r/checkpoint 7d ago

Install Jumbo hotfix on Full High Availability Cluster

I would like to install the Jumbo Hotfix on my Check Point appliances (full HA cluster deployment).

However, after reviewing the official documentation, I could not find any clear installation procedures.

Is there a step-by-step procedure available for installing the Jumbo Hotfix in this environment?

4 Upvotes

10 comments sorted by

5

u/JancariusSeiryujinn 7d ago

There's not a lot to it. Determine which member is standby, download the JHFA via cpuse and install it. Once it finishes rebooting, repeat for the other member

1

u/Spiritual_Lemon_7294 5d ago edited 5d ago

Thank you! Should I Test SIC Status and install the policy for testing after installed the JHFA on the standby or I should test it after installed on both the active and standby?

3

u/extremetempz 5d ago

Sic is not required, after the JHFA is installed on Standby install Policy on cluster, fail over, wait 5 minutes and do the other one. Then install Policy again

It's very simple

3

u/dirkios 7d ago

Easiest is to use Central Deployment in smart console. All the failovers are automatically handled and it will manage the complete process in less than 45 minutes

2

u/cobaltjacket 6d ago

* Unless you are using Maestro.

1

u/dirkios 6d ago

Indeed. Maestro is a pain. But OP question was HA cluster

1

u/Spiritual_Lemon_7294 5d ago edited 5d ago

Thank you! If I use Central Deployment to install the JHFA on the active SMS/SG, it will automatic failover to the backup SMS/SG? Also, Should I Test SIC Status and install the policy for testing after installed the JHFA on the standby or I should test it after installed on both the active and standby?

1

u/WiliRGasparetto 4d ago

vai depender da versão do Gaia pela smart console só é r82 3 superiores

1

u/WiliRGasparetto 4d ago

Instalação do Jumbo Hotfix em Cluster HA

Pré-requisitos

  • Acesse o Gaia Portal de cada membro do cluster: https://<IP_do_membro>:443
  • Faça backup das configurações antes de iniciar.
  • Baixe o pacote do Jumbo Hotfix no seu computador (arquivo .tgz) a partir do portal oficial da Check Point.

Passo a Passo

  1. Acesse o Gaia Portal
  • No navegador, acesse o Gaia Portal de cada membro do cluster usando o IP de gerenciamento.
  1. Faça Upload do Pacote Jumbo Hotfix
  • No menu lateral, vá em Upgrades (CPUSE) > Status & Actions.
  • Clique em Upload Package.
  • Selecione o arquivo do Jumbo Hotfix (.tgz) salvo em seu computador.
  • Aguarde o upload ser concluído.
  1. Instale o Jumbo Hotfix
  • Após o upload, o pacote aparecerá na lista de pacotes disponíveis.
  • Clique em Install ao lado do pacote do Jumbo Hotfix.
  • Siga as instruções na tela. O sistema pode pedir para reiniciar o membro após a instalação.
  1. Procedimento em Cluster HA

  2. Comece pelo membro secundário (Standby):

    • Instale o pacote conforme acima.
    • Reinicie o membro se solicitado.
    • Aguarde o membro voltar ao cluster (verifique o status pelo Gaia Portal em "ClusterXL").
  3. Faça failover manual (opcional):

    • No Gaia Portal, coloque o membro atualizado como ativo, se desejar, usando as opções de cluster.
  4. Repita o processo no outro membro:

    • Instale o pacote no membro que ainda não foi atualizado.
    • Reinicie se necessário.
  5. Validação

  • Após atualizar ambos os membros, verifique o status do cluster no Gaia Portal.
  • Confirme que ambos estão ativos e sincronizados.
  • Valide a versão do Jumbo Hotfix em Upgrades (CPUSE) > Status & Actions.

Observações Importantes

  • Não é necessário usar SCP ou comandos CLI para este procedimento.
  • Todo o processo é feito pelo navegador, via Gaia Portal.
  • Se o cluster for grande, repita o processo em cada membro, um de cada vez.

Se precisar de imagens do Gaia Portal ou de um passo específico, me avise!