Cloud Firewall VMSS Solution Upgrade
This section provides instructions for upgrading an already deployed Cloud Firewall VMSS solution.
The upgrade procedure includes these steps:
-
Deploying a new version of the Cloud Firewall VMSS solution alongside the older version (a side-by-side upgrade).
-
Reconfiguring Azure resources and Check Point configuration to use this new version of the Cloud Firewall VMSS solution.
Note - This procedure includes a connection draining mechanism which allows in-flight sessions to complete gracefully before de-allocating Virtual Machines. This ensures continuous service availability and supports zero-downtime deployments during instance scale-in, maintenance, or updates.
-
Deleting the older version of the Cloud Firewall VMSS solution.
|
|
Note:
|
Terms:
-
Source - The original template and solution (with the lower version)
-
Target - The new template and solution (with the higher version)
|
Step |
Description |
||||
|---|---|---|---|---|---|
|
1 |
Log in to the Azure portal. |
||||
|
2 |
Open the resource group of the source Cloud Firewall VMSS solution. |
||||
|
3 |
For the External Load Balancer ("frontend-lb") and the Internal Load Balancer ("backend-lb"):
|
||||
|
4 |
Deploy a target Cloud Firewall VMSS solution from the Azure Marketplace. To do this:
|
||||
|
5 |
Configure the CME template. For this, use SmartConsole or CME API.
|
||||
| 6 |
Wait for provisioning to complete and for the policy to install on the new Cloud Firewall VMSS instances. |
||||
|
7 |
Make sure the new Cloud Firewall Gateway |
||||
|
8 |
Drain connections from source Cloud Firewall VMSS instances:
|
||||
|
9 |
Monitor traffic drain with this command:
Wait until the number of active connections decreases significantly.
|
||||
|
10 |
Shut down the source Cloud Firewall VMSS and make sure that traffic flows correctly:
|
||||
|
11 |
Delete the CME template of the source Cloud Firewall VMSS. For this, use SmartConsole or CME API.
|
||||
|
12 |
Delete the corresponding VMSS resource.
|
Additional Information
Major upgrades:
Major upgrades happen when a new product version is installed (for example, when R81.20 is upgraded to R82.10).
During a scale-out event, the latest available image in the marketplace (the most recent build within the same major version of Cloud Firewall for Azure VMSS) is deployed on the new Virtual Machines.
Check Point recommends using the latest image for the best security and performance, but you can deploy a specific version of Azure image using this guide for reference.
For the latest versions of Cloud Firewall for Azure VMSS, see sk132192.
Minor upgrades:
Minor upgrades are performed with Jumbo Hotfix
Software package installed on top of the current software version to fix a wrong or undesired behavior, and to add a new behavior. Accumulators - special packages which contain stability and quality fixes, and enhancements that resolve multiple issues across different products.
To install Jumbo Hotfix Accumulator
Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA., see this guide.
If you have questions about the Jumbo Hotfix Accumulator deployment, see sk98028.