{"id":93433,"date":"2020-09-07T07:42:37","date_gmt":"2020-09-07T05:42:37","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/proczedura-obnovleniya-check-point-s-r80-20-r80-30-do-r80-40"},"modified":"2020-09-07T07:42:37","modified_gmt":"2020-09-07T05:42:37","slug":"proczedura-obnovleniya-check-point-s-r80-20-r80-30-do-r80-40","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/proczedura-obnovleniya-check-point-s-r80-20-r80-30-do-r80-40","title":{"rendered":"Check Point upgrade procedure from R80.20\/R80.30 to R80.40","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/7acecf42ffba8732d9006924b54aa490.png\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>Bol<em>e<\/em>Two years ago, we wrote about how every Check Point administrator inevitably faces the question of upgrading to a new version. In this article, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/353470\/\"><u>article<\/u><\/a><\/noindex> we discussed the upgrade from version R77.30 to R80.10. By the way, in January 2020, R77.30 became the certified version of FSTEC. However, a lot has changed in Check Point over the past 2 years. The article \"<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/467723\/\"><u>Check Point Gaia R80.40. What\u2019s new?<\/u><\/a><\/noindex>\" covers all the new features, of which there are many. In this article, the upgrade procedure will be described in as much detail as possible.&nbsp;<\/p>\n<p>As is known, there are 2 deployment options for Check Point: Standalone and Distributed, that is, with and without a dedicated management server. The Distributed option is highly recommended for several reasons:<\/p>\n<ul>\n<li>\n<p>minimized load on the gateway resources;<\/p>\n<\/li>\n<li>\n<p>no need to plan a maintenance window to perform work on the management server;<\/p>\n<\/li>\n<li>\n<p>proper functioning of SmartEvent, as it is unlikely to work in the Standalone option;<\/p>\n<\/li>\n<li>\n<p>it is highly recommended to build a cluster of gateways in a Distributed configuration.<\/p>\n<\/li>\n<\/ul>\n<p>Considering all the advantages of the Distributed configuration, we will examine the upgrade of the management server and the security gateway separately.<\/p>\n<h3>Upgrading the Security Management Server (SMS)<\/h3>\n<p>There are 2 methods to upgrade SMS:<\/p>\n<ul>\n<li>\n<p>using CPUSE (via Gaia Portal)<\/p>\n<\/li>\n<li>\n<p>using Migration Tools (requires a clean installation \u2014 <strong>fresh install<\/strong>)<\/p>\n<\/li>\n<\/ul>\n<p>Upgrading using CPUSE is not recommended by colleagues at Check Point, as it will not update the file system version and kernel. However, this method does not require policy migration and is much faster and simpler than the second method.<\/p>\n<p>A clean installation and migration of policies using Migration Tools \u2014 is the recommended method. In addition to the new file system and OS kernel, it is often the case that the SMS database becomes 'cluttered', and a clean installation is an excellent option to enhance server performance.<\/p>\n<p>1) The first step in any upgrade is to create backups and snapshots. If you have a physical management server, the backup should be made from the Gaia Portal web interface. Go to the tab <em>Maintenance &gt; System Backup &gt; Backup<\/em>. You will then specify the backup storage location. This can be an SCP, FTP, TFTP server, or locally on the device; however, you will have to later transfer this backup to the server or computer.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/d365a22846bdc716bcf0adf90cd5c851.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 1. Creating a backup in Gaia Portal<\/p>\n<p>2) Next, a snapshot should be taken in the tab <em>Maintenance \u2192 Snapshot Management \u2192 New. <\/em>The difference between backups and snapshots is that snapshots contain more information, including all installed hotfixes. Nevertheless, it's best to do both.<\/p>\n<p>If your management server is installed as a virtual machine, it is recommended to back up the virtual machine using the hypervisor's built-in tools. It's simply faster and more reliable.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/c2bd3da4f9eddcf8524f7006f8e8e37d.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 2. Creating a snapshot in Gaia Portal<\/p>\n<p>3) Save the device configuration from Gaia Portal. You can screenshot all the settings tabs available in Gaia Portal, or enter the command from Clish <strong>save configuration<\/strong>. Then, retrieve the file to your PC using WinSCP or another client.