> Source: [sk101515](https://support.checkpoint.com/results/sk/sk101515)

# sk101515 - How to Reconfigure a VSX Cluster member 

| Property | Value |
|----------|-------|
| Solution ID | sk101515 |
| Date Created | 2014-07-05 |
| Last Modified | 2022-07-03 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81 (EOS) |
| OS | Gaia |

## Solution

For **R80.10 and higher** versions, refer to the Installation and Upgrade Guide of the version, to which you upgrade. ([R80.10](https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_Installation_and_Upgrade_Guide/html_frameset.htm), [R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_Installation_and_Upgrade_Guide/html_frameset.htm), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/html_frameset.htm), [R80.40](https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Installation_and_Upgrade_Guide/Default.htm), [R81](https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Installation_and_Upgrade_Guide/Default.htm))

For **R77.30 and lower** versions, Refer to the main [sk97552 (VSX Reconfigure and Upgrade Matrix to R77.10 / R77.20 / R77.30)](http://supportcontent.checkpoint.com/solutions?id=sk97552).

When to use this procedure
--------------------------

* After unrecoverable hardware or software failure.
* Adding a new cluster member.

Procedure
---------

Note: ***Renewable*** in the procedure below denotes a VSX cluster member, which should be reconfigured.

1. Backup the involved machines at the same time:

   * Security Management Server / Multi-Domain Security Management Server
   * ***Renewable*** VSX cluster member

   <br />

   Note: Refer to "Related Documentation" section below - "How to Backup".   

2. After a hardware failure on VSX machine, install replacement machine with identical hardware configuration.   

   * Install additional memory on the appliance (if needed)
   * Verify that all cluster members have same physical components
   * Make sure the CPUSE Agent is installed with the latest build
3. Remove all the DATA ports and Sync interfaces and leave only the MGMT interface for the 'vsx_util reconfigure'.   

4. Perform clean installation of R77.30 / R80.10 / R80.20 / R80.30 / R80.40 / R81 on the ***Renewable*** VSX cluster member (refer to "Related Documentation" section below).   

5. Run Gaia First Time Configuration Wizard on the ***Renewable*** VSX cluster member (refer to [sk71000](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk71000) and [sk69701](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk69701)).   

   In case of recovery from a failure, you must use the same Management IP address as was used by the previous cluster member (prior to the failure).  

   In case of adding new member, you will need to set the member IP address as specified in the 'vsx_util add_member' procedure.  

   **Note:** You do not need to establish SIC with the gateway - the vsx_util reconfigure process will do this for you.   

6. If any hotfixes were installed, then install them on the ***Renewable*** VSX cluster member.  
   For hotfix installation instructions, refer to the release notes that were provided with the hotfix, or [contact Check Point Support](http://www.checkpoint.com/services/contact/index.html).   
   **Important Note:** Installation of Jumbo Hotfixes requires an active Software-Blades License and cannot be completed with the default Trial License Configuration.  

7. Merging configuration files with cluster nodes:  

   1. $FWDIR/boot/modules/fwkern.conf
   2. $FWDIR/boot/modules/vpnkern.conf - For versions R80.20 and higher, add the content of this file to $FWDIR/boot/modules/fwkern.conf ([sk166179](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166179))
   3. R80.10 and lower: $PPKDIR/boot/modules/simkern.conf   
      R80.20 and higher: $PPKDIR/conf/simkern.conf
   4. $PPKDIR/boot/modules/sim_aff.conf
   5. $FWDIR/conf/fwaffinity.conf
   6. $FWDIR/conf/fwauthd.conf
   7. $FWDIR/conf/local.arp
   8. $FWDIR/conf/discntd.if
   9. $FWDIR/conf/cpha_bond_ls_config.conf
   10. $FWDIR/conf/resctrl - relevant only for versions R80.30 and lower ([sk162434](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk162434))
   11. $FWDIR/conf/vsaffinity_exception.conf
   12. $FWDIR/database/qos_policy.C
   13. $FWDIR/conf/trac_client_1.ttm
   14. $FWDIR/conf/ipassignment.conf

   <br />

   <br />

8. Configure same number of CPUs for SND and configure MultiQ (If configured).  

9. Validation of number of CPUs and Hyper Threaded  

   Note: Please make sure CoreXL is disabled on VS0.   

