Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
891 Views 3 Replies Latest reply: Apr 10, 2013 4:12 PM by mtuma RSS
chriselize Newcomer 6 posts since
Apr 10, 2013
Currently Being Moderated

Apr 10, 2013 7:32 AM

McAfee Firewall Enterprise HA Cluster Upgrade

I need to upgrade a Failover  High Availability Cluster that is managed by a Control Center from version 8.2.0 to 8.2.1 P6.  They are set up in a Peer-to-Peer configuration.  According to the Control Center product guide, the Apply packages on all of the synced members option can be selected in the Packages tab of the Manage Firewalls window.  My question is, will this option automatically push the package to the secondary if I install it on the primary?  If so, in the Firewall Maintenance WIndow, should I select both members before selecting "Manage Firewalls", or only the primary?  The alternative might be to upgrade the secondary first, and if successful, switch off the primary to allow the secondary to become primary, and when traffic flow is confirmed, upgrade the previous primary (now standby).  I am concerned that a mismatch of the versions might prevent correct functioning of the failover process.  Can anyone assist?

 

  • mtuma McAfee SME 313 posts since
    Nov 3, 2009
    Currently Being Moderated
    1. Apr 10, 2013 8:58 AM (in response to chriselize)
    Re: McAfee Firewall Enterprise HA Cluster Upgrade

    Hello,

     

    Many customer choose to upgrade one firewall at a time so that they can test the new patch(es). The main problem it will cause is that any policy changes done while they are at different versions will not synchronize. The failover functionality should still work just fine, so if the primary firewall has an issue, the standby will take over, they just might have different policy versions.

     

    -Matt

  • mtuma McAfee SME 313 posts since
    Nov 3, 2009
    Currently Being Moderated
    3. Apr 10, 2013 4:12 PM (in response to chriselize)
    Re: McAfee Firewall Enterprise HA Cluster Upgrade

    It is really up to you, but deselecting that option would make sense so that you can upgrade one before the other. That other issue you have run into is pretty intersting. If you like it would probably make sense to open a case with support.

     

    -Matt

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points