> Source: [sk101518](https://support.checkpoint.com/results/sk/sk101518)

# sk101518 - Upgrade VSX Cluster from any version to R77.20 / R77.30 using clean install

| Property | Value |
|----------|-------|
| Solution ID | sk101518 |
| Date Created | 2014-07-05 |
| Last Modified | 2017-09-10 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Solution

**Refer to the main [sk97552 (VSX Reconfigure and Upgrade Matrix to R77.10 / R77.20 / R77.30)](http://supportcontent.checkpoint.com/solutions?id=sk97552).**

When to use this procedure
--------------------------

* Upgrading VSX cluster members from any version to R77.20 / R77.30 (using clean installation).

Part 1 - Upgrade of Security Management Server / Multi-Domain Security Management Server
----------------------------------------------------------------------------------------

1. Backup the involved machines at the same time:

   * Security Management Server / Multi-Domain Security Management Server
   * All VSX cluster members

   <br />

   Note: Refer to "Related Documentation" section below - "How to Backup".   

2. If required, upgrade your Security Management Server / Multi-Domain Security Management Server to the desired version. R77.20 / R77.30 Security Gateways (in Gateway mode and in VSX mode) can be managed by the following Security Management Servers / Multi-Domain Security Management Servers:

   * R76 with hotfix from [sk97626 (How to manage R77.10 / R77.20 / R77.30 gateway with R76 Security Management server)](http://supportcontent.checkpoint.com/solutions?id=sk97626)
   * R77 GA
   * R77.10
   * R77.20
   * R77.30
   * R80 GA

   **Note:** Only features relevant to the version installed on the Security Management Servers / Multi-Domain Security Management Server will be available in SmartDashboard and in '`vsx_util`' command.  
   *Examples* :  
   * You will not be able to upgrade the VSX Gateway / VSX cluster configuration from R77 to R77.20, if you manage it with R77 Security Management server.
   * You will not be able to use Mobile Access Blade on VSX R77.20, if you manage it with R76 Security Management server.
   * You will not be able to use Multi Bridge capability on R77.30, if you manage it with prior version to R77.30 Security Management server.

Part 2 - Upgrade of VSX Cluster
-------------------------------

The following references are used in the procedure below:

* ***Last upgraded*** - denotes last member to be upgraded (in HA cluster, this should be the Active member).
* ***First upgraded*** - denotes first member to be upgraded and reconfigured.

Procedure:

1. Upgrade the configuration of the VSX cluster object to R77.20 / R77.30 version on the Security Management Server / *Main* Domain Management Server.

   Note:
   * If your VSX cluster object is **R77** , and you do *not* want new R77.20 / R77.30 features on the VSX Cluster, then skip this step (proceed to *Step 2* below).
   * If your VSX cluster object is **R76 and lower**, then this step is mandatory.

   Run the '**`vsx_util upgrade`** ' command and follow on-screen instructions.  
   Select your VSX Cluster and then select the R77.20 / R77.30 version.
   **Important Note:** On Management Server R77.20 and lower, when '`vsx_util upgrade`' operation completes, user is prompted to reconfigure the VSX machines. **User must refuse - select "no"** - and proceed to *Step 2* below.   

2. Stop Check Point services on the ***first upgraded*** VSX cluster member:

   **`[Expert@HostName:0]# cpstop`**
   **Note:** In VSX Load Sharing (VSLS) cluster, this will cause a fail-over.   

3. Perform clean installation of R77.20 / R77.30 on the ***first upgraded*** VSX cluster member (refer to "Related Documentation" section below).   

4. Run Gaia First Time Configuration Wizard on the ***first upgraded*** VSX cluster member (refer to [sk71000](http://supportcontent.checkpoint.com/solutions?id=sk71000) and [sk69701](http://supportcontent.checkpoint.com/solutions?id=sk69701)).  
   You must use the same Management IP address as was used by the previous cluster member (prior to the upgrade).  

   **Note: On R77.30** configure the *Cluster ID* to be the same as the *fwha_mac_magic* parameter from the previous cluster version.  

