About Firepower Software Upgrade Packages
To upgrade Firepower software (or perform a readiness check), the software upgrade package must be on the appliance.
In Version 6.5.0 and earlier, FMC-managed devices must get their upgrade packages from the FMC. This means you must upload both FMC and device upgrade packages onto the FMC. Version 6.6.0 adds the ability to use your own internal web server instead of the FMC as the source for FTD upgrade packages. This means that FTD upgrade packages no longer have to 'go through' the FMC.
This table explains how to get upgrade packages onto the FMC.
Method |
Details |
---|---|
Manual |
Download from the Cisco Support & Download site, then upload to the FMC. See Downloading Firepower Software Upgrade Packages and Upload Firepower Software Upgrade Packages to the FMC. |
Direct from Cisco |
An FMC with internet access can download Version 6.2.3–6.5.0 Firepower patches and all maintenance releases (third-digit upgrades) directly from Cisco, about two weeks after they become available for manual download. Direct download from Cisco is not supported for:
|
This table explains how to get upgrade packages onto FMC-managed devices.
Method |
Source |
Details |
Advantages |
Supported Versions/Platforms |
---|---|---|---|---|
Copy (push) packages before upgrade. Recommended. |
FMC |
Upload device upgrade packages to the FMC, but choose when to copy them to devices. |
Reduces the length of your upgrade maintenance window. |
Version 6.2.3 FMC |
Internal web server |
Configure an internal web server instead of the FMC as the source for FTD upgrade packages, and choose when to copy the packages to devices. See Get FTD Upgrade Packages from an Internal Server and Push Upgrade Packages to FMC-Managed Devices. |
Reduces the length of your upgrade maintenance window. Useful if you have limited bandwidth between the FMC and its devices.Saves space on the FMC. |
Version 6.6.0+ FTD devices |
|
Copy packages as part of upgrade. When you start a device upgrade, the system copies the upgrade package to the device as the first task. |
FMC |
Upload device upgrade packages to the FMC before you upgrade the devices. See the previous table. |
— |
Any. If your FMC is Version 6.2.2 or earlier, this is your only choice. |
Internal web server |
Upload device upgrade packages to an internal web server. Then, configure your FTD devices to get upgrade packages from the server instead of the FMC. |
Useful if you have limited bandwidth between the FMC and its devices. Saves space on the FMC. |
Version 6.6.0+ FTD devices |