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/bcdf28ffb804edd3ece43f3cd0b11ee6.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 3. Saving the configuration to a text file)<\/p>\n<p><strong>Note<\/strong><em><strong>: <\/strong><\/em>if WinSCP does not allow you to connect, change the user's shell to \/bin\/bash either in the Users tab of the web interface or by entering the command<em><strong> <\/strong><\/em><strong>chsh \u2013s \/bin\/bash<\/strong>.<\/p>\n<p>Updating with CPUSE<\/p>\n<p>4) The first three steps are mandatory for any update option. If you decide to take the simpler update path, go to the web interface and navigate to the tab <em>Upgrades (CPUSE) &gt; Status and Actions &gt; Major Versions &gt; Check Point R80.40 Gaia Fresh Install and Upgrade. <\/em>Right-click on this update and select <em>Verifier. <\/em>The verification process will run for a few minutes, after which you will see a message indicating that the device can be updated. If you see errors, they need to be resolved.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/a02b7b395d395c6eb36e90f8824e516b.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 4. Updating via CPUSE<\/p>\n<p>5) Update to the latest version of CDT (Central Deployment Tool) \u2014 a utility that runs on the management server and allows for updates, update packages, backup management, snapshots, scripts, and much more. An outdated version of CDT can cause issues during updates. You can download CDT from <noindex><a rel=\"nofollow\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal\/role\/supportcenterUser\/page\/default.psml\/media-type\/html?action=portlets.DCFileAction&amp;eventSubmit_doGetdcdetails=&amp;fileid=104450\"><u>this link<\/u><\/a><\/noindex>.<\/p>\n<p>6) After placing the downloaded archive on SMS in any directory via WinSCP, connect to SMS via SSH and enter expert mode. Reminder: the WinSCP user must have shell <strong>\/bin\/bash<\/strong>!<\/p>\n<p>7) Enter the commands:<strong>&nbsp;<\/strong><\/p>\n<p><em>cd \/somepathtoCDT\/<\/em><\/p>\n<p><em>tar -zxvf .tgz<\/em><\/p>\n<p><em>rpm -Uhv \u2014force CPcdt-00-00.i386.rpm<\/em><\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/6c1f64e57f24d9fb6d117fa3a7a09461.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 5. Installing Central Deployment Tool (CDT)<\/p>\n<p>8) The next step is installing the R80.40 image. Right-click on the update <em>Download, <\/em>then <em>Install.<\/em> Please note that the update takes about 20-30 minutes, and the management server will be unavailable for some time. Therefore, it makes sense to coordinate a maintenance window.<\/p>\n<p>9) All licenses and security policies are maintained, so you should download the new <noindex><a rel=\"nofollow\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?action=portlets.DCFileAction&amp;eventSubmit_doGetdcdetails=&amp;fileid=108335\"><u>SmartConsole R80.40<\/u><\/a><\/noindex>.<\/p>\n<p>10) Connect to the new SmartConsole SMS and set the security policies. The button <em>Install Policy<\/em> is in the upper left corner.<\/p>\n<p>11) Your SMS has been updated, and you should now install the latest hotfix. In the <em>Upgrades (CPUSE) &gt; Status and Actions &gt; Hotfixes <\/em>right-click <em>Verifier<\/em>, then <em>Install Update<\/em>. The device will reboot automatically after the update is installed.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/bced9cc3fce6f65835ffdff00a1ccdfb.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 6. Installing the latest hotfix via CPUSE<\/p>\n<p>Updating using Migration Tools<\/p>\n<p>4) To begin, you should also update to the latest version of CDT \u2014 items 5, 6, 7 from the section <em>\u201cUpdating using CPUSE.\u201d<\/em><\/p>\n<p>5) Install the Migration Tools package required for migrating policies from the management server. The <noindex><a rel=\"nofollow\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk135172\"><u>this link<\/u><\/a><\/noindex> Migration Tools can be found for versions: R80.20, R80.20 M1, R80.20 M2, R80.30, R80.40. You should download Migration Tools for the version <strong>you want to upgrade to<\/strong>, not the one you currently have! In our case, this is R80.40.<\/p>\n<p>6) Next, in the SMS web interface, go to the tab <em>Upgrades (CPUSE) &gt; Status and Actions &gt; Import Package &gt; Browse &gt; Select the downloaded file &gt; Import<\/em>.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/b1b1164018a9750bfb952b1b650ea341.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 7. Importing Migration Tools<\/p>\n<p>7) From expert mode on the SMS, check that the Migration Tools package is installed using the command (the output of the command should match the number in the name of the Migration Tools archive):<\/p>\n<p><em><strong>cpprod_util CPPROD_GetValue CPupgrade-tools-R80.40 BuildNumber 1<\/strong><\/em><\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/1a0e032ec53ee5a05f979637217a9562.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 8. Checking the installation of Migration Tools<\/p>\n<p>8) Navigate to the $FWDIR\/scripts folder on the management server:<\/p>\n<p><em><strong>cd $FWDIR\/scripts<\/strong><\/em><\/p>\n<p>9) Run the pre-upgrade verifier (verification script) using the command (if there are errors, fix them before proceeding):<\/p>\n<p><em><strong>.\/migrate_server verify -v R80.40<\/strong><\/em><\/p>\n<p><strong>Note<\/strong>: if you see the error <em>\u201cFailed to retrieve Upgrade Tools package\u201d<\/em>, but you confirmed that the archive was successfully imported (see item 4), use the command:<\/p>\n<p><em><strong>.\/migrate_server verify -v R80.40 -skip_upgrade_tools_check<\/strong><\/em><\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/a6b29e5fb7b3c183ec3c9fc92c32db6c.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 9. Running the verification script<\/p>\n<p>10) Export the security policies using the command:<\/p>\n<p><em><strong>.\/migrate_server export -v R80.40 \/\/.tgz<\/strong><\/em><\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/1bd0c4604bdcc5640280f1cbed4837b1.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 10. Exporting security policies<\/p>\n<p><strong>Note<\/strong>: if you see the error <em>\u201cFailed to retrieve Upgrade Tools package\u201d<\/em>, but you confirmed that the archive was successfully imported (item 7), use the command:<\/p>\n<p><em><strong>.\/migrate_server export -skip_upgrade_tools_check -v R80.40 \/\/.tgz<\/strong><\/em><\/p>\n<p>11) Calculate the MD5 hash checksum and save the output of the command:<\/p>\n<p><em><strong>md5sum \/\/.tgz<\/strong><\/em><\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/f0c2e03613eba64d1047011a135db217.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 11. Calculating the MD5 hash checksum<\/p>\n<p>12) Use WinSCP to transfer this file to your computer.<\/p>\n<p>13) Enter the command <strong>df -h <\/strong>and keep the percentage ratio of directories based on the space occupied.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/09d8134e5f5813530b389d36a4f2001c.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 12. Percentage ratio of directories on SMS<\/p>\n<p>14.1)  <strong>In case you have a real SMS<\/strong><\/p>\n<p>14.1.1) Using <noindex><a rel=\"nofollow\" href=\"https:\/\/yadi.sk\/d\/DSv8P5CVxipSrw\"><u>Isomorphic Tool<\/u><\/a><\/noindex> a bootable USB flash drive with an image is created <noindex><a rel=\"nofollow\" href=\"https:\/\/yadi.sk\/d\/f2B0zsgTLJi4Yw\"><u>Gaia R80.40<\/u><\/a><\/noindex>.&nbsp;<\/p>\n<p>14.1.2) I recommend preparing at least 2 bootable flash drives, since sometimes the flash drive may not be readable.&nbsp;<\/p>\n<p>14.1.3) As an administrator on the computer, run<em> ISOmorphic.exe. <\/em>In point 1, select the downloaded Gaia R80.40 image, and in point 4, select the flash drive. Points 2 and 3 should not be changed <strong>at all.<\/strong>!<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/8718bfa85d3a4f0d3aa371b3adcdc064.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 13. Creating a bootable flash drive<\/p>\n<p>14.1.4) Select the option <em>\u201cInstall automatically without confirmation\u201d <\/em>and it is important to specify your management server model. For SMS, you should select line 3 or 4.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/56f0106357b3d39edd8b7bafa5bb1f80.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 14. Selecting the device model for creating a bootable flash drive<\/p>\n<p>14.1.5) Next, you turn off the appliance, insert the flash drive into the USB port, connect via a console cable through the COM port to the device, and power on the SMS. The installation process occurs automatically. The default IP address \u2014 <strong>192.168.1.1\/24<\/strong>, and the login data is <strong>admin \/ admin<\/strong>.