03-22-2018 04:03 PM - edited 02-21-2020 07:33 AM
Hi everyone,
I'd like to update the software version of my active/standby firewall pair.
At present the FW SW version is 9.8(1), ASDM is 7.8(1)
I found the latest version on Cisco website is 9.9.1(for 5525-X), 7.9(1) for ASDM.
Here's my questions:
- Is v9.9.1 a better and more stable version than v9.8(1) ?
- same question for ASDM 7.9(1)
- can I update FW SW and ASDM at the same time, then reboot the Fw once after these 2 updates?
(I have to update ASDM because of the version compatibility)
Since I have 2 FWs in A/S mode, I will update the Standby unit first, then make a failover, then update the old Active unit. Is it the best way to do ?
Thanks.
Regards.
Solved! Go to Solution.
03-22-2018 08:50 PM - edited 03-24-2018 06:40 AM
Please see the software download page for current recommended versions.
As of right now, if you are running 9.8, the recommendation is to use the latest 9.8(2) interim - currently interim build 24 dated 5 March 2018.
ASDM can always be updated without a reload. 7.9(1) is what I currently recommend as a few people have been reporting problems with the recent 7.9(1-151) build.
Your method for upgrading A/S is correct. Cisco documents this pretty well here:
It's an older doc but the procedure remains the same.
03-22-2018 08:50 PM - edited 03-24-2018 06:40 AM
Please see the software download page for current recommended versions.
As of right now, if you are running 9.8, the recommendation is to use the latest 9.8(2) interim - currently interim build 24 dated 5 March 2018.
ASDM can always be updated without a reload. 7.9(1) is what I currently recommend as a few people have been reporting problems with the recent 7.9(1-151) build.
Your method for upgrading A/S is correct. Cisco documents this pretty well here:
It's an older doc but the procedure remains the same.
03-24-2018 06:34 AM
03-24-2018 06:48 AM
Note that the ASA compatibility matrix recommends ASDM 7.8(2)+ (I.e., or later versions) for ASA software 9.8(2).
https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#id_59423
The FirePOWER module is pretty much independent and not affected by ASA or ASDM upgrades; but we should still follow the table further down in the compatibility matrix for that aspect as well. ASA 9.8(x) will be supported with FirePOWER 6.1.0 or later.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide