> Source: [sk60443](https://support.checkpoint.com/results/sk/sk60443)

# sk60443 - How to install and upgrade Full HA cluster R80.20 - R80.40

| Property | Value |
|----------|-------|
| Solution ID | sk60443 |
| Date Created | 2011-01-05 |
| Last Modified | 2025-04-05 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Hardware |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, Not Version-Specific |
| OS | Gaia |

## Solution

**Note** - For versions **R81 and higher** , see the [Installation and Upgrade Guide](https://support.checkpoint.com/product/531#f-commonsource=C.%20Documentation) for your version:

* Chapter "**Installing a ClusterXL, VSX Cluster, VRRP Cluster** " \> Section "**Full High Availability Cluster on Check Point Appliances**".
* Chapter "**Upgrade of Security Gateways and Clusters** " \> Section "**Upgrading a Full High Availability Cluster**".

<br />

### Introduction

This article provides the relevant guidelines for configuring a Full High Availability (Full HA) cluster in versions R80.20, R80.30, and R80.40.

These guidelines apply to all Check Point appliances that support Full HA cluster on Gaia OS.

For the list of the appliances that support the Standalone / Full High Availability configuration, see the *Release Notes* ([R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RN/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RN/204123&anchor=o210171), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_RN/Content/Topics/cp_appliances.htm#Security_Gateway_and_Standalone_(Gateway_+_Management)_appliances), [R80.40](https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RN/Topics-RN/Supported-Environments.htm#Standalone_and_Full_High_Availability)).

Both members of a Full High Availability (Full HA) cluster run the *Security Management Server* and the *Security Gateway* products.

One Cluster Member is Active, and one Cluster Member is Standby:

* If the Active Cluster Member has a failure that affects the Security Management Server product and the Security Gateway product, then both these products fail over to the Standby Cluster Member.
* If only the Security Management Server product on the Active Cluster Member experiences a failure, then only the Security Management Server product fails over to the Standby Cluster Member.  
  The Security Gateway product on the first Cluster Member continues to function.
* If only the Security Gateway product on the Active Cluster Member experiences a failure, then only the Security Gateway product fails over to the Standby Cluster Member.  
  The Security Management Server product on the first Cluster Member continues to function.

### Configuration Action Plan

1. Install the required software version on both appliances.

2. With your web browser, connect to each appliance:

   `https://<IP Address of Gaia Management Interface>`

   See the [Getting Started Guide](https://support.checkpoint.com/results/sk/sk96246) for your appliance model.
3. Follow the *First Time Configuration Wizard* steps:

   * Configure each appliance as a **Security Management Server** and as a **Security Gateway**.

   * Configure the **Advanced** settings:

     * Select ***Unit is part of a cluster***

     * Select ***ClusterXL***

     * Select ***Primary*** for the primary Cluster Member

       and ***Secondary***for the secondary Cluster Member
   * Configure the administrator account credentials for the Security Management Server.

   * Configure the allowed SmartConsole GUI clients.

4. Reboot each appliance.

5. Optional: Change the IP Address of the Management Interface to the required IP address on each appliance.

6. In SmartConsole, create a ClusterXL object - add new Cluster Member objects, establish SIC, configure the required settings.

7. Install the security policy on the cluster object.

8. Examine the cluster state on each Cluster Member:

   `[Expert@HostName:0]# cphaprob state`

### Upgrade Action Plan

An *upgrade* of a Full HA cluster to a higher software version is supported only after configuring the Full HA cluster.

1. In SmartConsole, understand which Management Server is currently Active and which is currently Standby in **Menu** \> **Management High Availability**.

   If needed, change the states of the Management Servers.
   See the *Security Management Administration Guide* ([R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_SecurityManagement_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_SecurityManagement_AdminGuide/161279), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_SecurityManagement_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_SecurityManagement_AdminGuide/161279), [R80.40](https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SecurityManagement_AdminGuide/Topics-SECMG/Management-High-Availability.htm)) \> Chapter "*Management High Availability*".
2. In CLI on each Cluster Member, understand which Cluster Member is currently Active and which is currently Standby:

   `[Expert@HostName:0]# cphaprob state`

   Make sure the Cluster Member that runs the Active Management Server has the Active cluster state.

   If the Active Management Server runs on the Standby Cluster Member, then perform a controlled fail-over:

   |-------------------------------------------------------|---------------------------------------------|
   | ClusterXL configuration in the Full HA Cluster object | Command to run on the Active Cluster Member |
   | `Maintain current active Cluster Member`              | *clusterXL_admin down ; clusterXL_admin up* |
   | `Switch to higher priority Cluster Member`            | *clusterXL_admin down*                      |

   See the *ClusterXL Administration Guide* ([R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_ClusterXL_AdminGuide/html_frameset.htm), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_ClusterXL_AdminGuide/html_frameset.htm), [R80.40](https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_ClusterXL_AdminGuide/Default.htm)).
3. In CLI on each Cluster Member, export the Management Database.

   You must use the correct version of the [Upgrade Tools](https://support.checkpoint.com/results/sk/sk135172).

   Follow the *Installation and Upgrade Guide* ([R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_Installation_and_Upgrade_Guide/206475), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_Installation_and_Upgrade_Guide/206475), [R80.40](https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Installation_and_Upgrade_Guide/Topics-IUG/Upgrading-Full-HA-Cluster.htm)) \> procedure "*Upgrading Security Management Servers in Management High Availability*".
4. Upgrade the Standby Cluster Member in any supported way (In-place Upgrade, Clean Install from scratch, Advanced Upgrade, Migration).

5. If you upgraded with Clean Install / Advanced Upgrade / Migration, then you must import the Management database on the upgraded Cluster Member.

6. On the non-upgraded Cluster Member, run this command to perform a controlled fail-over from the non-upgraded Cluster Member to the upgraded Cluster Member:

   `clusterXL_admin down`
7. Upgrade the second Cluster Member (Steps 4 and 5 above).

### Important Note

* This article does ***not*** apply to Check Points [Public Cloud Network Security](https://www.checkpoint.com/products/iaas-public-cloud-security/) products.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