<\/p>\n<p>14.1.6) The next step is to connect to the web interface on Gaia Portal (default address <noindex><a rel=\"nofollow\" href=\"https:\/\/192.168.1.1\"><strong><u>https:\/\/192.168.1.1<\/u><\/strong><\/a><\/noindex>), where you will go through the device initialization. During initialization, you mainly click <em>Next, <\/em>as almost all settings can be changed in the future. However, you may change the IP address, DNS settings, and hostname right away.<\/p>\n<p>14.2) <strong>In case you have a virtual SMS<\/strong><\/p>\n<p>14.2.1) Under no circumstances should you delete the old SMS, create a new virtual machine with the same resources (CPU, RAM, HDD) with the same IP address. By the way, you can add RAM and HDD since R80.40 is somewhat more demanding. To avoid IP address conflicts, turn off the old SMS and start the installation of the new one.<\/p>\n<p>14.2.2) During the installation of Gaia, configure the current IP address and allocate appropriate space for the directory. <strong>\/root<\/strong> The percentage ratio of directories should approximately <strong>be preserved,<\/strong>use the output <strong>df -h<\/strong>.<\/p>\n<p>15) At the stage of selecting the installation type <em>\u201cInstallation Type\u201d <\/em>choose the first option, as you are most likely not using MDS (Multi-Domain Server). If you are using MDS, it means you managed many domains from different entities of SMS at the same time. In this case, you should choose the second option.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/4f04ee96ab5b888f5187de677255af90.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 15. Selecting the installation type of Gaia<\/p>\n<p>16) The most important point that cannot be corrected without reinstallation \u2014 is entity selection. You must choose <em><strong>Security Management<\/strong><\/em> and click <em>Next. <\/em>Next, leave everything at default.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/8a9f13889696bf7c95d50a6580c62722.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 16. Selecting the entity type during Gaia installation<\/p>\n<p>17) Once the device reboots, connect to the web interface at <noindex><a rel=\"nofollow\" href=\"https:\/\/192.168.1.1\"><u>https:\/\/192.168.1.1<\/u><\/a><\/noindex> or another IP address if you changed it.<\/p>\n<p>18)&nbsp;Transfer the settings from the screenshots to all tabs in Gaia Portal where configurations were made or execute the command from clish <strong>load configuration .txt<\/strong>. This config file should be uploaded to the SMS in advance.<\/p>\n<p><strong>Note<\/strong><em><strong>: <\/strong><\/em>Since the OS is new, WinSCP will not allow admin access; change the user's shell to \/bin\/bash either in the Users tab in the web interface or by entering the command<em><strong> <\/strong><\/em><strong>chsh \u2013s \/bin\/bash <\/strong>or create a new user.<\/p>\n<p>19) Upload the file with exported policies from the old management server into any directory. Then enter the console in expert mode and verify that the MD5 hash matches the previous one. If not, you need to export again:<\/p>\n<p><em><strong>md5sum<\/strong> <strong>\/&lt;Full Path&gt;\/&lt;Name of Exported File&gt;.tgz<\/strong><\/em><\/p>\n<p>20) Repeat step 6 and install Upgrade Tools on the new SMS in Gaia Portal under the <em>Upgrades (CPUSE) &gt; Status and Actions.<\/em><\/p>\n<p>21) Enter the command in expert mode:<\/p>\n<p><em><strong>.\/migrate_server import -v R80.40 -skip_upgrade_tools_check \/\/.tgz<\/strong><\/em><\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/9eab781ee0bd7f589859ff7360da35e7.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 17. Importing the security policy to the new SMS<\/p>\n<p>22) Start the services with the command <strong>cpstart<\/strong>.<\/p>\n<p>23) Download the new <noindex><a rel=\"nofollow\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?action=portlets.DCFileAction&amp;eventSubmit_doGetdcdetails=&amp;fileid=108335\"><u>SmartConsole R80.40<\/u><\/a><\/noindex> and connect to the management server. Go to <em>Menu &gt; Manage Licenses and Packages (SmartUpdate)<\/em> and check that your license is still valid. <\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/ab3a9b5ea4a778f7430861ac99de2ead.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 18. Checking installed licenses<\/p>\n<p>24) Set the security policy for the gateway or cluster \u2014 <em>Install Policy<\/em>.