You are upgrading a Security Gateway from R80.40 to R81.20 using the CPUSE 'In-place upgrade' method. The gateway is managed by a Multi-Domain Server. Which step is mandatory to ensure the gateway configuration is preserved after the upgrade?
Trap 1: Run 'cpconfig' to reset the SIC trust before starting the upgrade.
Resetting SIC trust before an upgrade is counterproductive as it breaks the existing communication between the Management Server and the Gateway. SIC needs to be maintained to ensure that the policy push continues to function correctly, and resetting it causes unnecessary administrative overhead and potential security policy deployment gaps.
Trap 2: Disable the Anti-Bot and Anti-Virus blades before the upgrade.
Disabling blades is not a mandatory prerequisite for CPUSE upgrades. Modern Check Point upgrade tools handle the migration of blade configuration automatically. Disabling them would only lead to a loss of security protection during the upgrade window, which contradicts the goal of maintaining a secure and stable network environment.
Trap 3: Upgrade the Security Management Server (SMS) after the gateway.
Check Point architecture mandates that the Management Server must be upgraded to a version equal to or higher than the managed gateways. Upgrading the gateway first can lead to compatibility issues where the management server cannot push policies correctly because it does not recognize the features of the newer gateway version.
- A
Run 'cpconfig' to reset the SIC trust before starting the upgrade.
Why it fails: Resetting SIC trust before an upgrade is counterproductive as it breaks the existing communication between the Management Server and the Gateway. SIC needs to be maintained to ensure that the policy push continues to function correctly, and resetting it causes unnecessary administrative overhead and potential security policy deployment gaps.
- B
Disable the Anti-Bot and Anti-Virus blades before the upgrade.
Why it fails: Disabling blades is not a mandatory prerequisite for CPUSE upgrades. Modern Check Point upgrade tools handle the migration of blade configuration automatically. Disabling them would only lead to a loss of security protection during the upgrade window, which contradicts the goal of maintaining a secure and stable network environment.
- C
Create a Gaia snapshot or perform a backup of the gateway.
Creating a snapshot or backup is the most critical safety step when upgrading gateways. It provides a complete restore point of the OS, configuration, and security policy. If the upgrade fails, you can revert to the known-good state, which minimizes downtime and prevents permanent loss of configuration data.
- D
Upgrade the Security Management Server (SMS) after the gateway.
Why it fails: Check Point architecture mandates that the Management Server must be upgraded to a version equal to or higher than the managed gateways. Upgrading the gateway first can lead to compatibility issues where the management server cannot push policies correctly because it does not recognize the features of the newer gateway version.