<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC upgrade to 6.4.0 - FAILED 200_pre/007_check_sru_install.sh in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4496948#M1084793</link>
    <description>&lt;P&gt;I have 2 FMC devices in a HA pair. They are currently running 6.1.0.6 and I am looking to update them to 6.4.0 before upgrading them further to the latest release.&lt;BR /&gt;&lt;BR /&gt;The 'upgrade readiness check' does not work from the GUI even when the HA is in a paused state. I thereby then broke the HA completely and run the readiness check from the CLI&amp;nbsp;via the command 'install_update.pl --detach --readiness-check /var/sf/updates/upgrade_package_name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when looking at the logs, the readiness check fails at the check&lt;BR /&gt;FAILED 200_pre/007_check_sru_install.sh&lt;BR /&gt;&lt;BR /&gt;I look at the log for this check at /var/log/sf/Cisco...Upgrade-6.4.0/upgrade_readiness/200_pre/007_check_sru_install.sh.log and it states:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Starting script: 200_pre/007_check_sru_install.sh&lt;/P&gt;&lt;P&gt;Entering 200_pre/007_check_sru_install.sh....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;previous SRU install completed succesfully&lt;/P&gt;&lt;P&gt;Lists a heap of files'&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;removed '/tmp/sru_sort'&lt;/P&gt;&lt;P&gt;SRU to be reinstalled later in upgrade is missing from the /var/sf/SRU/ directory!&lt;/P&gt;&lt;P&gt;2021-10-27-001-vrt&lt;/P&gt;&lt;P&gt;Please download Sourcefire_rule_update-2021-10-27-001-vrt.sh and put it under /var/sf/SRU/ then perform upgrade again&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;When I check under the /var/sf/SRU/ folder the vrt.sh file is there alongside its .lsm and .info counterparts....&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;As a side note that may or may not have some relationship. But when we had our 2 FMC in HA, the SRU rule updates applied to the active FMC would never be synced to the standby for whatever reason. Once an update was applied to the active, the HA sync would stay up fine, but it would state SRU content does not match. Thought this might be of use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Nov 2021 06:05:01 GMT</pubDate>
    <dc:creator>CraigR</dc:creator>
    <dc:date>2021-11-03T06:05:01Z</dc:date>
    <item>
      <title>FMC upgrade to 6.4.0 - FAILED 200_pre/007_check_sru_install.sh</title>
      <link>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4496948#M1084793</link>
      <description>&lt;P&gt;I have 2 FMC devices in a HA pair. They are currently running 6.1.0.6 and I am looking to update them to 6.4.0 before upgrading them further to the latest release.&lt;BR /&gt;&lt;BR /&gt;The 'upgrade readiness check' does not work from the GUI even when the HA is in a paused state. I thereby then broke the HA completely and run the readiness check from the CLI&amp;nbsp;via the command 'install_update.pl --detach --readiness-check /var/sf/updates/upgrade_package_name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when looking at the logs, the readiness check fails at the check&lt;BR /&gt;FAILED 200_pre/007_check_sru_install.sh&lt;BR /&gt;&lt;BR /&gt;I look at the log for this check at /var/log/sf/Cisco...Upgrade-6.4.0/upgrade_readiness/200_pre/007_check_sru_install.sh.log and it states:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Starting script: 200_pre/007_check_sru_install.sh&lt;/P&gt;&lt;P&gt;Entering 200_pre/007_check_sru_install.sh....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;previous SRU install completed succesfully&lt;/P&gt;&lt;P&gt;Lists a heap of files'&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;removed '/tmp/sru_sort'&lt;/P&gt;&lt;P&gt;SRU to be reinstalled later in upgrade is missing from the /var/sf/SRU/ directory!&lt;/P&gt;&lt;P&gt;2021-10-27-001-vrt&lt;/P&gt;&lt;P&gt;Please download Sourcefire_rule_update-2021-10-27-001-vrt.sh and put it under /var/sf/SRU/ then perform upgrade again&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;When I check under the /var/sf/SRU/ folder the vrt.sh file is there alongside its .lsm and .info counterparts....&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;As a side note that may or may not have some relationship. But when we had our 2 FMC in HA, the SRU rule updates applied to the active FMC would never be synced to the standby for whatever reason. Once an update was applied to the active, the HA sync would stay up fine, but it would state SRU content does not match. Thought this might be of use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 06:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4496948#M1084793</guid>
      <dc:creator>CraigR</dc:creator>
      <dc:date>2021-11-03T06:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: FMC upgrade to 6.4.0 - FAILED 200_pre/007_check_sru_install.sh</title>
      <link>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4497000#M1084794</link>
      <description>&lt;P&gt;Looks you follow the steps correctly, something wrong here - Hope you have enough disk space, (if yes)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;contact TAC is good option before you do anything else and totally mess up things go worst.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(Hope you have backup ?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 09:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4497000#M1084794</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-03T09:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: FMC upgrade to 6.4.0 - FAILED 200_pre/007_check_sru_install.sh</title>
      <link>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4498164#M1084826</link>