<\/p>\n<h2>Upgrading Security Gateway (SG)<\/h2>\n<p>The security gateway can be updated via CPUSE, just like the management server, or reinstalled \u2014 <strong>fresh install<\/strong>. From my experience, 99% of cases involve reinstalling the Security Gateway since it takes almost as much time as upgrading through CPUSE, but you get a clean, updated OS without bugs.<\/p>\n<p>Similarly to the SMS, a backup and snapshot need to be created and the settings from the Gaia Portal saved. Refer to steps 1, 2, and 3 in the section <em>\u2018Updating Security Management Server\u2019<\/em>.<\/p>\n<p>Updating with CPUSE<\/p>\n<p>Upgrading the Security Gateway through CPUSE is exactly the same process as upgrading the Security Management Server, so please refer to the beginning of the article.<\/p>\n<p>Important point: upgrading the SG requires <strong>a reboot<\/strong>! Therefore, perform the update during a maintenance window. If you have a cluster, first update the passive node, then switch roles and update the other node. In the case of a cluster, maintenance windows can be avoided.<\/p>\n<p>Installing a new OS version on Security Gateway<\/p>\n<p><strong>1.1) If you have a physical SG<\/strong><\/p>\n<p>1.1.1) Using <noindex><a rel=\"nofollow\" href=\"https:\/\/yadi.sk\/d\/DSv8P5CVxipSrw\"><u>Isomorphic Tool<\/u><\/a><\/noindex> a bootable USB flash drive with an image is created <noindex><a rel=\"nofollow\" href=\"https:\/\/yadi.sk\/d\/f2B0zsgTLJi4Yw\"><u>Gaia R80.40<\/u><\/a><\/noindex>. The image is the same as on SMS, but the procedure for creating a bootable flash drive looks slightly different.<\/p>\n<p>1.1.2) I recommend preparing at least 2 bootable flash drives, as sometimes a drive may not be read properly.&nbsp;<\/p>\n<p>1.1.3) Run<em> ISOmorphic.exe. <\/em>In point 1, select the downloaded Gaia R80.40 image, and in point 4, select the flash drive. Points 2 and 3 should not be changed <strong>at all.<\/strong>!<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/526c027ff55a2b9e47b53940583d9e81.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 19. Creating a bootable flash drive<\/p>\n<p>1.1.4) Select the option <em>\u201cInstall automatically without confirmation,\u201d <\/em>and it is important to specify the model of your Security Gateway \u2014 lines 2 or 3. If this is a physical sandbox (SandBlast Appliance), then choose line 5.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/2f3a348bf2875a82cb47183527fd0fe2.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 20. Choosing the device model for creating a bootable flash drive<\/p>\n<p>1.1.5) Next, you turn off the appliance, insert the flash drive into the USB port, connect via a console cable through the COM port to the device, and power on the gateway. The installation process occurs automatically. The default IP address \u2014 <strong>192.168.1.1\/24<\/strong>, and the login data is <strong>admin \/ admin<\/strong>. First, you should update <strong>the passive node<\/strong>, then set a policy for it, switch roles, and then update the other node. Most likely, a maintenance window will be needed.<\/p>\n<p>1.1.6) The next step is to connect to the web interface on Gaia Portal, where you go through the initial setup of the device. During initialization, you mainly click <em>Next, <\/em>as almost all settings can be changed in the future. However, you may change the IP address, DNS settings, and hostname right away.<\/p>\n<p><strong>1.2) If you have a virtual SG<\/strong><\/p>\n<p>1.2.1) Create a new virtual machine with the same or greater resources (CPU, RAM, HDD), as version R80.40 is slightly more demanding. To avoid IP address conflicts, turn off the old gateway and start the installation of the new one with the same IP address. The old SG can be safely deleted, as there is nothing valuable on it; all the most important information \u2014 the security policy \u2014 is on the management server.<\/p>\n<p>1.2.2) During the OS installation, configure the current IP address and allocate an adequate amount of space for the directory. <strong>\/root<\/strong> 3) Connect via HTTPS port to the gateway and start the initialization process. At the installation type selection stage<\/p>\n<p>select the first option \u2014 Security Gateway and\/or Security Management. <em>\u201cInstallation Type\u201d <\/em>select the first option \u2014 Security Gateway and\/or Security Management.