<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3885194#M1028725</link>
    <description>&lt;P&gt;Your FMC should detect the new version even if it is installed manually on the ASA appliance running FTD. Your HA should remain intact. I'd recommend following a similar procedure to what is done when you upgrade a plain ASA HA pair (get image on both, upgrade Secondary - Standby, verify success, wait for return to Standby - Ready state, make it Active and repeat of the Primary unit.&lt;/P&gt;
&lt;P&gt;Most of the underlying failover operations and associated code is inherited from ASA as the LINA subsystem on FTD.&lt;/P&gt;
&lt;P&gt;Of course it would be nice to lab that all in advance.&lt;/P&gt;
&lt;P&gt;Note that once you are on 6.2.3, you will have the option to push an update to the device from FMC prior to upgrade.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jul 2019 11:43:51 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-07-05T11:43:51Z</dc:date>
    <item>
      <title>ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3777380#M1028719</link>
      <description>&lt;P&gt;Dear Team:&lt;/P&gt;
&lt;P&gt;is there any Cisco&amp;nbsp;documentation for &lt;STRONG&gt;Upgrade Procedures&lt;/STRONG&gt; on&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;ASA 5525-x from 6.2.2 to the last release 6.3?&lt;/P&gt;
&lt;P&gt;I've seen int the web page a file name but with a different extension ".tar"&lt;/P&gt;
&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/286271172/type/286306337/release/6.3.0" target="_blank"&gt;https://software.cisco.com/download/home/286271172/type/286306337/release/6.3.0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cisco_download.png" style="width: 399px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/27566iDE7E92278C714D97/image-dimensions/399x200?v=v2" width="399" height="200" role="button" title="Cisco_download.png" alt="Cisco_download.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;best regards,&lt;/P&gt;
&lt;P&gt;Jhon&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:38:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3777380#M1028719</guid>
      <dc:creator>jhontoc24</dc:creator>
      <dc:date>2020-02-21T16:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3777387#M1028720</link>
      <description>&lt;P&gt;1. Download the tar file to your workstation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. If you are managing the device with FMC, upload the tar file to FMC (via System &amp;gt; Updates) and then select and install it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. If you are managing the device via FDM, do a similar process via Updates &amp;gt; System Upgrade.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 03:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3777387#M1028720</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-01-11T03:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3777503#M1028721</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial black,avant garde"&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/213269-upgrade-procedure-through-fmc-for-firepo.html" target="_self"&gt;Upgrade Procedure Doc&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Abheesh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2019 07:24:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3777503#M1028721</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2019-01-11T07:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3877229#M1028722</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two ASA 5525 with FTD version 6.2.3.3 (active/strandby) - both are registered with FMC.&lt;/P&gt;&lt;P&gt;Now I want to upgrade FTDs to 6.3 and wanted to do it without FMC. Is there any way we can upgrade the devices without FMC and then register in FMC again ?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 06:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3877229#M1028722</guid>
      <dc:creator>Muhammad Abubakar</dc:creator>
      <dc:date>2019-06-21T06:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3877358#M1028723</link>
      <description>&lt;P&gt;It can be done but it's a LOT more work. It's not a recommended path nor is it strictly supported.&lt;/P&gt;
&lt;P&gt;The cli procedure is referenced in this thread:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/firepower/fmc-upgrade-from-cli/td-p/3401740" target="_blank"&gt;https://community.cisco.com/t5/firepower/fmc-upgrade-from-cli/td-p/3401740&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;What's your reason for wanting to use the cli method?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 11:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3877358#M1028723</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-06-21T11:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3885122#M1028724</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply, the link is helpful. Sorry for returning late here I was busy with many things together.. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our reason to do it manually is that the location where these FTDs are, have bandwidth limitations. So if I push the package and start the upgrade from FMC I'm afraid it'll take the bandwidth and will effect other services on the link. we are upgrading the SFRs manually for the same reason on other sites.&amp;nbsp;But since this is first time I'm upgrading the FTDs hence the question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently I'm ding PoC for FTD upgrade in my LAB. I'll update here once done.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But meanwhile another questions, Since the FTDs are in cluster I wonder if I need to remove it from FMC ?? (since I'm upgrading the FTDs with out FMC) and then add them back when they are upgraded.. If not, then I wonder what will be the cluster status in FMC once I start upgrading the secondary&amp;nbsp; box .. As I know If we upgrade it from FMC the cluster goes into maintenance state.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; have a very nice weekend.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 08:35:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3885122#M1028724</guid>
      <dc:creator>Muhammad Abubakar</dc:creator>
      <dc:date>2019-07-05T08:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3885194#M1028725</link>
      <description>&lt;P&gt;Your FMC should detect the new version even if it is installed manually on the ASA appliance running FTD. Your HA should remain intact. I'd recommend following a similar procedure to what is done when you upgrade a plain ASA HA pair (get image on both, upgrade Secondary - Standby, verify success, wait for return to Standby - Ready state, make it Active and repeat of the Primary unit.&lt;/P&gt;
&lt;P&gt;Most of the underlying failover operations and associated code is inherited from ASA as the LINA subsystem on FTD.&lt;/P&gt;
&lt;P&gt;Of course it would be nice to lab that all in advance.&lt;/P&gt;
&lt;P&gt;Note that once you are on 6.2.3, you will have the option to push an update to the device from FMC prior to upgrade.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 11:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3885194#M1028725</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-05T11:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3923946#M1028726</link>
      <description>&lt;P&gt;finally I got time to do this in the lab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Mervin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, you are right. I followed the same process. download upgrade and patch versions to devices and than upgrade secondary first then wait for the HA status OK (in FMC) and switch peer active&amp;lt;-&amp;gt;standby, upgrade the second unit .. All went smooth.but after the patch upgrade on second unit it doesn't show the HA active and standby ready.. Instead second unit is now in disabled state. with following logs from "sh fail hist" command.&amp;nbsp; on secondary (disabled) unit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;==========================================================================&lt;BR /&gt;From State&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To State&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; Reason&lt;BR /&gt;==========================================================================&lt;BR /&gt;11:27:28 UTC Sep 13 2019&lt;BR /&gt;Not Detected&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Negotiation&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; No Error&lt;/P&gt;&lt;P&gt;11:28:03 UTC Sep 13 2019&lt;BR /&gt;Negotiation&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Cold Standby&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Detected an Active mate&lt;/P&gt;&lt;P&gt;11:28:04 UTC Sep 13 2019&lt;BR /&gt;Cold Standby&amp;nbsp; &amp;nbsp; &amp;nbsp;App Sync&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Detected an Active mate&lt;/P&gt;&lt;P&gt;11:33:57 UTC Sep 13 2019&lt;BR /&gt;App Sync&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Disabled CD&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; App Sync error is app sync failure with error code device_failure_configuration&lt;BR /&gt;==========================================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its strange. even when first unit was upgraded and the FTD version was different on both devices the HA was OK. but now when both devices are with same version, secondary unit went disabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried reboot the secondary unit but no luck..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 14:09:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3923946#M1028726</guid>
      <dc:creator>Muhammad Abubakar</dc:creator>
      <dc:date>2019-09-13T14:09:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5525 FTD Upgrade from 6.2.2 to 6.3</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3924206#M1028727</link>
      <description>&lt;P&gt;You may need to remove and then re-add it onto the HA configuration from FMC.&lt;/P&gt;
&lt;P&gt;Opening a TAC case might be the best course of action given the current state of the unit.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 23:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-ftd-upgrade-from-6-2-2-to-6-3/m-p/3924206#M1028727</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-13T23:18:54Z</dc:date>
    </item>
  </channel>
</rss>