5. In case Bonding needs to be configured, then configure it now on the ***first upgraded*** VSX cluster member. Refer to the [R77 Gaia Administration Guide](http://supportcontent.checkpoint.com/documentation_download?id=24828).   

6. Prevent the ***first upgraded*** VSX cluster member from becoming Active before the reconfigure process ends:

   **```
   [Expert@HostName]# cphastop
   [Expert@HostName]# cphaconf fini
   [Expert@HostName]# touch /dev/shm/during_vsx_reconfigure
   ```**
7. Install the required licenses on the ***first upgraded*** VSX cluster member using *cplic put* command.   

8. **Important Note:** If you have vital configuration in Gaia OS / FireWall / SecureXL / CoreXL / etc. (e.g., Dynamic Routing, DHCP Relay, `$FWDIR/boot/modules/fwkern.conf`, `$PPKDIR/boot/modules/simkern.conf`, `$FWDIR/conf/fwaffinity.conf`, or any other special configuration), then reconfigure the required Gaia OS settings in Clish, add the required settings in the configuration files, and do NOT reboot. Proceed to the next step.   

   **Important Note:** Make sure that the CCP mode (*Multicast* or *Broadcast* ) is the **same** on both cluster members.  

9. Start the reconfigure process on the Security Management Server / *Main* Domain Management Server.

   Run the '**`vsx_util reconfigure`** ' command and follow on-screen instructions.  
   Select the ***first upgraded*** VSX cluster member.  

10. On the ***first upgraded*** VSX cluster member, verify that this cluster member is ready for fail-over:

    * All Virtual Systems must be up with the correct policy (this may take few minutes):

      **`[Expert@HostName:0]# vsx stat -v`**   

    * The state of the cluster member must be 'Ready':

      **`[Expert@HostName:0]# cphaprob state`**

    <br />

    <br />

11. Stop Check Point services on the ***last upgraded*** VSX cluster member (the one still running on old VSX version):

    **`[Expert@HostName:0]# cpstop`**
    **Note:** This will cause a fail-over, and the ***first upgraded*** VSX cluster member will become Active.   

12. Perform clean installation of R77.20 / R77.30 on the ***last upgraded*** VSX cluster member (refer to "Related Documentation" section below).   

13. Run Gaia First Time Configuration Wizard on the ***last upgraded*** VSX cluster member (refer to [sk71000](http://supportcontent.checkpoint.com/solutions?id=sk71000) and [sk69701](http://supportcontent.checkpoint.com/solutions?id=sk69701)).  
    You must use the same Management IP address as was used by the previous cluster member (prior to the upgrade).   

    **Note:** On R77.30 configure the *Cluster ID* to be the same as the *fwha_mac_magic* parameter from the previous cluster version.  

14. In case Bonding needs to be configured, then configure it now on the ***last upgraded*** VSX cluster member. Refer to the [R77 Gaia Administration Guide](http://supportcontent.checkpoint.com/documentation_download?id=24828).   

15. Prevent the ***last upgraded*** VSX cluster member from becoming Active before the reconfigure process ends:

    **```
    [Expert@HostName]# cphastop
    [Expert@HostName]# cphaconf fini
    [Expert@HostName]# touch /dev/shm/during_vsx_reconfigure
    ```**
16. Install the required licenses on the ***last upgraded*** VSX cluster member using *cplic put* command.   

17. **Important Note:** If you have vital configuration in Gaia OS / FireWall / SecureXL / CoreXL / etc. (e.g., Dynamic Routing, DHCP Relay, `$FWDIR/boot/modules/fwkern.conf`, `$PPKDIR/boot/modules/simkern.conf`, `$FWDIR/conf/fwaffinity.conf`, or any other special configuration), then reconfigure the required Gaia OS settings in Clish, add the required settings in the configuration files, and do NOT reboot. Proceed to the next step.  

    **Important Note:** Make sure that the CCP mode (*Multicast* or *Broadcast* ) is the **same** on both cluster members.
18. Start the reconfigure process on the Security Management Server / Multi-Domain Security Management Server.

    Run the '**`vsx_util reconfigure`** ' command and follow on-screen instructions.  
    Select the ***last upgraded*** VSX cluster member.

Related Documentation
---------------------

Show / Hide documentation  

Documents:

* [sk104859 - Check Point R77.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104859)
* [sk101208 - Check Point R77.20](http://supportcontent.checkpoint.com/solutions?id=sk101208)
* [R77 VSX Administration Guide](http://supportcontent.checkpoint.com/documentation_download?id=24802)
* [R77 Gaia Installation and Upgrade Guide](http://supportcontent.checkpoint.com/documentation_download?id=24831)
* [R77 Gaia Administration Guide](http://supportcontent.checkpoint.com/documentation_download?id=24828)
* [R77 Command Line Interface Reference Guide](http://supportcontent.checkpoint.com/documentation_download?id=24833)

Solutions:

* [sk71000 (First Time Configuration Wizard on Check Point appliances)](http://supportcontent.checkpoint.com/solutions?id=sk71000)
* [sk69701 (How to run the First Time Configuration Wizard through CLI in Gaia)](http://supportcontent.checkpoint.com/solutions?id=sk69701)
* [sk107042 (ClusterXL upgrade methods and paths)](http://supportcontent.checkpoint.com/solutions?id=sk107042)
* [sk74300 (Optimal Service Upgrade (OSU) from R67.10 / R75.40VS to R75.40VS / R76 / R77 / R77.10 / R77.20 / R77.30)](http://supportcontent.checkpoint.com/solutions?id=sk74300)

How to Backup:

* [sk108902 (Best Practices - Backup on Gaia OS)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108902)
* [sk91400 (System Backup and Restore feature in Gaia)](http://supportcontent.checkpoint.com/solutions?id=sk91400)
* [sk54100 (How to back up your system on SecurePlatform)](http://supportcontent.checkpoint.com/solutions?id=sk54100)
* [sk98153 (How to take snapshot of Endpoint Security Management Server database)](http://supportcontent.checkpoint.com/solutions?id=sk98153)
* [sk33329 (How to exclude or include files in the Backup on SecurePlatform or Gaia OS)](http://supportcontent.checkpoint.com/solutions?id=sk33329)
* [sk92570 (How to exclude logs from Provider-1 backup on Gaia)](http://supportcontent.checkpoint.com/solutions?id=sk92570)
* [sk62226 (How to test Provider-1 MDS Backup file)](http://supportcontent.checkpoint.com/solutions?id=sk62226)
* Gaia Administration Guide ([R76](http://supportcontent.checkpoint.com/documentation_download?id=22928), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24828)):  
  * Chapter 10 'Maintenance' - System Configuration Backup
* SecurePlatform Administration Guide ([R76](http://supportcontent.checkpoint.com/documentation_download?id=22919), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24810)):  
  * Chapter 4 'Configuration Using the Web Interface' - Device - Backup
  * Chapter 7 'SecurePlatform Shell' - System Commands - backup
  * Chapter 7 'SecurePlatform Shell' - Snapshot Image Management
* Multi-Domain Security Management Administration Guide ([R76](http://supportcontent.checkpoint.com/documentation_download?id=22916), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24807)):  
  * Chapter 12 'Multi-Domain Security Management Commands and Utilities' - Command Line Reference - cma_migrate
  * Chapter 12 'Multi-Domain Security Management Commands and Utilities' - Command Line Reference - mds_backup
  * Chapter 12 'Multi-Domain Security Management Commands and Utilities' - Command Line Reference - mds_restore
* Installation and Upgrade Guide ([R76](http://supportcontent.checkpoint.com/documentation_download?id=22901), [R77 Gaia](http://supportcontent.checkpoint.com/documentation_download?id=24831), [R77 Non-Gaia](http://supportcontent.checkpoint.com/documentation_download?id=30531)):  
  * Chapter 'Upgrading Multi-Domain Security Management' - Upgrade Multi-Domain Security Management Tools - migrate export
  * Chapter 'Upgrading Multi-Domain Security Management' - Upgrade Multi-Domain Security Management Tools - cma_migrate
  * Chapter 'Upgrading Multi-Domain Security Management' - Upgrade Multi-Domain Security Management Tools - Backup and Restore

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
