02-23-2023 10:36 AM - edited 02-23-2023 12:41 PM
Hi,
I've been asked to take advantage of an upcoming plant outage to do some firmware updates on an active/standby pair of ASA5516 protecting an ICS/OT network. These firewalls are currently running ASA 9.10(1)22, ASDM 7.10(1), and have FXOS 2.4(1.244) installed. The Firepower module is NOT being used at all - the firewall is simply working as a traditional ASA with ASDM. I haven't done an ASA firmware upgrade in a long time, and I've never upgraded one of these newer ASAs with the Firepower module.
Current "gold star" release appears to be 9.16.3 interim, and it appears from the ASA upgrade guides I've seen so far I should be able to upgrade to directly from 9.10 to that. I also read that ASA images posted on or after Aug 10, 2022 require ASDM 7.18(1.152)+, so I've downloaded ASDM 7.19.1.
1. Do I need to bother with any upgrades to the Firepower module if its not being used at all?
2. Are there any other problems I might run into if I proceed with just upgrading the ASA and ASDM firmware as per this guide?: https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/asa-appliance-asav.html#concept_F0701C3A86854801958757CEF1E4D999
Any tips or warnings from any of you with similar experience is appreciated. Thanks in advance!
Solved! Go to Solution.
02-23-2023 02:49 PM
ASA5516 running with ASA code (software) upgrade and the SFR (Firepower module sensor) are two different entities. if you do not plan to use to SFR module then you do not need to upgrade/install the software on the ASA5516.
as long as you follow the cisco documentation for ASA softare you good to go and upgrade the system in HA pair with zero downtime.
02-23-2023 01:18 PM
please see my response to your questions.
I've been asked to take advantage of an upcoming plant outage to do some firmware updates on an active/standby pair of ASA5516 protecting an ICS/OT network. These firewalls are currently running ASA 9.10(1)22, ASDM 7.10(1), and have FXOS 2.4(1.244) installed. The Firepower module is NOT being used at all - the firewall is simply working as a traditional ASA with ASDM. I haven't done an ASA firmware upgrade in a long time, and I've never upgraded one of these newer ASAs with the Firepower module.
you are using ASA 5516 (They are EOL now) these units running ASA 9.10(1)22, ASDM 7.10(1). Great. but how ASA runing FXOS 2.4(1.244) at the same time. ASA5516 can run either as ASA code or FTD code. I assume and you mentioned the Firepower sensor is not used in your ASA.
1. Do I need to bother with any upgrades to the Firepower module if its not being used at all?
2. Are there any other problems I might run into if I proceed with just upgrading the ASA and ASDM firmware as per this guide?: https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/asa-appliance-asav.html#concept_F0701C3A86854801958757CEF1E4D999
Any tips or warnings from any of you with similar experience is appreciated. Thanks in advance!
If you planning not to use the Firepower module in that case you do not need to download/no need to install the firepower module on your ASA at all. remember in your case you already running your ASA in traditional way.
these guide is very soild you would be able to upgrade both appliances. just remember first upgrade the secondary/standby first as mentioned in cisco documention. word of advise read the documenation 3 to 5 time you are confident and make sure do this change in change window
02-23-2023 02:17 PM
Thanks @Sheraz.Salim for your reply. These firewalls have FXOS 2.4(1.244) installed, but the Firepower module is not being used at all and I just wanted to be sure that I wasn't going to run into problems treating these the same as older ASA firewalls. Yes, these are EoL now, but we do not have a suitable replacement yet.
02-23-2023 02:49 PM
ASA5516 running with ASA code (software) upgrade and the SFR (Firepower module sensor) are two different entities. if you do not plan to use to SFR module then you do not need to upgrade/install the software on the ASA5516.
as long as you follow the cisco documentation for ASA softare you good to go and upgrade the system in HA pair with zero downtime.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide