Minimum Downtime Upgrade of a VSX Cluster

Best Practice - Use the Central Deployment in SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on.. For more information, see the R81.20 Security Management Administration Guide > Chapter Managing Gateways > Section Central Deployment of Hotfixes and Version Upgrades.

Warning - This is the behavior when you upgrade a VSXClosed Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Security Gateways and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. ClusterClosed Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. from R80.40 / R81 / R81.10, on which CoreXLClosed Performance-enhancing technology for Security Gateways on multi-core processing platforms. Multiple Check Point Firewall instances are running in parallel on multiple CPU cores. Dynamic Balancing was not disabled explicitly, to R81.20 and then install the R81.20 Jumbo Hotfix AccumulatorClosed Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA. (see sk164155 > Limitation PMTR-114499):

  • CoreXL Dynamic Balancing will be enabled by default.

  • Any previously configured manual affinity settings for interfaces / daemons will be overridden.

As a workaround, follow this upgrade action plan to make sure CoreXL Dynamic Balancing stays disabled by default, and manual affinity settings are not overridden (if they exist):

  1. Upgrade the VSX Cluster Members to R81.20 and reboot.

  2. Connect to the command line on each VSX Cluster MemberClosed Security Gateway that is part of a cluster..

  3. Log in to the Expert mode.

  4. Back up the $FWDIR/conf/dynamic_split.conf file:

    cp -v $FWDIR/conf/dynamic_split.conf{,_BKP}

  5. Edit the $FWDIR/conf/dynamic_split.conf file:

    vi $FWDIR/conf/dynamic_split.conf

  6. In this parameter, configure the value "1" (one):

    OFF_BY_DEFAULT_ON_VSX=1

  7. Save the changes in the file and exit the editor.

  8. Install the R81.20 Jumbo HotfixClosed Software package installed on top of the current software version to fix a wrong or undesired behavior, and to add a new behavior. Accumulator on each Traditional VSX Cluster Member and reboot.

    Important - Perform the installation of a Jumbo Hotfix Accumulator as an upgrade in a Traditional VSX Cluster.

Important - Before you upgrade a VSX Cluster:

Step

Instructions

1

Back up your current configuration (see Backing Up and Restoring).

Important - Back up both the Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. and the VSX Cluster Members. Follow sk100395.

2

See the Upgrade Options and Prerequisites.

3

Upgrade the Management Server and Log Servers.

4

See Planning a Cluster Upgrade.

5

Schedule a full maintenance window to make sure you can make all the custom configurations again after the upgrade.

The procedure below describes an example VSX Cluster with three VSX Cluster Members M1, M2, and M3.

However, you can use it for clusters that consist of two or more Cluster Members.

Procedure:

For more information, see the: