Cloud Firewall VMSS Solution Upgrade

This section provides instructions for upgrading an already deployed Cloud Firewall VMSS solution.

The upgrade procedure includes these steps:

  1. Deploying a new version of the Cloud Firewall VMSS solution alongside the older version (a side-by-side upgrade).

  2. Reconfiguring Azure resources and Check Point configuration to use this new version of the Cloud Firewall VMSS solution.

    Note - This procedure includes a connection draining mechanism which allows in-flight sessions to complete gracefully before de-allocating Virtual Machines. This ensures continuous service availability and supports zero-downtime deployments during instance scale-in, maintenance, or updates.

  3. Deleting the older version of the Cloud Firewall VMSS solution.

Note:

Terms:

  • Source - The original template and solution (with the lower version)

  • Target - The new template and solution (with the higher version)

Additional Information

Major upgrades:

Major upgrades happen when a new product version is installed (for example, when R81.20 is upgraded to R82.10).

During a scale-out event, the latest available image in the marketplace (the most recent build within the same major version of Cloud Firewall for Azure VMSS) is deployed on the new Virtual Machines.

Check Point recommends using the latest image for the best security and performance, but you can deploy a specific version of Azure image using this guide for reference.

For the latest versions of Cloud Firewall for Azure VMSS, see sk132192.

Minor upgrades:

Minor upgrades are performed with Jumbo HotfixClosed Software package installed on top of the current software version to fix a wrong or undesired behavior, and to add a new behavior. Accumulators - special packages which contain stability and quality fixes, and enhancements that resolve multiple issues across different products.

To install Jumbo Hotfix AccumulatorClosed Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA., see this guide.

If you have questions about the Jumbo Hotfix Accumulator deployment, see sk98028.