09-23-2020 01:50 PM
I have tried to update one of our ftd 1010 from fmc. But two times the update is failed. The running software is 6.4. The update I‘m trying to do 6.6. The logs I‘ve seen at ftd:
[200923 09:01:22:591] MAIN_UPGRADE_SCRIPT_START
[200923 09:01:22:665] #####################################
[200923 09:01:22:667] # UPGRADE STARTING
[200923 09:01:22:669] #####################################
compare 6.4.0 and 6.6.0 and
compare, on older version! 6.4.0 < 6.6.0
END_SCRIPT_000_start_000_0_minimum_28GB_RAM_NEEDED_sh=1 #[200923 06:41:09]
[200923 09:01:22:732] SKIP 000_start/000_0_minimum_28GB_RAM_NEEDED.sh
compare 6.4.0 and 6.4.0 and
compare they are equal, 6.4.0 = 6.4.0
END_SCRIPT_000_start_000_0_start_upgrade_status_api_stack_sh=1 #[200923 06:41:10]
[200923 09:01:22:779] SKIP 000_start/000_0_start_upgrade_status_api_stack.sh
END_SCRIPT_000_start_000_check_platform_support_sh=1 #[200923 06:41:10]
[200923 09:01:22:812] BEGIN 000_start/000_check_platform_support.sh
[200923 09:01:25:638] END 000_start/000_check_platform_support.sh
END_SCRIPT_000_start_000_check_sign_type_sh=1 #[200923 06:41:10]
[200923 09:01:25:681] SKIP 000_start/000_check_sign_type.sh
END_SCRIPT_000_start_000_check_update_sh=1 #[200923 06:41:10]
[200923 09:01:25:723] BEGIN 000_start/000_check_update.sh
[200923 09:01:28:092] END 000_start/000_check_update.sh
compare 6.4.0 and 6.4.0 and
compare they are equal, 6.4.0 = 6.4.0
compare 6.4.0 and 6.5.0 and
compare, on older version! 6.4.0 < 6.5.0
END_SCRIPT_000_start_099_repair_ftd_csp_id_sh=1 #[200923 06:41:10]
[200923 09:01:28:156] SKIP 000_start/099_repair_ftd_csp_id.sh
END_SCRIPT_000_start_100_start_messages_sh=1 #[200923 06:41:11]
[200923 09:01:28:209] BEGIN 000_start/100_start_messages.sh
[200923 09:01:30:650] END 000_start/100_start_messages.sh
END_SCRIPT_000_start_101_run_pruning_pl=1 #[200923 06:41:21]
[200923 09:01:30:709] SKIP 000_start/101_run_pruning.pl
END_SCRIPT_000_start_102_check_sru_install_running_pl=1 #[200923 06:41:21]
[200923 09:01:30:785] SKIP 000_start/102_check_sru_install_running.pl
END_SCRIPT_000_start_105_check_model_number_sh=1 #[200923 06:41:22]
[200923 09:01:30:849] BEGIN 000_start/105_check_model_number.sh
[200923 09:01:33:243] END 000_start/105_check_model_number.sh
END_SCRIPT_000_start_106_check_HA_sync_pl=1 #[200923 06:41:23]
[200923 09:01:33:320] BEGIN 000_start/106_check_HA_sync.pl
[200923 09:01:36:933] END 000_start/106_check_HA_sync.pl
END_SCRIPT_000_start_106_check_HA_updates_pl=1 #[200923 06:41:25]
[200923 09:01:37:017] SKIP 000_start/106_check_HA_updates.pl
END_SCRIPT_000_start_107_version_check_sh=1 #[200923 06:41:27]
[200923 09:01:37:110] BEGIN 000_start/107_version_check.sh
[200923 09:01:40:431] END 000_start/107_version_check.sh
END_SCRIPT_000_start_108_check_sensors_ver_pl=1 #[200923 06:41:27]
[200923 09:01:40:524] SKIP 000_start/108_check_sensors_ver.pl
END_SCRIPT_000_start_109_check_HA_MDC_status_pl=1 #[200923 06:41:30]
[200923 09:01:40:607] BEGIN 000_start/109_check_HA_MDC_status.pl
[200923 09:01:45:217] END 000_start/109_check_HA_MDC_status.pl
END_SCRIPT_000_start_110_DB_integrity_check_sh=1 #[200923 06:41:35]
[200923 09:01:45:337] SKIP 000_start/110_DB_integrity_check.sh
END_SCRIPT_000_start_112_CF_check_sh=1 #[200923 06:41:35]
[200923 09:01:45:455] SKIP 000_start/112_CF_check.sh
END_SCRIPT_000_start_113_EO_integrity_check_pl=1 #[200923 06:41:51]
[200923 09:01:45:567] SKIP 000_start/113_EO_integrity_check.pl
END_SCRIPT_000_start_125_verify_bundle_sh=1 #[200923 06:43:17]
[200923 09:01:45:702] BEGIN 000_start/125_verify_bundle.sh
[200923 09:03:10:535] END 000_start/125_verify_bundle.sh
END_SCRIPT_000_start_200_clean_csp_files_sh=1 #[200923 06:43:17]
[200923 09:03:10:654] SKIP 000_start/200_clean_csp_files.sh
END_SCRIPT_000_start_250_check_system_files_sh=1 #[200923 06:43:17]
[200923 09:03:10:772] SKIP 000_start/250_check_system_files.sh
END_SCRIPT_000_start_320_remove_backups_sh=1 #[200923 06:43:18]
[200923 09:03:10:912] SKIP 000_start/320_remove_backups.sh
END_SCRIPT_000_start_400_run_troubleshoot_sh=1 #[200923 06:47:32]
[200923 09:03:11:045] SKIP 000_start/400_run_troubleshoot.sh
