CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-06
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default A cluster for zero downtime during an upgrade?

hi Folks,
At one of our sites we have a Sunfire V210 box running Checkpoint R62. This is the only box at this site and in order to bring it inline with our other firewalls we would like to upgrade it to R65.
As we would like as little down time as possible we are investigating using a cluster to bring up a second box (temporarily) to take the load whilst the primary box is upgraded.
Does this sound like a feasable plan? Are there any issues or "gotchas" that I need to look out for? Do the boxes need to be identical hardware wise? OS wise? Checkpoint version wise? Will we have any licence issues as this will only be a temporary cluster up for the length of the upgrade.
Any advise or help minimizing our downtime for this upgrade would be appreciated
Reply With Quote
  #2 (permalink)  
Old 2007-08-06
Senior Member
 
Join Date: 2006-12-16
Posts: 162
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: A cluster for zero downtime during an upgrade?

The os needs to be the same with R62 and I would put the same memory in both boxes. I would then add them to a New mode HA Cluster with a cross over cable between them for sync traffic. The cluster XL pdf will show you how to set this up.
Reply With Quote
  #3 (permalink)  
Old 2007-08-06
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: A cluster for zero downtime during an upgrade?

I think you might be over complicating the process.

If you can upgrade hardware, just do a fresh install and use the upgrade tools to "migrate" the config. If you can't do it like that, just get a box, install R62 and copy the config, put that one online, test, move to upgrade the original, etc.

In any of these scenarios you should have very limited downtime.

PS Edit... remember "Arp cache is your enemy" ;)
Reply With Quote
  #4 (permalink)  
Old 2007-08-07
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: A cluster for zero downtime during an upgrade?

Quote:
Originally Posted by MarioL View Post
I think you might be over complicating the process.

If you can upgrade hardware, just do a fresh install and use the upgrade tools to "migrate" the config. If you can't do it like that, just get a box, install R62 and copy the config, put that one online, test, move to upgrade the original, etc.
Once you move the new box in place (by moving cables) you've disconnected everyone connected. He wants a zero downtime upgrade and that's a necessarily complicated process.

You can do as Routerkid suggests, use the same OS / patch level etc. But there's one catch that may present a problem. For HA clusters to talk to each other there needs to be the HA software installed. During a new SPLAT install for a VPN-1 gateway, there's a question that asks "Will this gateway participate in a cluster?" If you said No to that question then you do not have that piece of the cluster HA software installed. You can install it after the fact, but I do not know if you need to reboot / cprestart for that change to take effect. If you don't have to reboot then you can do the zero downtime upgrade without any problems.

You can install this piece / see if its installed by running cpconfig. It'll be listed as "Enable cluster membership for this gateway" if its not installed or "Disable cluster membership for this gateway" if it is.

HTH
Reply With Quote
  #5 (permalink)  
Old 2007-08-08
Member
 
Join Date: 2007-06-06
Posts: 46
Rep Power: 0
GordonCopestake has an average reputation (10+)
Default Re: A cluster for zero downtime during an upgrade?

Thanks for all the replies, it's helped me greatly :)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 04:17.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0