Supported Upgrade Paths in R82

Note - For information about Security Management Servers and supported managed Security Gateways see:

Upgrade Paths for Security Gateways, Management Servers, Log Servers, SmartEvent Servers, Standalone Servers

Upgrade to R82 is available only from these versions for Security Gateways, Management Servers, Log Servers, SmartEvent Servers, and StandaloneClosed Configuration in which the Check Point Firewall and the Security Management Server products are installed and configured on the same server. Servers:

Current Version

Security Gateways,

Cluster Members,

Traditional VSX (1)

Management Servers,

Multi-Domain Servers,

Log Servers,

SmartEvent Servers

Standalone

Servers

R81.20,

R81.10,

R81,

R80.40

Yes

Yes

Yes

R80.30 kernel 3.10,

R80.30 kernel 2.6,

R80.20 kernel 3.10,

R80.20 kernel 2.6

Requires a 2-step

upgrade path (2)

Requires a 2-step

upgrade path (2)

Requires a 2-step

upgrade path (2)

R80.20.M2,

R80.20.M1

Not applicable

Requires a 2-step

upgrade path (2)

Not applicable

R80.10

Requires a 2-step

upgrade path (2)(4)

Requires a 2-step

upgrade path (2)

Requires a 2-step

upgrade path (2)(4)

R80

Not applicable

Requires a 2-step

upgrade path (2)

Not applicable

R77.30

Requires a 2-step

upgrade path (2)(3)(4)

Requires a 2-step

upgrade path (2)(3)

Requires a 2-step

upgrade path (2)(3)(4)

Notes:

  1. Starting from R81.10, VSLS is the only supported mode for new installations of VSX Clusters (does not apply to the VSNext mode).

    Upgrade of a VSXClosed Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Firewalls and other network devices. These Virtual Devices provide the same functionality as their physical counterparts. ClusterClosed Two or more Check Point Firewalls that work together in a redundant configuration - High Availability, or Load Sharing. in the High Availability mode from R81.10 and earlier versions to R82 is supported.

    To convert the upgraded VSX Cluster to VSLS, use the "vsx_util convert_cluster" command.

  2. The required 2-step upgrade path is:

    1. Upgrade to one of these versions:

    2. Upgrade to R82.

  3. To upgrade an R77.30 environment that implements Carrier Security (former Firewall-1 GX), you must follow sk169415.

  4. Before you start the upgrade on R77.30 or R80.10, you must make sure the GaiaClosed Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. OS edition is 64-bit:

    1. Get the current Gaia OS edition with this Gaia ClishClosed The name of the default command line shell in Check Point Gaia operating system. This is a restricted shell (role-based administration controls the number of commands available in the shell). command:

      show version all

    2. If the Gaia OS edition is "32-bit", run these Gaia Clish commands:

      set edition 64-bit

      save config

      reboot

Upgrade Paths for Scalable Platforms

Upgrade to R82 on Scalable Platforms (Maestro and Scalable ChassisClosed The container that contains the all the components of a 60000 / 40000 Appliance. Synonym: Chassis.) is available only from these versions:

Current Version

for Scalable Platforms

Mode

Upgrade Path

R81.20,

R81.10

Security Gateway,

Traditional VSX

Requires a 3-step

upgrade path (1)

R81,

R80.30SP,

R80.20SP

Security Gateway,

Traditional VSX

Requires a 4-step

upgrade path (2)

Notes:

  1. To upgrade a Security GroupClosed A logical group of Security Appliances (in Maestro) / Security Gateway Modules (on Scalable Chassis) that provides Active/Active cluster functionality. A Security Group can contain one or more Security Appliances / Security Gateway Modules. Security Groups work separately and independently from each other. To the production networks, a Security Group appears a single Check Point Firewall. In Maestro, each Security Group contains: (A) Applicable Uplink ports, to which your production networks are connected; (B) Security Appliances (the Maestro Orchestrator determines the applicable Downlink ports automatically); (C) Applicable management port, to which the Check Point Management Server is connected. from R81.10, R81.20 to R82, you must follow this 3-step upgrade path (for the required packages, see sk181127 > section"Downloads and Installation" > section "Quantum Maestro and Scalable Chassis (Scalable Platforms)"):

    1. Install the required Jumbo Hotfix AccumulatorClosed Collection of hotfixes combined into a single package. Acronyms: JHA, JHF, JHFA. on the current version (R81.20, R81.10).

    2. Install the required CPUSEClosed Check Point Upgrade Service Engine for Gaia Operating System. With CPUSE, you can automatically update Check Point products for the Gaia OS, and the Gaia OS itself. Deployment Agent on the current version.

    3. Upgrade to R82.

  2. To upgrade a Security Group from R80.20SP, R80.30SP, R81 to R82, you must follow this 3-step upgrade path (for the required packages, see sk181127 > section"Downloads and Installation" > section "Quantum Maestro and Scalable Chassis (Scalable Platforms)"):

    1. Upgrade to one of these versions:

    2. Install the required Jumbo HotfixClosed Software package installed on top of the current software version to fix a wrong or undesired behavior, and to add a new behavior. Accumulator on R81.10 / R81.20 for Scalable Platforms.

    3. Install the required CPUSE Deployment Agent on R81.10 / R81.20 for Scalable Platforms.

    4. Upgrade to R82.

  3. In a Maestro environment, you must follow this upgrade order:

    1. Upgrade the Management ServerClosed Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. that manages the Maestro Security Group.

    2. Upgrade the Maestro OrchestratorsClosed A scalable Network Security System that connects multiple Check Point Security Appliances into a unified system. Synonyms: Orchestrator, Maestro Hyperscale Orchestrator. Acronym: MHO. on each Maestro Site.

      See Maestro Orchestrator and Security Group Versions.

    3. Upgrade the Maestro Security Groups on each Maestro Site.

  4. To upgrade a Security Group, it must contain a minimum of two configured and working Security Group MembersClosed Member of a Security Group in ElasticXL Cluster, Maestro, and Scalable Chassis. Acronym: SGM..