Thaum lub caij nplooj zeeg xyoo 2019, Check Point tau tso tseg kev txhawb nqa version R77.XX, thiab nws yuav tsum tau hloov kho. Ntau twb tau hais txog qhov sib txawv ntawm cov versions, qhov zoo thiab qhov tsis zoo ntawm kev hloov mus rau R80. Cia peb tham zoo dua txog yuav ua li cas hloov kho Check Point virtual khoom siv (CloudGuard rau VMware ESXi, Hyper-V, KVM Gateway NGTP) thiab dab tsi tuaj yeem ua yuam kev.
Yog li ntawd, peb muaj 2 CCSE engineers, ntau tshaj li ib tug kaum os Check Point R77.30 virtual pawg, ob peb huab, ob peb hotfixes thiab tag nrho hiav txwv ntawm ntau yam kab, glitches thiab tag nrho cov uas, ntawm tag nrho cov xim thiab ntau thiab tsawg, thiab kuj tseem nruj heev. Wb mus!
Thov nco ntsoov tias nyob ntawm txoj cai khaws cia thiab tshem tawm cov ntaub ntawv qub qub, nrog rau qhov loj ntawm cov ntaub ntawv xa tawm, yuav xav tau ntau qhov chaw. Yog tias, thaum tsim cov ntaub ntawv khaws cia, muaj qhov chaw dawb tsawg dua li tau teev tseg hauv txoj cai tswjfwm cov ntaub ntawv khaws cia, lub kaw lus yuav pib tshem cov log qub thiab yuav TSIS suav nrog lawv hauv cov ntaub ntawv khaws tseg.
Tsis tas li ntawd, rau cov txheej txheem hloov tshiab nws tus kheej, lub kaw lus yuav xav tau tsawg kawg 13 GB ntawm qhov chaw hard disk tsis tau faib. Koj tuaj yeem tshawb xyuas nws lub xub ntiag nrog cov lus txib:
Thaum ua tiav cov lus txib, ib daim ntawv qhia txog kev teeb tsa tsis sib xws yuav raug tsim tawm. Nws muaj nyob rau ntawm: /opt/CPsuite-R77/fw1/log/pre_upgrade_verification_report.(xls, html, txt). Nws yooj yim dua rau upload nws ntawm SCP thiab saib nws los ntawm browser.
Txhawm rau daws qhov teeb meem tsis sib xws, siv SK117237.
Tom qab ntawd rov ua haujlwm pre_upgrade_verifier qhov hluav taws xob kom paub tseeb tias txhua qhov ua rau tsis sib haum tau raug tshem tawm.
Tom ntej no, peb sau cov ntaub ntawv hais txog lub network interfaces, lub rooj sib tham thiab xa cov GAIA teeb tsa: ip a > /var/log/UpgradeR77.30_R80.20/cp-sms-config.txt
ip r > /var/log/UpgradeR77.30_R80.20/cp-sms-config.txt
clish -c "show configuration" > /var/log/UpgradeR77.30_R80.20/cp-sms-config.txt
Upload cov ntaub ntawv tshwm sim ntawm SCP.
Peb nqa ib qho snapshot ntawm qib virtualization.
Peb nce lub sijhawm ntawm SSH kev sib kho mus rau 8 teev. Nws nyob ntawm koj txoj hmoo: nyob ntawm qhov loj ntawm cov ntaub ntawv xa tawm, nws tuaj yeem kav ntev li ob peb feeb mus rau ob peb teev. Rau qhov no: [Expert@HostName]# clish -c "show inactivity-timeout" saib lub sij hawm tawm tam sim no,
[Expert@HostName]# clish -c "teeb ββtsis ua haujlwm-timeout 720" qhia lub sij hawm tawm tshiab (hauv feeb),
[Expert@HostName]# echo $TMOUT saib lub sijhawm tam sim no tus kws tshaj lij hom,
[Expert@HostName]# export TMOUT=3600 qhia lub sijhawm tshiab tus kws tshaj lij hom (hauv vib nas this), yog tias koj teeb tsa tus nqi rau 0, ces lub sijhawm yuav raug kaw.
Ua ntej cov kauj ruam tom ntej, nco ntsoov xyuas ob zaug kom paub tseeb tias koj muaj qhov chaw txaus rau hauv koj lub hard drive (nco ntsoov, koj xav tau 13 GB).