END_SCRIPT_000_start_410_check_disk_space_sh=1 #[200923 06:47:33]
[200923 09:03:11:194] BEGIN 000_start/410_check_disk_space.sh
[200923 09:03:13:656] END 000_start/410_check_disk_space.sh
END_SCRIPT_200_pre_001_check_reg_pl=1 #[200923 06:47:38]
[200923 09:03:13:848] BEGIN 200_pre/001_check_reg.pl
[200923 09:03:20:603] END 200_pre/001_check_reg.pl
END_SCRIPT_200_pre_002_check_mounts_sh=1 #[200923 06:47:38]
[200923 09:03:20:642] BEGIN 200_pre/002_check_mounts.sh
[200923 09:03:23:349] END 200_pre/002_check_mounts.sh
END_SCRIPT_200_pre_005_check_manager_pl=1 #[200923 06:47:41]
[200923 09:03:23:388] SKIP 200_pre/005_check_manager.pl
END_SCRIPT_200_pre_006_check_snort_sh=1 #[200923 06:47:42]
[200923 09:03:23:426] SKIP 200_pre/006_check_snort.sh
END_SCRIPT_200_pre_007_check_sru_install_sh=1 #[200923 06:47:43]
[200923 09:03:23:469] SKIP 200_pre/007_check_sru_install.sh
END_SCRIPT_200_pre_009_check_snort_preproc_sh=1 #[200923 06:47:43]
[200923 09:03:23:536] SKIP 200_pre/009_check_snort_preproc.sh
END_SCRIPT_200_pre_011_check_self_sh=1 #[200923 06:47:44]
[200923 09:03:23:585] SKIP 200_pre/011_check_self.sh
END_SCRIPT_200_pre_015_verify_rpm_sh=1 #[200923 06:47:44]
[200923 09:03:23:638] SKIP 200_pre/015_verify_rpm.sh
compare 6.4.0 and 6.5.0 and
compare, on older version! 6.4.0 < 6.5.0
END_SCRIPT_200_pre_100_650_remove_packet_analyzers_pl=1 #[200923 06:47:46]
[200923 09:03:23:711] SKIP 200_pre/100_650_remove_packet_analyzers.pl
END_SCRIPT_200_pre_100_check_dashboards_pl=1 #[200923 06:47:47]
[200923 09:03:23:773] SKIP 200_pre/100_check_dashboards.pl
[200923 09:03:23:850] ** enabling SCRIPT_RECOVERY_MODE for 200_pre/100_get_snort_from_dc.pl
[200923 09:03:23:852] BEGIN 200_pre/100_get_snort_from_dc.pl
[200923 09:03:28:492] END 200_pre/100_get_snort_from_dc.pl
[200923 09:03:28:498] FAILED 200_pre/100_get_snort_from_dc.pl
[200923 09:03:28:500] ====================================
[200923 09:03:28:502] tail -n 10 /ngfw/var/log/sf/Cisco_FTD_SSP_FP1K_Upgrade-6.6.0/200_pre/100_get_snort_from_dc.pl.log
[200923 09:03:23:887] Starting script: 200_pre/100_get_snort_from_dc.pl
entering script
Found snort that needs an update: /ngfw/var/sf/detection_engines/ce5ef4a4-f49a-11e9-a9e1-b1f272d21415/snort
Failure to copy snort pack from manager. Install aborting.
target version: |6.6.0|
snort log location: /ngfw/var/log/sf/Cisco_FTD_SSP_FP1K_Upgrade-6.6.0
Currently upgrading to 6.6.0
snort location: /ngfw/var/log/sf/Cisco_FTD_SSP_FP1K_Upgrade-6.6.0/snort6_6_0
install_mode: UPGRADE
Exit return value = 1
[200923 09:03:29:058] MAIN_UPGRADE_SCRIPT_END
[200923 09:03:29:060] Fatal error: Error running script 200_pre/100_get_snort_from_dc.pl
[200923 09:03:29:072] Exiting.
removed '/ngfw/tmp/upgrade.lock/status_log'
removed '/ngfw/tmp/upgrade.lock/PID'
removed '/ngfw/tmp/upgrade.lock/main_upgrade_script.log'
removed '/ngfw/tmp/upgrade.lock/LSM'
removed directory: '/ngfw/tmp/upgrade.lock'
[200923 09:03:29:077] Attempting to remove upgrade lock
[200923 09:03:29:078] Success, removed upgrade lock
Process 21577 exited.I am going away.
RC: 256
The update failed!
Solved! Go to Solution.
09-25-2020 12:29 AM
Before you upgrade, do a deploy first so that Snort rules are synced between the FMC and managed FTD devices.
09-25-2020 12:29 AM
Before you upgrade, do a deploy first so that Snort rules are synced between the FMC and managed FTD devices.
10-10-2020 01:08 AM
Hello Marvin,
thanks for your message. The next day I have synced the Snort rules and the update is done without any further issue.
You always give a great solution regarding Firepower issue. Three cheers to you!
10-12-2020 12:25 AM
You're welcome @QW_netzwerk . Thanks for rating.
09-28-2020 07:38 AM
The reasons might be different. Have to try to restore the previous version and then try again, Maybe it work for you.
01-18-2024 08:22 AM
Will you have the command and the root where to install the update? @QW_netzwerk @Marvin Rhoads
01-18-2024 09:27 AM
@juannegretej you update Snort rules from the managing FMC under System (gear icon on top right) > Updates
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide