Upgrade the Secure Firewall 3100/4200 Chassis
Use this procedure to upgrade the chassis on the Secure Firewall 3100/4200 in multi-instance mode.
As you proceed, the chassis upgrade wizard displays basic information about your selected chassis, as well as the current upgrade-related status. This includes any reasons why you cannot upgrade. If a chassis does not "pass" a stage in the wizard, it does not appear in the next stage.
If you navigate away from the wizard, your progress is preserved and other users cannot start a new upgrade workflow for any chassis you have already selected. (Exception: if you are logged in with a CAC, your progress is cleared 24 hours after you log out.) To return to your workflow, choose .
Chassis upgrade does not start until you complete the wizard and click Start Upgrade. All steps up to that point can be performed outside of a maintenance window, including downloading upgrade packages, copying them to chassis, and choosing upgrade options. For information on traffic handling during the upgrade, see Traffic Flow and Inspection for Chassis Upgrades.
Caution |
Do not make or deploy configuration changes to the chassis or threat defense instances during the upgrade. Even if the system appears inactive, do not manually reboot or shut down. In most cases, do not restart an upgrade in progress. You could place the system in an unusable state and require a reimage. Chassis may reboot multiple times during the upgrade. This is expected behavior. If you encounter issues with the upgrade, including a failed upgrade or unresponsive chassis, contact Cisco TAC. |
Before you begin
Make sure you are ready to upgrade:
-
Determine if you can run the target version: Compatibility
-
Plan the upgrade path: Upgrade Path
-
Review upgrade guidelines: Upgrade Guidelines
-
Check infrastructure and network: Network and Infrastructure Checks
-
Check configurations, tasks, and overall deployment health: Configuration and Deployment Checks
-
Perform backups: Backups
Procedure
Step 1 |
On the management center, choose System (). The Product Upgrades page provides an upgrade-centered overview of your deployment—how many devices you have, when they were last upgraded, whether there is an upgrade in progress, and so on. |
Step 2 |
Get the chassis upgrade packages onto the management center. Before you copy upgrade packages to managed chassis, you must upload the packages to the management center (or to an internal server that the chassis can access). The Product Upgrades page lists all upgrade packages that apply to your current deployment, with suggested releases specially marked. In most cases, you can just click Download next to the upgrade package or version you want. Note that you use the same package to upgrade the chassis and the threat defense software. For more information, see Managing Upgrade Packages with the Management Center and Troubleshooting Upgrade Packages. |
Step 3 |
Launch the upgrade wizard. Click Upgrade next to the target version. If you are given a drop-down menu, select Chassis. The chassis upgrade wizard appears. It has two panes: Device Selection on the left, and Device Details on the right. Click a device link in the Device Selection pane (such as '4 devices') to show the Device Details for those chassis. Your target version is pre-selected in the Upgrade to menu. The system determines which chassis can be upgraded to that version and displays them in the Device Details pane. The Device Selection pane also displays the FXOS and firmware versions contained in the upgrade package. |
Step 4 |
Select chassis to upgrade. In the Device Details pane, select the chassis you want to upgrade and click Add to Selection. You can use the device links on the Device Selection pane to toggle the Device Details pane between selected chassis, remaining upgrade candidates, ineligible chassis (with reasons why), chassis that need the upgrade package, and so on. You can add and remove chassis from your selection, or click Reset to clear your chassis selection and start over. Note that you do not have to remove ineligible chassis; they are automatically excluded from upgrade. |
Step 5 |
(Optional) Remove unneeded upgrade packages from your selected chassis. You must manually manage chassis upgrade packages. Right now is a good time to clean up. |
Step 6 |
Copy the new upgrade package to the chassis. Click Copy Upgrade Package and wait for the transfer to complete. |
Step 7 |
Click Next to choose upgrade options. By default, chassis upgrades run in parallel. For chassis with high availability instances, we recommend serial upgrade order. Select the appropriate chassis in the Device Details pane and click Move to Serial Upgrade. We also recommend you place the chassis with the standby unit first in the upgrade order. To change serial upgrade order, click Change Upgrade Order. For more information, see Upgrade Order for Threat Defense with Chassis Upgrade and High Availability/Clusters. |
Step 8 |
Reconfirm you are ready to upgrade. We recommend revisiting the configuration and deployment health checks you performed earlier: Configuration and Deployment Checks. |
Step 9 |
Click Start Upgrade, then confirm that you want to upgrade and reboot the chassis. The wizard shows your overall upgrade progress, which you can also monitor in the Message Center. For detailed status, click View DetailsDetailed Status next to the chassis you want to see. This detailed status is also available from the Upgrade tab on the Device Management page. |
Step 10 |
Verify success. After the upgrade completes, choose and confirm that the chassis you upgraded have the correct chassis version. |
Step 11 |
(Optional) Examine configuration changes. Before you upgrade threat defense, you may want to review the changes made by the chassis upgrade:
|
Step 12 |
(Optional) In high availability deployments, examine device roles. Depending on how you performed the upgrade, high availability instances may have switched roles. Keeping in mind that any subsequent threat defense upgrade will also switch device roles, make any desired changes. |
What to do next
-
(Optional) Clear the wizard by clicking Clear Upgrade Information. Until you do this, the page continues to display details about the upgrade you just performed. After you clear the wizard, use the Upgrade tab on the Device Management page to see last-upgrade information for chassis, and the Advanced Deploy screens to see configuration changes.
-
Back up again: Backups