<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrading an HA FTD pair in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712807#M995777</link>
    <description>&lt;P&gt;No you cannot pause the HA upgrade (short of some drastic and unsupported cli surgery).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It may change in future releases but that's the state of things as of 6.2.3.5.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Sep 2018 13:07:46 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-09-25T13:07:46Z</dc:date>
    <item>
      <title>Upgrading an HA FTD pair</title>
      <link>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712432#M995772</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the ASA world, when you had to upgrade a failover pair, you would upgrade the Standby unit, once the upgrade is complete and everything looks fine in the "show failover" command, you would failover to that unit, do all your testing and if everything is successful, upgrade the remaining unit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the FTD world (I am referring to FTDs managed by an FMC and not running FDM), when you upgrade a failover pair of FTDs you no longer have the option to actually test everything out after the first unit gets upgraded, takes over the active role and BEFORE upgrading the remaining unit. So if during testing of the new OS you find that many things are broken, you don't have a quick back out (the second unit upgrade starts right after the first unit upgrade finishes).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is, if there is a way to "pause" the upgrade once you finish the upgrade of the first unit.&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:16:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712432#M995772</guid>
      <dc:creator>arisgiannakopoulos</dc:creator>
      <dc:date>2020-02-21T16:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an HA FTD pair</title>
      <link>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712807#M995777</link>
      <description>&lt;P&gt;No you cannot pause the HA upgrade (short of some drastic and unsupported cli surgery).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It may change in future releases but that's the state of things as of 6.2.3.5.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 13:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712807#M995777</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-25T13:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an HA FTD pair</title>
      <link>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712834#M995787</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for the reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope that in a future release they will introduce a timer that you can leverage in order to have some time to do some thorough testing before upgrading the next unit. As it stands right now, if your network is broken because of the upgrade, you don't have a quick roll back as to downgrade a unit takes the same amount of time as for the upgrade.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 13:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712834#M995787</guid>
      <dc:creator>arisgiannakopoulos</dc:creator>
      <dc:date>2018-09-25T13:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading an HA FTD pair</title>
      <link>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712842#M995802</link>
      <description>&lt;P&gt;I agree - even simple policy deployments can take 6-7 minutes (if not longer). Break something with your policy change and you're looking at having to wait that long again to redeploy before it's fixed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco really needs to address that issue.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 13:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/upgrading-an-ha-ftd-pair/m-p/3712842#M995802</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-25T13:53:09Z</dc:date>
    </item>
  </channel>
</rss>

