CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-15
mc_rockz mc_rockz is offline
Member
 
Join Date: 2007-06-19
Posts: 41
Rep Power: 0
mc_rockz has an average reputation (10+)
Default CLUSTER FIREWALL UPGRADE NGR55 TO NGXR62

Guys need your inputs,

Current Setup:
1 - Smart Center Server NG R55 (Win2k)
1 - Pair Nokia IP530 Firewall, 512MB running Load sharing.
IPSO = 3.7.1
CP = R55
Upgrade to: CP NGX R62 using IPSO 4.1 build 28 or IPSO 4.2 build 42

My Procedure;
smartcenter:
1. Upgrade license on the smart center
2. Software upgrade on smart center to R62.
3. Test SIC Status, Push Policy.

Firewall: Individual firewall approach.
1. pullout 1st cluster firewall and do upgrade while 2nd cluster firewall is running.
2. After the upgrade of 1st cluster firewall, shutdown first the 2nd cluster firewall and insert back the 1st cluster firewall w new software installed.
3. Test SIC status bet smartcenter and 1st cluster firewall. Update the Firewall version at Cluster properties.
4. Clear the box On Gateway clusters, "Install on all members, if it fails do not install at all" before pushing the policy to the firewall this will install the policy to the 1st cluster firewall but not on 2nd cluster firewall since it is shutdown.
4. Upgrade the 2nd cluster firewall.
5. After the upgrade of the 2nd cluster firewall, shutdown again the 1st cluster firewall to perform verification and testing only on the 2nd cluster firewall.
6.Test SIC Status bet smartcenter and 2nd cluster firewall.Update the Firewall version at Cluster properties
7. Clear the box On Gateway clusters, "Install on all members, if it fails do not install at all" before pushing the policy to the firewall this will install the policy to the 2nd cluster firewall but not on 1st cluster firewall since it is shutdown.
8. If everythings ok. Power on the 1st cluster firewall while 2nd cluster is running to start the cluster setup.
9. Test the cluster setup.

Question: is there a problem i upgrade first the cluster member and not the cluster master?

thankx
Reply With Quote
  #2 (permalink)  
Old 2007-10-15
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 164
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: CLUSTER FIREWALL UPGRADE NGR55 TO NGXR62

Hi I must admit I have not done that many upgrades...but I take it your using High availability (Vrrp) and not Load sharing?

If so as long as you take one cluster member down at a time I can't see any issues. Probably best to upgrade the secondary member first depending on your current state.

Cheers

Dan

Last edited by Danielpb; 2007-10-15 at 04:02.
Reply With Quote
  #3 (permalink)  
Old 2007-10-15
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: CLUSTER FIREWALL UPGRADE NGR55 TO NGXR62

The process is fully documented in the upgrade guide. Please read it before you try the upgrade.
Reply With Quote
  #4 (permalink)  
Old 2007-10-15
mc_rockz mc_rockz is offline
Member
 
Join Date: 2007-06-19
Posts: 41
Rep Power: 0
mc_rockz has an average reputation (10+)
Default Re: CLUSTER FIREWALL UPGRADE NGR55 TO NGXR62

Quote:
Originally Posted by Danielpb View Post
Hi I must admit I have not done that many upgrades...but I take it your using High availability (Vrrp) and not Load sharing?

If so as long as you take one cluster member down at a time I can't see any issues. Probably best to upgrade the secondary member first depending on your current state.

Cheers

Dan


Hi Dan,
im using clustering Load sharing.


Marlon
Reply With Quote
  #5 (permalink)  
Old 2007-10-17
mc_rockz mc_rockz is offline
Member
 
Join Date: 2007-06-19
Posts: 41
Rep Power: 0
mc_rockz has an average reputation (10+)
Default Re: CLUSTER FIREWALL UPGRADE NGR55 TO NGXR62

Hi chillyjim,

i already read the upgrade guide. im using the individual gateway upgrade for our clusters.

is there anything i missed out. because my worries is the clustering after the upgrade. we are not using the VRRP.

Regards,
Marlon
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:50.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0