Important - Before you upgrade your Cluster members, you must upgrade your Security Management Server or Multi-Domain Server. You can also upgrade your High Availability system.
Before you upgrade a ClusterXL, consider the available upgrade options.
Upgrades that guarantee minimal connectivity loss
Note - Before you select the Connectivity Upgrade (CU) option, see sk107042 ClusterXL upgrade methods and paths for limitations.
Effort and time efficient upgrades with some loss of connectivity
An administrator can customize the Firewall, VPN, CoreXL, and SecureXL configuration on cluster members by configuring the relevant kernel parameters in special configuration files - $FWDIR/boot/modules/fwkern.conf
, $FWDIR/boot/modules/vpnkern.conf
, $PPKDIR/boot/modules/simkern.conf
, $FWDIR/conf/fwaffinity.conf
. For examples, see sk25977. During the upgrade, all customized configuration files are overwritten with the default configuration files.
If you upgrade the cluster through CLI, you can preserve the customized configuration. To do that, you must back up the configuration files before the upgrade and restore them manually immediately after upgrade, before the cluster members are rebooted. See sk42498 for details.
If you upgrade the cluster gateways through Gaia Portal, they are rebooted automatically immediately after the upgrade, and the customized configuration is lost.
Note - If configuration customizations are lost during the upgrade, different issues can occur in the upgraded cluster. Cluster members can stop detecting each other, cluster members can move to undesired state, and traffic can be dropped.
When cluster members of different versions are on the same network, cluster members of the new (upgraded) version remain in the state Ready, and cluster members of the previous version remain in state Active Attention. Cluster members in the state Ready do not process traffic and do not synchronize with other cluster members.
To prevent cluster members from being in the state "Ready":
Option |
Instructions |
---|---|
1 |
|
2 |
|
For more information, see sk42096: Cluster member is stuck in 'Ready' state.
Cluster deployments are supported on 32-bit and 64-bit kernel Gaia operating systems. Make sure that all cluster members are running the same 32-bit or the same 64-bit operating system. If the kernel versions are different among the cluster members, those that are running the 64-bit version will stay in the state Ready and will not synchronize with the other cluster members and will not process traffic sent to the cluster Virtual IP addresses.
Important - If you perform a major upgrade, first complete the upgrade of all cluster members and only then change the Gaia kernel edition to 64-bit.
Important - Before you upgrade your Cluster members, you must upgrade your Security Management Server or Multi-Domain Server. You can also upgrade your Management High Availability system.
If the appliance to upgrade was not the primary member of a cluster before, export its database before you upgrade. If it was the primary member before, you do not have to do this.
To upgrade an appliance and add it to a cluster: