CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-03
Member
 
Join Date: 2007-06-19
Posts: 43
Rep Power: 0
mc_rockz has an average reputation (10+)
Default Upgrading Nokia cluster setup which comes first Master or Member?

Hi,

I would like to know if there is a difference if i upgrade first the cluster member instead the cluster master? Bcoz im upgrading my Nokia IP530 fromm R55 to R62 in 3 weeks time.


Mc_rockz
Reply With Quote
  #2 (permalink)  
Old 2007-10-03
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 285
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Upgrading Nokia cluster setup which comes firs Master or Member?

First, is your config distributed or standalone? (is your SCS a separate server or is it on one of your gateways?)

A good place for you to start would be reading this:

CheckPoint_R65_UpgradeGuide.pdf
__________________
There's no place like 127.0.0.1
Reply With Quote
  #3 (permalink)  
Old 2007-10-03
Member
 
Join Date: 2007-06-19
Posts: 43
Rep Power: 0
mc_rockz has an average reputation (10+)
Default Re: Upgrading Nokia cluster setup which comes firs Master or Member?

Yes it is distributed. and there is a seperate smartcenter management server.
Reply With Quote
  #4 (permalink)  
Old 2007-10-04
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 285
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Upgrading Nokia cluster setup which comes firs Master or Member?

All the better! This is a very stripped down version of the procedure, but using this and reading the guide should get you where you need to be.

I always upgrade my HA (standby) node first per the zero-downtime upgrade procedure.

Disconnect SYNC cable (since STATE won't sync between different versions anyway)

Once the standby gateway is upgraded (IPSO - then CP), go into SCS and change the Version to R65 (or version du jour that you installed). Then push policy.

Policy will only push to the upgraded host because of the version change. If all is well, you should be able to set VRRP (assumption for Nokia box) to a higher priority on the upgraded node so it takes over permanently and then reboot your primary node. It has been my experience that during this process, rebooting the primary or disconnecting the interfaces are the only things that make it fail over because of the loss of state sync.

When the untouched node is rebooting, you can stop the boot and enter command line to do the IPSO upgrade on that node. Complete this node, reboot, connect sync cable, push policy and finally, change VRRP back so the designated primary takes over again.

During this last VRRP change, STATE sync should be back to normal and you should be done.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #5 (permalink)  
Old 2007-10-04
Member
 
Join Date: 2007-06-19
Posts: 43
Rep Power: 0
mc_rockz has an average reputation (10+)
Default Re: Upgrading Nokia cluster setup which comes firs Master or Member?

Hi lammbo,

tnx for your guide, im running an Active/active mode load sharing.

so im planning to upgrade individually the firewalls. and dont let each other see when one is running an old version and new version.

is this right?


regards,
Mc_rockz
Reply With Quote
  #6 (permalink)  
Old 2007-10-05
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 285
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Upgrading Nokia cluster setup which comes first Master or Member?

I can't be 100% certain as I've never built or worked with Active/Active clusters.

I can only guess that in your case, this same procedure should work.

Can anyone else provide confirmation on this?
__________________
There's no place like 127.0.0.1
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:19.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0