<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Phil, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884232#M155059</link>
    <description>&lt;P&gt;Hi Phil,&lt;/P&gt;
&lt;P&gt;This what I'm doing generally for a failover pair step by step. I always announce a disruption of service for this kind of upgrade.&lt;/P&gt;
&lt;P&gt;- Upgrade the memory of the Secondary unit&lt;/P&gt;
&lt;P&gt;- Upgrade the memory of the Primary Unit&lt;/P&gt;
&lt;P&gt;- Upload all packages (8.4.6 and 9.1.7 + ASDM if required)&lt;/P&gt;
&lt;P&gt;- Change boot option to 8.4.6 on the Primary Unit (replicated to the Secondary Unit) and save.&lt;/P&gt;
&lt;P&gt;- Then I'm turning off both ASA.&lt;/P&gt;
&lt;P&gt;- Reboot the Primary Unit and let it boot and migrate the configuration. Once it's done you can do the same with your Secondary Unit.&lt;/P&gt;
&lt;P&gt;- Then you can do your test and review all your ACLs and NAT rules in order to get a clean configuration.&lt;/P&gt;
&lt;P&gt;- Then do the same for the other steps of version.&lt;/P&gt;
&lt;P&gt;I never had problems with this process. It just cause disruption of service of 2*15 minutes. We usually do these upgrades on non-working hour.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Apr 2016 16:30:50 GMT</pubDate>
    <dc:creator>Alexandre.Parent92</dc:creator>
    <dc:date>2016-04-06T16:30:50Z</dc:date>
    <item>
      <title>Cisco ASA 5520 upgrade 8.2.5 to 9.1.7</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884227#M155051</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have an upgrade tonight for a customer in order to upgrade a StandAlone ASA 5520 in version 8.2.5 to 9.1.7. I have the same upgrade next week for the same customer for a Failover Pair.&lt;/P&gt;
&lt;P&gt;I already made this kind of upgrade process from 8.2.x to 9.1.x so I know all the process since i have to make a first step from 8.2.5 to 8.4.6 and then 9.1.7. In addition this customer doesn't have any Nat Statement so normally an easy process.&lt;/P&gt;
&lt;P&gt;But today during my routine in order to prepare the upgrade (i prefer make a double or triple check before) i found this bug :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuh19234;jsessionid=0A693D57F1BED0C4E78355A4270FD5E" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuh19234;jsessionid=0A693D57F1BED0C4E78355A4270FD5E&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This bug is resolved in the version 8.4.7 and 8.4.6.99 .But it's not recommended by the upgrade process to make a jump from 8.2.5 to 8.4.7 and I can't find the 8.4.6.99 version.&lt;/P&gt;
&lt;P&gt;I don't want to have any problems during my upgrade with something that i can avoid.&lt;/P&gt;
&lt;P&gt;As I said I already done this upgrade in the past without any problems and with more complex configuration.&lt;/P&gt;
&lt;P&gt;Did anyone as a return for this process for the last months? Should I make an additionnal step ? (8.2.5 to 8.4.5 first prior to 8.4.6 or 8.4.7)&lt;/P&gt;
&lt;P&gt;Thanks by advance for your anwser.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884227#M155051</guid>
      <dc:creator>Alexandre.Parent92</dc:creator>
      <dc:date>2019-03-12T07:35:09Z</dc:date>
    </item>
    <item>
      <title>There are few incidents</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884228#M155052</link>
      <description>&lt;P&gt;There are few incidents reported for ASA 5520 running 8.2.5 hitting this defect.&lt;/P&gt;
&lt;P&gt;You might want to go for additional upgrade for 8.4.x like you mentioned&amp;nbsp;to avoid the defect as one can not say for sure whether you will run into this situation or not.&amp;nbsp;&lt;SPAN&gt; 8.4.6.99 might be a development image so may not be available unless you want to call TAC and confirm&amp;nbsp;that or get any other image in 8.4.x train.&amp;nbsp;&lt;BR /&gt;Perhaps, adding another code in upgrade might not hurt as much as hitting the bug.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 11:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884228#M155052</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-04-06T11:01:08Z</dc:date>
    </item>
    <item>
      <title>Hi Alexandre, I am planning</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884229#M155053</link>
      <description>&lt;P&gt;Hi Alexandre, I am planning to execute a similar upgrade (8.2.5 Failover Pair to 9.1.7-4) and was curious on how you planned to implement this?&lt;/P&gt;
&lt;P&gt;I understand that this exercise requires multiple jumps (8.2.5 to 8.4.6 to 9.1.7) as well as config (ACL/NAT) changes. &amp;nbsp;However, in my circumstance - I will also need to upgrade from 1Gb to 2Gb RAM.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;One option is to break the failover pair&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;upgrade the standby offline&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;move traffic (cables/etc) to the &lt;/SPAN&gt;&lt;SPAN style="line-height: normal;"&gt;updated ASA&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Repeat for remaining ASA&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;then re-establish the failover pair.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Another option is to build an upgraded ASA w/ the current config.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Replace it with the failover pair&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Upgrade the pair offline&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Replace upgraded pair back into the network.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;The main concern I have is the multiple upgrades, config changes and RAM upgrade all in one shot.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Just curious on how you were planning to roll out your pair upgrade.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 14:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884229#M155053</guid>
      <dc:creator>Joe Bubba</dc:creator>
      <dc:date>2016-04-06T14:31:13Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884230#M155054</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;you could do the upgrade path:&lt;/P&gt;
&lt;P&gt;8.2.5 &amp;gt; 8.4.6 &amp;gt; 9.1.7&lt;/P&gt;
&lt;P&gt;see links below:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/upgrade/upgrade84.html#pgfId-50546&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/upgrade/upgrade91.html#pgfId-61264&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 14:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884230#M155054</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-04-06T14:40:59Z</dc:date>
    </item>
    <item>
      <title>Hi.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884231#M155056</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;As I said my question is about a bug during the upgrade process from 8.2.5 to 8.4.6. I don't know if this bug is recent or no because I never had that bug during my previous upgrades that's why I'm asking.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 16:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884231#M155056</guid>
      <dc:creator>Alexandre.Parent92</dc:creator>
      <dc:date>2016-04-06T16:02:01Z</dc:date>
    </item>
    <item>
      <title>Hi Phil,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884232#M155059</link>
      <description>&lt;P&gt;Hi Phil,&lt;/P&gt;
&lt;P&gt;This what I'm doing generally for a failover pair step by step. I always announce a disruption of service for this kind of upgrade.&lt;/P&gt;
&lt;P&gt;- Upgrade the memory of the Secondary unit&lt;/P&gt;
&lt;P&gt;- Upgrade the memory of the Primary Unit&lt;/P&gt;
&lt;P&gt;- Upload all packages (8.4.6 and 9.1.7 + ASDM if required)&lt;/P&gt;
&lt;P&gt;- Change boot option to 8.4.6 on the Primary Unit (replicated to the Secondary Unit) and save.&lt;/P&gt;
&lt;P&gt;- Then I'm turning off both ASA.&lt;/P&gt;
&lt;P&gt;- Reboot the Primary Unit and let it boot and migrate the configuration. Once it's done you can do the same with your Secondary Unit.&lt;/P&gt;
&lt;P&gt;- Then you can do your test and review all your ACLs and NAT rules in order to get a clean configuration.&lt;/P&gt;
&lt;P&gt;- Then do the same for the other steps of version.&lt;/P&gt;
&lt;P&gt;I never had problems with this process. It just cause disruption of service of 2*15 minutes. We usually do these upgrades on non-working hour.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 16:30:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-upgrade-8-2-5-to-9-1-7/m-p/2884232#M155059</guid>
      <dc:creator>Alexandre.Parent92</dc:creator>
      <dc:date>2016-04-06T16:30:50Z</dc:date>
    </item>
  </channel>
</rss>

