cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
738
Views
10
Helpful
3
Replies

ASA5516 firmware update - ASA/ASDM only (not FXOS)?

gopher73
Level 1
Level 1

Hi,

I've been asked to take advantage of an upcoming plant outage to do some firmware updates on an active/standby pair of ASA5516 protecting an ICS/OT network.   These firewalls  are currently running ASA 9.10(1)22, ASDM 7.10(1), and have FXOS 2.4(1.244) installed.  The Firepower module is NOT being used at all - the firewall is simply working as a traditional ASA with ASDM. I haven't done an ASA firmware upgrade in a long time, and I've never upgraded one of these newer ASAs with the Firepower module.   

Current "gold star" release appears to be 9.16.3 interim, and it appears from the ASA upgrade guides I've seen so far I should be able to upgrade to directly from 9.10 to that.  I also read that ASA images posted on or after Aug 10, 2022 require ASDM 7.18(1.152)+, so I've downloaded ASDM 7.19.1.   

1.  Do I need to bother with any upgrades to the Firepower module if its not being used at all?

2.  Are there any other problems I might run into if I proceed with just upgrading the ASA and ASDM firmware as per this guide?:  https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/asa-appliance-asav.html#concept_F0701C3A86854801958757CEF1E4D999

Any tips or warnings from any of you with similar experience is appreciated.   Thanks in advance!

 

1 Accepted Solution

Accepted Solutions

ASA5516 running with ASA code (software) upgrade and the SFR (Firepower module sensor) are two different entities. if you do not plan to use to SFR module then you do not need to upgrade/install the software on the ASA5516.

as long as you follow the cisco documentation for ASA softare you good to go and upgrade the system in HA pair with zero downtime.

please do not forget to rate.

View solution in original post

3 Replies 3

Sheraz.Salim
VIP Alumni
VIP Alumni

please see my response to your questions.

 


I've been asked to take advantage of an upcoming plant outage to do some firmware updates on an active/standby pair of ASA5516 protecting an ICS/OT network. These firewalls are currently running ASA 9.10(1)22, ASDM 7.10(1), and have FXOS 2.4(1.244) installed. The Firepower module is NOT being used at all - the firewall is simply working as a traditional ASA with ASDM. I haven't done an ASA firmware upgrade in a long time, and I've never upgraded one of these newer ASAs with the Firepower module. 


you are using ASA 5516 (They are EOL now) these units running ASA 9.10(1)22, ASDM 7.10(1). Great. but how ASA runing FXOS 2.4(1.244) at the same time. ASA5516 can run either as ASA code or FTD code. I assume and you mentioned the Firepower sensor is not used in your ASA.

 


1.  Do I need to bother with any upgrades to the Firepower module if its not being used at all?

2.  Are there any other problems I might run into if I proceed with just upgrading the ASA and ASDM firmware as per this guide?:  https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/asa-appliance-asav.html#concept_F0701C3A86854801958757CEF1E4D999

Any tips or warnings from any of you with similar experience is appreciated.   Thanks in advance!

 

 




If you planning not to use the Firepower module in that case you do not need to download/no need to install the firepower module on your ASA at all. remember in your case you already running your ASA in traditional way.

 

these guide is very soild you would be able to upgrade both appliances. just remember first upgrade the secondary/standby first as mentioned in cisco documention. word of advise read the documenation 3 to 5 time you are confident and make sure do this change in change window

 

 

 

 

please do not forget to rate.

gopher73
Level 1
Level 1

Thanks @Sheraz.Salim for your reply.   These firewalls have FXOS 2.4(1.244) installed, but the Firepower module is not being used at all and I just wanted to be sure that I wasn't going to run into problems treating these the same as older ASA firewalls.  Yes, these are EoL now, but we do not have a suitable replacement yet.  

ASA5516 running with ASA code (software) upgrade and the SFR (Firepower module sensor) are two different entities. if you do not plan to use to SFR module then you do not need to upgrade/install the software on the ASA5516.

as long as you follow the cisco documentation for ASA softare you good to go and upgrade the system in HA pair with zero downtime.

please do not forget to rate.
Review Cisco Networking for a $25 gift card