CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-27
charliey_2000 charliey_2000 is offline
Junior Member
 
Join Date: 2007-11-30
Posts: 24
Rep Power: 0
charliey_2000 has an average reputation (10+)
Default VRRP upgrade procedures

Can someone with real working experience outline the steps to upgrade a VRRP HA environment. Ideally I would like to have any down time to a minimum if any at all. This would include upgrading IPSO and Checkpoint from NG 55 to NGX 61.
Reply With Quote
  #2 (permalink)  
Old 2008-04-14
chrisbw chrisbw is offline
Junior Member
 
Join Date: 2007-11-13
Posts: 5
Rep Power: 0
chrisbw has an average reputation (10+)
Default Re: VRRP upgrade procedures

Hi Charliey 2000,

I did this years ago when going from NG FP3 to NGAI R55. First off start with upgradng your licenses in usercentre and download the licenses ready for use. The best way to do this is to upgrade your mgmt server first and ensure that it works with your enforcment nodes first (remember to use new version of gui too). Once you have confirmed that, then in smartdashboard remove the backup node from the cluster object. Next step woud be to upgrade your backup node's IPSO and CP to the versions you want and configured inc vrrp (again as backup).Next you will need to go into smartdashboard and remove the master node from the cluster object, amend the cluster object up to the new version of CP and then add the backup node into the cluster object and push the policy.
You now have 1 node with old CP and 1 with new CP version. Fail the firewall over to the backup node by increasing the priority on the backup node to more than the master.
Repeat process of upgrading the master node and import into cluster object and push policy again and now you have working HA cluster at new version - with only a 3 second downtime whilst you failed over.

Worked for me very well and my last company were well impressed!!

Last edited by chrisbw; 2008-04-14 at 06:52.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:27.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0