Upgrading a VSX Gateway with CPUSE

Best Practice - Use the Central Deployment in SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on.. For more information, see the R81.20 Security Management Administration Guide > Chapter Managing Gateways > Section Central Deployment of Hotfixes and Version Upgrades.

Warning - This is the behavior when you upgrade a VSX GatewayClosed Physical server that hosts VSX virtual networks, including all Virtual Devices that provide the functionality of physical network devices. It holds at least one Virtual System, which is called VS0. from R80.40 / R81 / R81.10, on which CoreXLClosed Performance-enhancing technology for Security Gateways on multi-core processing platforms. Multiple Check Point Firewall instances are running in parallel on multiple CPU cores. Dynamic Balancing was not disabled explicitly, to R81.20 and then install the R81.20 Jumbo Hotfix AccumulatorClosed Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA. (see sk164155 > Known Limitation PMTR-114499):

  • CoreXL Dynamic Balancing will be enabled by default.

  • Any previously configured manual affinity settings for interfaces / daemons will be overridden.

As a workaround, follow this upgrade action plan to make sure CoreXL Dynamic Balancing stays disabled by default, and manual affinity settings are not overridden (if they exist):

  1. Upgrade the VSXClosed Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Security Gateways and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. Gateway to R81.20 and reboot.

  2. Connect to the command line on the VSX Gateway.

  3. Log in to the Expert mode.

  4. Back up the $FWDIR/conf/dynamic_split.conf file:

    cp -v $FWDIR/conf/dynamic_split.conf{,_BKP}

  5. Edit the $FWDIR/conf/dynamic_split.conf file:

    vi $FWDIR/conf/dynamic_split.conf

  6. In this parameter, configure the value "1" (one):

    OFF_BY_DEFAULT_ON_VSX=1

  7. Save the changes in the file and exit the editor.

  8. Install the R81.20 Jumbo HotfixClosed Software package installed on top of the current software version to fix a wrong or undesired behavior, and to add a new behavior. Accumulator on the VSX Gateway and reboot.

Notes:

Important - Before you upgrade a VSX Gateway:

Step

Instructions

1

Back up your current configuration (see Backing Up and Restoring).

Important - Back up both the Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. and the VSX Gateway. Follow sk100395.

2

See the Upgrade Options and Prerequisites.

3

Upgrade the Management Server and Log Servers.

4

Upgrade the licenses on the VSX Gateway, if needed.

See Working with Licenses.

4

Schedule a full maintenance window to make sure you can make all the custom configurations again after the upgrade.

The upgrade process replaces all existing files with default files.

If you have custom configurations on the VSX Gateway, they are lost during the upgrade.

As a result, different issues can occur in the upgraded VSX Gateway.

These upgrade scenarios are available:

For more information, see the: