Professional Documents
Culture Documents
Scenario: Two Nokia boxes (IP 260) with IPSO 4.1 and Check Point version NGX R61 in a VRRP cluster configuration.
SmartConsole R60
First: Install SmartConsole R62 Then: Upgrade SmartCenter to R62 Upgrade the Standby Gateway to R62 But which one is the Standby Gateway?
Command to identify the standby gateway: iclid> show vrrp or echo show vrrp | iclid
What to do prior to upgrading. Set the Cluster Control Protocol into broadcast mode:
cphaconf set_ccp broadcast
Should you have to upgrade IPSO first, the command therefor is: newimage i k
-i: interactive mode -k: keep previously installed packages activated!
SmartConsole R62
Gateway B: IPSO 4.1/ NGX R60 (Standby) Command to Upgrade Check Point: [gatewayB]# newpkg
! Dont use the i switch here, unless you want to use it explicitly!
At this stage, GateA is still the active node. You have to transfer the State Table to GateB (to be shown in the next slide) You have to disable the cluster service of GateA GateB shall take over almost all connections! If not, you dont have a second chance!
Before disabling cluster service from GateA, wait until the following message is being displayed:
[GateB]# Full sync connection finished successfully
After that, GateB should have taken over almost all connections.
Now, you can upgrade GateA with the commands already used. GateB will process all requests. After upgrading, reboot GateA and install the last policy on both cluster members!
Important information for you: There are some connections which will be disrupted anyway:
User Authentication Connections Connections with Resources (SMTP, URI, FTP) Client Authentication (partially automatic and fully automatic for HTTP, FTP, Telnet, rlogin)
But what if.? What do you need in the case of failing upgrade procedure?
If you would like to escape from your customers site
DISCLAIMER: I am not responsible for sponsoring you a race car should your attempt to upgrade the cluster failing!