Cloud Firewall VMSS Solution Upgrade
This section provides instructions for upgrading an already deployed Cloud Firewall VMSS solution.
The upgrade procedure includes these steps:
-
Deploying a new version of the Cloud Firewall VMSS solution alongside the older version (a side-by-side upgrade).
-
Reconfiguring Azure resources and Check Point configuration to use this new version of the Cloud Firewall VMSS solution.
Note - This procedure includes a connection draining mechanism which allows in-flight sessions to complete gracefully before de-allocating Virtual Machines. This ensures continuous service availability and supports zero-downtime deployments during instance scale-in, maintenance, or updates.
-
Deleting the older version of the Cloud Firewall VMSS solution.
|
|
Note:
|
Terms:
-
Source - The original template and solution (with the lower version)
-
Target - The new template and solution (with the higher version)
|
Step |
Description |
||
|---|---|---|---|
|
1 |
Log in to the Azure portal. |
||
|
2 |
Open the resource group of the source Cloud Firewall VMSS solution. |
||
|
3 |
For the External Load Balancer ("frontend-lb") and the Internal Load Balancer ("backend-lb"):
|
||
|
4 |
Deploy a target Cloud Firewall VMSS solution from the Azure Marketplace. To do this:
|
||
|
5 |
Configure the CME template. For this, run:
|
||
| 6 |
Wait for provisioning to complete and for the policy to install on the new Cloud Firewall VMSS instances. |
||
|
7 |
Make sure the new Cloud Firewall Gateway instances are added to the Frontend-LB and Backend-LB backend pools and new Cloud Firewall Gateway objects appear in SmartConsole |
||
|
8 |
Drain connections from source Cloud Firewall VMSS instances:
|
||
|
9 |
Monitor traffic drain with this command:
Wait until the number of active connections decreases significantly.
|
||
|
10 |
Shut down the source Cloud Firewall VMSS and make sure that traffic flows correctly:
|
||
|
11 |
Delete the CME template of the source Cloud Firewall VMSS. For this, run:
|
||
|
12 |
Delete the corresponding VMSS resource.
|