      <description>&lt;P&gt;Noticed that all the file names in the /var/sf/SRU are lower case, where as the error in the log was requesting a SRU file with capitals in it.&lt;BR /&gt;&lt;BR /&gt;I copied the SRU file with this 'capitalised' naming convention, and the readiness check then passes.....&lt;BR /&gt;&lt;BR /&gt;Go figure. Hopefully the upgrade works succesfully based on this same logic and doesnt screw up.&lt;BR /&gt;&lt;BR /&gt;No support on these devices anymore so TAC aint an option sadly&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 22:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4498164#M1084826</guid>
      <dc:creator>CraigR</dc:creator>
      <dc:date>2021-11-04T22:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: FMC upgrade to 6.4.0 - FAILED 200_pre/007_check_sru_install.sh</title>
      <link>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4498305#M1084833</link>
      <description>&lt;P&gt;Oh that good trick, ye we need to spend more time to get to know what was the errors. if no support, no option than investigate our time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;some of the areas we do not get access to as much as we like. so we need to rely on TAC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 08:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4498305#M1084833</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-05T08:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: FMC upgrade to 6.4.0 - FAILED 200_pre/007_check_sru_install.sh</title>
      <link>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4559228#M1087656</link>
      <description>&lt;P&gt;So finally getting round to running the actual upgrader, and its failing here.&lt;BR /&gt;[220224 01:35:35:478] END 800_post/400_update_sfipproxy.pl&lt;BR /&gt;[220224 01:35:35:613] BEGIN 800_post/500_update_correlation_rules.pl&lt;BR /&gt;[220224 01:35:37:434] END 800_post/500_update_correlation_rules.pl&lt;BR /&gt;[220224 01:35:37:437] FAILED 800_post/500_update_correlation_rules.pl&lt;BR /&gt;[220224 01:35:37:438] ====================================&lt;BR /&gt;[220224 01:35:37:439] tail -n 10 /var/log/sf/Cisco_Firepower_Mgmt_Center_Upgrade-6.4.0/800_post/500_update_correlation_rules.pl.log&lt;BR /&gt;[220224 01:35:38:125] MAIN_UPGRADE_SCRIPT_END&lt;BR /&gt;[220224 01:35:38:126] Fatal error: Error running script 800_post/500_update_correlation_rules.pl&lt;BR /&gt;[220224 01:35:38:129] Exiting.&lt;BR /&gt;[220224 01:35:38:131] Attempting to remove upgrade lock&lt;BR /&gt;[220224 01:35:38:132] Success, removed upgrade lock&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The actual error from the 500_update_correlation_rules.pl is as follows.&lt;/P&gt;&lt;P&gt;**********************************************************&lt;BR /&gt;[220224 01:35:35:617] Starting script: 800_post/500_update_correlation_rules.pl&lt;BR /&gt;Entering script: 800_post/500_update_correlation_rules.pl&lt;BR /&gt;Loading rules from file...&lt;BR /&gt;Storing updated rules...&lt;BR /&gt;DBD::SQLAnywhere::db prepare failed: Table 'rna_policy_rules' not found (DBD: prepare failed) at /usr/local/sf/lib/perl/5.10.1/SF/EODataHandler/ComplianceRule.pm line 118.&lt;BR /&gt;Store Failed\n at /usr/local/sf/lib/perl/5.10.1/SF/EOHandler.pm line 3437.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Can't call method "execute" on an undefined value at /usr/lib/perl5/site_perl/5.10.1/Error.pm line 273&lt;BR /&gt;Error::subs::run_clauses('HASH(0xa26a200)', 'Can\'t call method "execute" on an undefined value at /usr/lo...', undef, 'ARRAY(0x9c92ab8)')&lt;BR /&gt;called at /usr/lib/perl5/site_perl/5.10.1/Error.pm line 390&lt;BR /&gt;Error::subs::try('CODE(0xa4ca658)', 'HASH(0xa26a200)')&lt;BR /&gt;called at /usr/local/sf/lib/perl/5.10.1/SF/EOHandler.pm line 3443&lt;BR /&gt;SF::EOHandler::_storeObject('HASH(0x9188b30)', 'HASH(0x8dbe240)')&lt;BR /&gt;called at /usr/local/sf/lib/perl/5.10.1/SF/EOHandler.pm line 1757&lt;BR /&gt;SF::EOHandler::storeObject('HASH(0x9188b30)', 'HASH(0x8dbe240)')&lt;BR /&gt;called at 800_post/500_update_correlation_rules.pl line 29&lt;BR /&gt;Error saving correlation rules: Can't call method "execute" on an undefined value&lt;BR /&gt;500_update_correlation_rules.pl.log (END)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appears the error is around a SQL DB missing a table called 'rna_policy_rules'.....&lt;BR /&gt;&lt;BR /&gt;Any ideas on a workaround or such?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 01:19:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4559228#M1087656</guid>
      <dc:creator>CraigR</dc:creator>
      <dc:date>2022-02-25T01:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: FMC upgrade to 6.4.0 - FAILED 200_pre/007_check_sru_install.sh</title>
      <link>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4559359#M1087659</link>
      <description>&lt;P&gt;When there are database issues, TAC will typically run DBCheck.pl as root user and take appropriate action based on the outcome there. It is not recommended to try your own work around in such cases - use the TAC and their much more extensive knowledge base.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 07:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4559359#M1087659</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-02-25T07:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: FMC upgrade to 6.4.0 - FAILED 200_pre/007_check_sru_install.sh</title>
      <link>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4560498#M1087741</link>
      <description>&lt;P&gt;Thanks Marvin,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Running that command shows 182 fatal errors, with a bunch of missing tables and fields.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Hopefully TAC can help, or possibly we can get the 6.4.0 Restore ISO and just rebuild this one from scratch&lt;/P&gt;</description>
      <pubDate>Sun, 27 Feb 2022 22:18:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-upgrade-to-6-4-0-failed-200-pre-007-check-sru-install-sh/m-p/4560498#M1087741</guid>
      <dc:creator>CraigR</dc:creator>
      <dc:date>2022-02-27T22:18:00Z</dc:date>
    </item>
  </channel>
</rss>