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/d775729e7a6890e97621d2d56e993ce7.png\" style=\"display:block;margin: 0 auto;\" \/>4) A crucial point is the selection of the entity (Products). You should choose<\/p>\n<p>4) The most important point \u2014 selecting the entity (Products). You should choose <em><strong>Security Gateway<\/strong><\/em> And if you have a cluster, check the box <em><strong>\"Unit is a part of a cluster, type: ClusterXL\"<\/strong><\/em>. If you have a VRRP cluster, choose that type, but this is unlikely.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/822897faf0380d1bcb5b6c1412aae51a.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 22. Choosing the entity type during the Gaia installation<\/p>\n<p>5) In the next step, set a one-time SIC password to establish trust with the management server. This password generates a certificate, and via the encrypted communication channel, the management server will communicate with the gateway. Check the box <em>\"Connect to your Management as a Service\" <\/em>if the management server is in the cloud. We recently wrote about this <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/517370\/\"><u>the article<\/u><\/a><\/noindex> and how convenient and easy cloud management is.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/eccc5423cafd0356eb1dafbd560eb150.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 23. Creating SIC <\/p>\n<p>6) Start the initialization process on the next tab. Once the device reboots, connect to the web interface and transfer the settings from the screenshots to all tabs in the Gaia Portal where something was configured, or execute the command <strong>load configuration .txt<\/strong>. This config file should first be uploaded to the security gateway.<\/p>\n<p><strong>Note<\/strong><em><strong>: <\/strong><\/em>Since the OS is new, WinSCP will not allow admin access; change the user's shell to \/bin\/bash either in the Users tab in the web interface or by entering the command<em><strong> <\/strong><\/em><strong>chsh \u2013s \/bin\/bash <\/strong>or create a new user with that shell.<\/p>\n<p>7) Open <noindex><a rel=\"nofollow\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?action=portlets.DCFileAction&amp;eventSubmit_doGetdcdetails=&amp;fileid=108335\"><u>SmartConsole R80.40<\/u><\/a><\/noindex> and access the security gateway object that you just reinstalled. Open the tab<em> General Properties &gt; Communication &gt; Reset SIC <\/em>and enter the password set in step 5.<\/p>\n<p><img decoding=\"async\" alt=\"Check Point upgrade procedure from R80.20\/R80.30 to R80.40\" src=\"\/wp-content\/uploads\/2020\/09\/f0b755e9e09bb07478cd52ce26afbd8f.png\" style=\"display:block;margin: 0 auto;\" \/>Figure 24. Establishing trust with the new security gateway<\/p>\n<p>8) The Gaia version of the object should change; if it doesn't, change it manually. Then set the policy on the gateway.<\/p>\n<p>9) In Gaia Portal, go to the tab <em>Upgrades (CPUSE) &gt; Status and Actions &gt; Hotfixes <\/em>and install the latest hotfix. The device will go into <strong>reboot <\/strong>during the installation!<\/p>\n<p>10) In the case of a cluster, switch the node roles and perform the same steps for the other node.<\/p>\n<h2>Conclusion<\/h2>\n<p>I tried to create a clear and comprehensive guide for upgrading from version R80.20\/R80.30 to the current R80.40, as much has changed. The version <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/517378\/\"><u>Gaia R81<\/u><\/a><\/noindex> is already available in demo mode, however, the upgrade procedure remains largely the same. Following the official <noindex><a rel=\"nofollow\" href=\"https:\/\/sc1.checkpoint.com\/documents\/R80.40\/WebAdminGuides\/EN\/CP_R80.40_Installation_and_Upgrade_Guide\/Content\/Topics-IUG\/Upgrading-Management-Servers-and-Log-Servers.htm?tocpath=Upgrade%20of%20Security%20Management%20Servers%20and%20Log%20Servers%7C_____0\"><u>guide<\/u><\/a><\/noindex> from Check Point, you will be able to navigate all the nuances yourself.<\/p>\n<p>For any questions, you can contact us. We would be happy to assist with the most complex upgrades and cases within our technical support <noindex><a rel=\"nofollow\" href=\"https:\/\/cpsupport.ru\/\"><u>CPSupport<\/u><\/a><\/noindex>. Also, on our <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/\"><u>the website<\/u><\/a><\/noindex> there is an option to order an audit of the Check Point settings or leave a free <noindex><a rel=\"nofollow\" href=\"https:\/\/cpsupport.ru\/\"><u>the ticket<\/u><\/a><\/noindex> on a technical case.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/358508\/\"><strong><u>A large collection of materials on Check Point from TS Solution<\/u><\/strong><\/a><\/noindex>. Stay tuned for updates (<noindex><a rel=\"nofollow\" href=\"https:\/\/t.me\/tssolution\">Telegram<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/groups\/tssolution.info\/\">Facebook<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/vk.com\/ts_solution\">VK<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/tssolution.ru\/blog\">TS Solution Blog<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/zen.yandex.ru\/id\/5c7d2162fa818600ae386a52\">Yandex.Zen<\/a><\/noindex>).<\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/517716\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0411\u043e\u043b\u0435\u0435 \u0434\u0432\u0443\u0445 \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434 \u043c\u044b \u043f\u0438\u0441\u0430\u043b\u0438 \u043e \u0442\u043e\u043c, \u0447\u0442\u043e \u043f\u0435\u0440\u0435\u0434 \u043a\u0430\u0436\u0434\u044b\u043c \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u043e\u043c Check Point \u0440\u0430\u043d\u043e \u0438\u043b\u0438 \u043f\u043e\u0437\u0434\u043d\u043e \u0432\u0441\u0442\u0430\u0435\u0442 \u0432\u043e\u043f\u0440\u043e\u0441 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u043d\u0430 \u043d\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e. \u0412 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u0431\u044b\u043b\u043e \u043e\u043f\u0438\u0441\u0430\u043d\u043e \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u0435 \u0441 \u0432\u0435\u0440\u0441\u0438\u0438 R77.30 \u0434\u043e R80.10. \u041a \u0441\u043b\u043e\u0432\u0443, \u0432 \u044f\u043d\u0432\u0430\u0440\u0435 2020-\u0433\u043e R77.30 \u0441\u0442\u0430\u043b\u0430 \u0441\u0435\u0440\u0442\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0432\u0435\u0440\u0441\u0438\u0435\u0439 \u0424\u0421\u0422\u042d\u041a. \u041e\u0434\u043d\u0430\u043a\u043e \u0437\u0430 2 \u0433\u043e\u0434\u0430 \u0432 Check Point \u043c\u043d\u043e\u0433\u043e\u0435 \u0438\u0437\u043c\u0435\u043d\u0438\u043b\u043e\u0441\u044c. \u0412 \u0441\u0442\u0430\u0442\u044c\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":93434,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-93433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0411\u043e\u043b\u0435\u0435 \u0434\u0432\u0443\u0445 \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434 \u043c\u044b.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/proczedura-obnovleniya-check-point-s-r80-20-r80-30-do-r80-40\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f Check Point \u0441 R80.20\/R80.30 \u0434\u043e R80.40 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0411\u043e\u043b\u0435\u0435 \u0434\u0432\u0443\u0445 \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434 \u043c\u044b.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/proczedura-obnovleniya-check-point-s-r80-20-r80-30-do-r80-40\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-07T05:42:37+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-07T05:42:37+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Upgrade procedure for Check Point from R80.20\/R80.30 to R80.40 | ProHoster","description":"More than two years ago we.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/proczedura-obnovleniya-check-point-s-r80-20-r80-30-do-r80-40","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u043e\u0446\u0435\u0434\u0443\u0440\u0430 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f Check Point \u0441 R80.20\/R80.30 \u0434\u043e R80.40 | ProHoster","og:description":"\u0411\u043e\u043b\u0435\u0435 \u0434\u0432\u0443\u0445 \u043b\u0435\u0442 \u043d\u0430\u0437\u0430\u0434 \u043c\u044b.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/proczedura-obnovleniya-check-point-s-r80-20-r80-30-do-r80-40","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-07T05:42:37+00:00","article:modified_time":"2020-09-07T05:42:37+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"93433","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:47:32","updated":"2022-10-02 09:45:58","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/93433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=93433"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/93433\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/93434"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=93433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=93433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=93433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}