Ua ntej pib export lub configuration, hloov cov ntaub ntawv log nrog cov lus txib: fwv logs
Export configuration thiab cav
Khiav lub migrate_export utility mus download tau lub configuration. Txhawm rau ua qhov no, mus rau lub nplaub tshev uas tau tsim yav dhau los: cd /var/log/UpgradeR77.30_R80.20/ thiab siv cov lus txib: ./migrate export -l /var/log/UpgradeR77.30_R80.20/SMS_w_logs_export_r77_r80.tgz
los yog
mus rau lub folder: cd $FWDIR/bin/upgrade_tools/ ΠΈ
khiav cov lus txib los ntawm qhov ntawd: ./migrate export -l /var/log/UpgradeR77.30_R80.20/SMS_w_logs_export_r77_r80.tgz
Peb tshem checksum los ntawm archive: md5sum /var/log/UpgradeR77.30_R80.20/SMS_w_logs_export_r77_r80.tgz
Peb nce lub sijhawm ntawm SSH kev sib kho mus rau 8 teev. Rau qhov no:
[Expert@HostName]# clish -c "show inactivity-timeout" saib lub sij hawm tawm tam sim no,
[Expert@HostName]# clish -c "teeb ββtsis ua haujlwm-timeout 720" qhia lub sij hawm tawm tshiab (hauv feeb),
[Expert@HostName]# echo $TMOUT saib lub sijhawm tam sim no tus kws tshaj lij hom,
[Expert@HostName]# export TMOUT=3600 qhia txog lub sijhawm tshiab tus kws tshaj lij hom (hauv vib nas this). Yog tias koj teeb tsa tus nqi rau 0, lub sijhawm yuav raug kaw.
Txhawm rau import cov teeb tsa, khiav cov khoom siv migrate import. Txhawm rau ua qhov no, mus rau lub nplaub tshev: cd $FWDIR/bin/upgrade_tools/thiab khiav lub import: ./migrate imp
ort -l /var/log/UpgradeR77.30_R80.20/SMS_w_logs_export_r77_r80.tgz
Cia peb ua neej nyob rau ob peb teev tom ntej no. TSIS TXHOB txiav koj qhov SSH SESSION thaum lub sijhawm ua haujlwm. Thaum kawg, cov txheej txheem tsiv teb tsaws yuav pom cov lus ua tiav lossis qhov yuam kev.
Tshawb xyuas tom qab hloov kho
Muaj peev txheej.
SIC with GW.
Daim ntawv tso cai. Yog tias cov ntawv tso cai tso tawm tsis raug lossis tsis pom hauv SMS, khiav cov lus txib vsec_central_licence rau kev faib daim ntawv tso cai.
Kev teeb tsa txoj cai.
Ntshuam SmartEvent database
Qhib lub SmartEvent hniav.
Peb txuas ntawm WinSCP rau SMS thiab xa cov ntaub ntawv rub tawm yav dhau los hauv hom binary -db-backup.backup ΠΈ eventiaUpgrade.tar rau nplaub tshev /var/log/UpgradeR77.30_R80.20/
Hloov kho qhov Check Point GW pawg (Active/Backup)
Ua ntej pib ua haujlwm
Peb khaws GAIA teeb tsa los ntawm txhua pawg ntawm cov ntaub ntawv, ua qhov no siv cov lus txib: clish -c "show configuration" > ./.txt
Uploading cov ntaub ntawv siv WinSCP.
Txuas mus rau WebUI ntawm ob lub nodes thiab mus rau lub tab CPUSE β Qhia tag nrho cov pob.
Nrhiav lub pob hloov tshiab rau lub version R80.20 Fresh Install, xovxwm Download tau.
Peb xyuas tias CCP raws tu qauv ua haujlwm hauv hom Tshaj tawm, ua qhov no, sau cov lus txib: cphaprob - ib
Yog xaiv hom Multicast, hloov nws nrog cov lus txib: cphaconf set_ccp tshaj tawm (qhov kev hais kom ua yog ua tiav ntawm txhua qhov).
Qhib cov khoom pawg thiab hloov cov pawg ntawm R77.30 rau R80.20. Nyem OK. Yog tias qhov yuam kev tshwm sim thaum txuag kev hloov pauv: Ib qho yuam kev sab hauv tau tshwm sim. (Code: 0x8003001D, Tsis tuaj yeem nkag mus rau cov ntaub ntawv sau ua haujlwm),
ua raws SK119973. Tom qab ntawd, txuag cov kev hloov pauv thiab nyem Nruab Txoj Cai.
Hauv kev teeb tsa, uncheck qhov kev xaiv Rau pawg rooj vag, yog tias kev teeb tsa ntawm pawg neeg ua tsis tiav, tsis txhob nruab rau pawg ntawd.
Peb teeb tsa txoj cai. Lub kaw lus yuav tsim qhov yuam kev rau lub Active node uas tseem tsis tau hloov kho.
Peb txuas mus rau qhov kho tshiab ntawm ssh thiab khiav cov lus txib los saib xyuas lub xeev ntawm pawg: watch -n 2 cphaprob stat
Txuas mus rau WebUI Active node thiab mus rau tab CPUSE β Qhia tag nrho cov pob.Nrhiav lub pob hloov tshiab rau lub version R80.20 Fresh Install, nias Download tau.