CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-09-22
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Upgrading cluster firewall with ZERO downtime

I have a pair of SPLAT NGx R65 running on IBM x3650 with ClusterXL
Unicast Active/Active mode. These firewalls are being managed
by a CMA inside of Provider-1. Firewalls are running NGx R65 with
HFA_02 and HFA_249. Same thing on the Provider-1 side.

I just upgrade the Provider-1 NGx to HFA_30 over the weekend without
any issues so far. Now I would like to upgrade both gateways with NO
DOWNTIME.

Here is my approach:

1) perform cpstop on gw2,
2) upgrade it to HFA_30,
3) reboot gw2,
4) gw2 will come back with HFA_30,
5) perform cpstop on gw1,
6) upgrade it to HFA_30,
7) reboot gw1,
8) gw1 will come back with HFA_30

The issue here is between step 4 and step 6. During this time,
gw1 and gw2 will have different HFA version and it will cause
problem.

Has anyone upgraded a cluster firewall with ZERO DOWNTIME and give
me some advice here? Thanks.
Reply With Quote
  #2 (permalink)  
Old 2008-09-22
Senior Member
 
Join Date: 2007-07-16
Posts: 693
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Upgrading cluster firewall with ZERO downtime

Read the ClusterXL guides on this - This will do zero downtime but connections will drop during the cutover. Look up the fw fcu command - this will sync the firewall tables between devices during the upgrade (and is documented in the CXL guides).

Also, Valeri's presentation from CPUG2008 had some great tips around this, I strongly recommend you check that out.

Good luck!

R.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 09:18.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0