CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 3 of 3

Thread: R77.30 to R80.20 migration.

  1. #1
    Join Date
    2019-05-17
    Posts
    4
    Rep Power
    0

    Post R77.30 to R80.20 migration.

    Hello guys,

    I ma planning to do migration of existing checkpoint version R77.30 to R80.20 so walked through the number of articles and videos but there are lots of things but simply i want to know the steps and recommended options for this upgrade.

    so here is the infra 2 Smart center in HA R77.30 and VSX cluster for the GWs. R77.30

    so
    1- if i want to plan Smart center first then shall plan upgrade with CPUSE on existing machine or clean installation on new VM/Hardware ? Please suggest
    2- Clean install on secondary smart center and connect with primary.
    3- when upgrading the VSX gateways the best to upgrade .


    looking for your kind response.

  2. #2
    Join Date
    2019-06-13
    Posts
    4
    Rep Power
    0

    Default Re: R77.30 to R80.20 migration.

    I am in the same boat as you...

    Waiting for response on the thread

  3. #3
    Join Date
    2007-03-30
    Location
    DFW, TX
    Posts
    422
    Rep Power
    17

    Default Re: R77.30 to R80.20 migration.

    I am told with R80.20, a clean install is preferred. Here's the general process I would use:
    1. Export the configuration from the management and import it into a VM for testing purposes. Do you get any errors?
    2. When ready to make the upgrade for real, freeze changes to the management.
    3. Export a new copy of the configuration.
    4. Import into a VM to make sure the file is good.
    5. Perform a clean install on whatever platform you want. VM, physical box, wherever you want your primary management to end up.
    6. Import the configuration onto the "new" management server.
    7. Make sure you can push policy to the firewalls. It should be safe to unfreeze management changes at this point.
    8. Do a clean install on the secondary management.
    9. Establish communications between the primary and secondary managements, and synchronize them.

    Fortunately, VSX means the firewall upgrades will be extremely easy after the management upgrade is done. Again, a general process:
    1. Build config_system files for each firewall. These files contain answers for all the first-time wizard questions.
    2. Record any local configuration from the contexts. The only local items I can think of are proxy ARP (in the $FWDIR/local.arp for each context) and dynamic routing config.
    3. Do a clean install on your first member. Use config_system to configure it according to the file created earlier.
    4. Use 'vsx_util reconfigure' on the SmartCenter to establish SIC and provision the first member.
    5. Apply any local config for the first member.
    6. Do a clean install on your second member. Use config_system to configure it according to the file created earlier.
    7. Use 'vsx_util reconfigure' on the SmartCenter to establish SIC and provision the second member.
    8. Apply any local config for the second member.

    Depending on the traffic outage you can tolerate, it may actually be that simple. You can also use some more involved options like the Connectivity Upgrade (described in sk107042) if you need a shorter outage window. That mostly affects things between the first 'vsx_util reconfigure' and the clean install on the second member.

Similar Threads

  1. Migration from R75.40 to R77.30
    By sysroute in forum Security Management Server (Formerly SmartCenter Server ((Formerly Management Server))
    Replies: 5
    Last Post: 2017-03-21, 08:09
  2. MDS migration R71.10 to R76
    By kanna_vk in forum Provider-1 (Multi-Domain Management)
    Replies: 1
    Last Post: 2013-08-14, 21:50
  3. UTM-1 Migration
    By sleepytom in forum Check Point UTM-1 Appliances
    Replies: 0
    Last Post: 2011-11-08, 05:31
  4. P-1 to CMA migration.
    By rss8309 in forum Provider-1 (Multi-Domain Management)
    Replies: 2
    Last Post: 2009-08-28, 14:22
  5. Migration R55 to R65
    By elo93 in forum Installing And Upgrading
    Replies: 3
    Last Post: 2009-03-14, 20:07

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •