cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1511
Views
0
Helpful
4
Replies

ASA active/standby software upgrades

Jeroen Huysmans
Level 1
Level 1

Hi,

We currently have 3 ASA clusters, running different software versions. I'd like to upgrade them to the newest release 8.4(2) and have some questions...

  • cluster 1:

2 nodes running active/standby, both nodes running 7.2(4)

this cluster is mostly used for access-lists, no NAT, ...

according to the zero-dowtime guide, I'd upgrade them like this: 7.2(4) => 8.0(5) => 8.2(5) => 8.3(2) => 8.4(2) => 8.4(2)

=> is this a correct path to follow the zero-dowtime upgrade?

=> do I have to worry about significant configuration differences between these software releases?

  • cluster 2:

2 nodes running active/standby, both nodes running 7.2(2)22

this cluster is mostly used for access-lists and NAT

according  to the zero-dowtime guide, I'd upgrade them like this: 7.2(2)22 =>  8.0(5) => 8.2(5) => 8.3(2) => 8.4(2) => 8.4(2)

=> is this a correct path to follow the zero-dowtime upgrade?

=> do I have to worry about significant configuration differences between these software releases?

  • cluster 3:

2 nodes running active/standby, both nodes running 8.3(2)

this cluster is mostly used for VPN

according   to the zero-dowtime guide, I'd upgrade them like this: 8.3(2) => 8.4(2)

=> is this a correct path to follow the zero-dowtime upgrade?

=> do I have to worry about significant configuration differences between these software releases?

when all upgrades are succesfull, I'd keep them updated at all times to avoid this upgrade-mess. Is there any way to be informed about ASA (and IOS) software upgrades?

regards,

Jeroen

4 Replies 4

varrao
Level 10
Level 10

Hi Jeroen,

The action-plan that you have in place is perfect and that what it should be. I would suggest you to go through these docs for complete info on upgrades:

https://supportforums.cisco.com/docs/DOC-12690

zero downtime upgrade:

http://www.cisco.com/en/US/partner/products/ps6120/products_configuration_example09186a0080b20f35.shtml

Go through the first doc carefully.

Thanks,

Varun

Thanks,
Varun Rao

You should also go through the release notes for 8.4 as well:

http://www.cisco.com/en/US/docs/security/asa/asa84/release/notes/asarn84.html

Thanks,

Varun

Thanks,
Varun Rao

Hi Varun,

many thanks. I was unaware of the memory upgrade... 2 clusters only have 512MB RAM, so I'll first have to upgrade their memory before continuing.

regards,

Jeroen

Hi Jeroen,

sure you would need that first.

Thanks,

Varun

Thanks,
Varun Rao
Review Cisco Networking for a $25 gift card