Rolling Back a Failed Upgrade of a Security Group to R81.20 - Minimum Downtime

This section describes the steps to roll back a failed upgrade of a Security GroupClosed A logical group of Security Appliances that provides Active/Active cluster functionality. A Security Group can contain one or more Security Appliances. Security Groups work separately and independently from each other. To the production networks, a Security Group appears a single Security Gateway. Every Security Group contains: (A) Applicable Uplink ports, to which your production networks are connected; (B) Security Appliances (the Quantum Maestro Orchestrator determines the applicable Downlink ports automatically); (C) Applicable management port, to which the Check Point Management Server is connected. from R81.20 with Minimum Downtime.

This procedure supports only these downgrade paths for Security Groups:

  • from R81.20 to R81.10

  • from R81.20 to R81

  • from R81.20 to R80.30SP

  • from R81.20 to R80.20SP

Rolling Back If Only Some of the Security Group Members Were Upgraded - Minimum Downtime

Important - Use this rollback procedure if you upgraded only some (not all) Security Group Members in the Security Group.

Rolling Back the Whole Security Group - Minimum Downtime

Use this rollback procedure if you upgraded all Security Group Members in the Security Group and it is not necessary to keep the current connections.

Important - Schedule a maintenance window because this procedure interrupts all traffic that passes through the Security Group.

This rollback procedure save time because you revert all upgraded Security Group Members in a specific Security Group at the same time.

If traffic must not be interrupted, then follow the procedure Rolling Back a Failed Upgrade of a Security Group to R81.20 - Zero Downtime (MVC).