.

 

  • In step 6 (answer for "A":
    • Important - If your Security Management Server manages dedicated Log Servers or SmartEvent Servers, you must update the version of the corresponding objects in SmartConsole.

  • In step 9 (answer for "B")
    • Important - This step applies only if you enabled the SmartProvisioningClosed Software Blade on this Management Server

Question "C": the object will be on R81.20, it will change automatically

Question "D": Hard question. First, trust in the software. Second, check "random" rules before and after. 

Question "E": to be 100% sure, save the configuration. Last time when R81.10 -> R81.20 the upgrade kept the config.

 

Akos

 

 

----------------
\m/_(>_<)_\m/
fjulianom
Advisor

Hi Akos,

 

Thank you very much for your answer.

Your link is for "Upgrading a Security Management Server or Log Server from R80.20 and higher with CPUSE". The link I made a reference is for "Upgrading one Multi-Domain Server from R80.20 and higher with CPUSE" (Upgrading one Multi-Domain Server from R80.20 and higher with CPUSE). My customer has an MDS environment.

Then:

a) Still confused.

b) According to the guide I made a reference, which I think is the correct one because my customer has MDS environment, it says "Important - This step applies to each Domain Management Server that manages SmartLSM Security Profiles." --> how can I know if my Domain Management Servers manages SmartLSM Security Profiles?

c) OK.

d) OK.

e) OK. Then, if for some reason the Log Exporter configuration is not kept (it happens to me once when upgrading SMS from R80.30 to R81.20), do I only have to paste Log Exporter saved configuration?

 

By the way, it seems your R81.20 upgrade guide for SMS makes more sense, but is for SMS and not MDS.

 

Regards,

Julián

0 Kudos
AkosBakos
Advisor

a) based on my experiece, the version will automaticly change, because the server upgraded itself. I case of a LogServer, you need to set is manually.

b) You can check here that the SmartProvisionig is enabled or not. 

  • In the Gateways & Servers view, double-click the Multi-Domain Server object.

  • In the General Properties page, go to the Management tab, and select Provisioning.
    2024-09-09 16_03_41-Cloud Demo Server [ID_877653519]-R81.20-SmartConsole.png

e) based on my experience I had to configured manually, but from R81.10 -> R81.20 the config was kept. 

Akos

----------------
\m/_(>_<)_\m/
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events