Automatic Hotfix Deployment

Automatic HotfixClosed Software package installed on top of the current software version to fix a wrong or undesired behavior, and to add a new behavior. Deployment for CloudGuard autoscaling solutions automatically deploys a preconfigured CPUSEClosed Check Point Upgrade Service Engine for Gaia Operating System. With CPUSE, you can automatically update Check Point products for the Gaia OS, and the Gaia OS itself. Hotfix or Jumbo Hotfix AccumulatorClosed Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA. (JHF) when an instance scales out.

This feature allows you to do all the necessary configuration on the Management or Multi-Domain Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server.. You do not have to access each Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. instance manually.

Prerequisites:

Configuring the Automatic Hotfix Deployment

Disabling Automatic Hotfix Deployment

You can disable Automatic Hotfix Deployment for scale out instances you plan to connect in the future.

Viewing Configuration Parameters

Viewing Package Deployment Status

Limitations

  • The package is only installed on new instances.

    To install the package on all existing instances, do these steps:

    1. Remove instances that do not contain the package.

    2. Scale out new instances.

    3. Wait for the provisioning to finish.

  • Supported cloud platforms: Azure, AWSClosed Amazon® Web Services. Public cloud platform that offers global compute, storage, database, application and other cloud services., GCPClosed Google® Cloud Platform is a suite of products and services that includes hosting, cloud computing, database services and more..

  • Central Deployment Tool:

    • Because Automatic Hotfix Deployment relies on CDT, see CDT Limitations in sk111158.

    • CDT version 1.9 is not compatible with Auto-HF in CME.

    • When another CDT operation is in progress, you cannot use the Display Hotfix deployment status option.

      If you do, it shows an error message.

      The solution is to wait until the CDT operation is finished, and then try the Display Hotfix deployment status again.

  • When scaling out several instances, the package is not installed in parallel.

  • Enabling Automatic Hotfix Deployment significantly increase the time until a scaled-out instance finishes provisioning.

    This is due to the time it takes for a Hotfix or Jumbo Hotfix Accumulator to be installed.

  • Only Hotfixes and Jumbo Hotfixes are supported.

    Minor and Major upgrades are not supported.

  • Automatic HF deployment does not support name-prefix.