10. Prevent the ***Renewable*** VSX cluster member from becoming Active before the reconfigure process ends:  

    **`[Expert@HostName]# cphastop`
    ` [Expert@HostName]# cphaconf fini`
    ` [Expert@HostName]# touch /dev/shm/during_vsx_reconfigure`**   

11. Install the required licenses on the ***Renewable*** VSX cluster member using the cplic put command.  

    **Pre-reconfigure**   

12. In case Bonding, SNMP, IPV6 need to be configured, then configure it now on the ***Renewable*** VSX cluster member. Refer to the R77 Gaia Administration Guide.  

    **Reconfigure**   

13. Make sure that nobody is logged into any of the CMAs/MGMT which are being managed.  

14. Start the reconfigure process on the Security Management Server / Main Domain Management Server.  

    In case of recovery from a failure, Run the **`'vsx_util reconfigure'`** command and follow on screen instructions.  

    In case of adding new member, Run the **`'vsx_util add_member_reconf'`** command and follow on screen instructions. (Make sure you run 'vsx_util add_member' procedure before, as mentioned in step 4.)  

    **Post-reconfigure**   

15. Before reboot the ***Renewable*** VSX cluster member:  

    If you have vital configuration in Gaia OS / FireWall / SecureXL / CoreXL / etc. e.g:  

    * Relevant Only for **R80.10** :  

      * In case we are using 64 bit per VS - align the configuration before reboot (It Should be same as other cluster members) - refer to [sk94627](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk94627).  

        `# vsenv`  
        ` # vs_bits 64`  

    * Relevant to **all R80.X** versions:  

      * In case of using Dynamic Routing / DHCP relay / Proxy ARP reconfigure the required Gaia OS settings in Clish.
      * Verify that reconfigured cluster member should not be an active member for VSs
      * For VSLS cluster - Enabling VSLS on ***Renewable*** VSX cluster member via cpconfig - Check Point Per Virtual System State

      <br />

      <br />

      * Validation of custom configuration file on VS and VSX level: each file must be validated with existing cluster member:   

        1. $FWDIR/boot/modules/fwkern.conf
        2. $FWDIR/boot/modules/vpnkern.conf
        3. R80.10 and lower: $PPKDIR/boot/modules/simkern.conf   
           R80.20 and higher: $PPKDIR/conf/simkern.conf
        4. $PPKDIR/boot/modules/sim_aff.conf
        5. $FWDIR/conf/fwaffinity.conf
        6. $FWDIR/conf/fwauthd.conf
        7. $FWDIR/conf/local.arp
        8. $FWDIR/conf/discntd.if
        9. $FWDIR/conf/cpha_bond_ls_config.conf
        10. $FWDIR/conf/resctrl
        11. $FWDIR/conf/vsaffinity_exception.conf
        12. $FWDIR/database/qos_policy.C
        13. $FWDIR/conf/trac_client_1.ttm
        14. $FWDIR/conf/ipassignment.conf
16. Reboot the ***Renewable*** VSX cluster member  

17. Validations:  

    1. Connect Data and SYNC interfaces
    2. Validate cluster state
    3. Configuration (include configuration that was manually added to VS level)
    4. Failover to this member, verify traffic flow - depends on customer permission
    5. Check for hidden drops using "# fw ctl zdebug drop" - Depends on customer permission
    6. Check failover from this cluster node - depends on customer permission

Related Documentation
---------------------

Show / Hide documentation  

Documents:

* [sk104859 - Check Point R77.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104859)
* [sk101208 - Check Point R77.20](http://supportcontent.checkpoint.com/solutions?id=sk101208)
* [R77 VSX Administration Guide](http://supportcontent.checkpoint.com/documentation_download?id=24802)
* [R77 Gaia Installation and Upgrade Guide](http://supportcontent.checkpoint.com/documentation_download?id=24831)
* [R77 Gaia Administration Guide](http://supportcontent.checkpoint.com/documentation_download?id=24828)
* [R77 Command Line Interface Reference Guide](http://supportcontent.checkpoint.com/documentation_download?id=24833)

Solutions:

* [sk71000 (First Time Configuration Wizard on Check Point appliances)](http://supportcontent.checkpoint.com/solutions?id=sk71000)
* [sk69701 (How to run the First Time Configuration Wizard through CLI in Gaia)](http://supportcontent.checkpoint.com/solutions?id=sk69701)
* [sk107042 (ClusterXL upgrade methods and paths)](http://supportcontent.checkpoint.com/solutions?id=sk107042)
* [sk74300 (Optimal Service Upgrade (OSU) from R67.10 / R75.40VS to R75.40VS / R76 / R77 / R77.10 / R77.20 / R77.30)](http://supportcontent.checkpoint.com/solutions?id=sk74300)

How to Backup:

* [sk108902 (Best Practices - Backup on Gaia OS)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108902)
* [sk91400 (System Backup and Restore feature in Gaia)](http://supportcontent.checkpoint.com/solutions?id=sk91400)
* [sk54100 (How to back up your system on SecurePlatform)](http://supportcontent.checkpoint.com/solutions?id=sk54100)
* [sk98153 (How to take snapshot of Endpoint Security Management Server database)](http://supportcontent.checkpoint.com/solutions?id=sk98153)
* [sk33329 (How to exclude or include files in the Backup on SecurePlatform or Gaia OS)](http://supportcontent.checkpoint.com/solutions?id=sk33329)
* [sk92570 (How to exclude logs from Provider-1 backup on Gaia)](http://supportcontent.checkpoint.com/solutions?id=sk92570)
* [sk62226 (How to test Provider-1 MDS Backup file)](http://supportcontent.checkpoint.com/solutions?id=sk62226)
* Gaia Administration Guide ([R76](http://supportcontent.checkpoint.com/documentation_download?id=22928), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24828)):  
  * Chapter 10 'Maintenance' - System Configuration Backup
* SecurePlatform Administration Guide ([R76](http://supportcontent.checkpoint.com/documentation_download?id=22919), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24810)):  
  * Chapter 4 'Configuration Using the Web Interface' - Device - Backup
  * Chapter 7 'SecurePlatform Shell' - System Commands - backup
  * Chapter 7 'SecurePlatform Shell' - Snapshot Image Management
* Multi-Domain Security Management Administration Guide ([R76](http://supportcontent.checkpoint.com/documentation_download?id=22916), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24807)):  
  * Chapter 12 'Multi-Domain Security Management Commands and Utilities' - Command Line Reference - cma_migrate
  * Chapter 12 'Multi-Domain Security Management Commands and Utilities' - Command Line Reference - mds_backup
  * Chapter 12 'Multi-Domain Security Management Commands and Utilities' - Command Line Reference - mds_restore
* Installation and Upgrade Guide ([R76](http://supportcontent.checkpoint.com/documentation_download?id=22901), [R77 Gaia](http://supportcontent.checkpoint.com/documentation_download?id=24831), [R77 Non-Gaia](http://supportcontent.checkpoint.com/documentation_download?id=30531)):  
  * Chapter 'Upgrading Multi-Domain Security Management' - Upgrade Multi-Domain Security Management Tools - migrate export
  * Chapter 'Upgrading Multi-Domain Security Management' - Upgrade Multi-Domain Security Management Tools - cma_migrate
  * Chapter 'Upgrading Multi-Domain Security Management' - Upgrade Multi-Domain Security Management Tools - Backup and Restore

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
