02-02-2018 01:35 PM - edited 02-21-2020 07:16 AM
I would like to upgrade our firepower modules as well as our firesight management console. Our modules are running 5.4.0.3-37 and our FMC is running 5.4.1.2. Is there a compatibility matrix that defines which modules are compatible with which FMC versions? I have searched the below link and it does not seem to contain this information.
https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html
Solved! Go to Solution.
02-03-2018 06:53 PM
Philip is correct about matching, generally speaking. However FMC 6.2.x (most recent is 6.2.2.1 as of this posting) requires the managed devices be at 6.1 or later.
If you upgrade sequentially you are in for a loooooooong process since your devices are very out of date.
An FMC upgrade takes 30 minutes to an hour depending on the platform and each device upgrade of the several you will need to do per device takes from 15-ish minutes (Firepower 7000 or 8000 series appliance) to as long as an hour and a half (ASA 5506 Firepower service module).
Depending on how many devices you are managing it may be easier to unregister the the devices, update your FMC to 6.2.2, re-image the sensors to 6.2.2 and then re-register / deploy policies. then finally deploy the 6.2.2.1 patch
02-02-2018 09:41 PM
You should keep the module version matching the FMC version. You are asking for trouble by not keeping them in sync.
02-03-2018 06:53 PM
Philip is correct about matching, generally speaking. However FMC 6.2.x (most recent is 6.2.2.1 as of this posting) requires the managed devices be at 6.1 or later.
If you upgrade sequentially you are in for a loooooooong process since your devices are very out of date.
An FMC upgrade takes 30 minutes to an hour depending on the platform and each device upgrade of the several you will need to do per device takes from 15-ish minutes (Firepower 7000 or 8000 series appliance) to as long as an hour and a half (ASA 5506 Firepower service module).
Depending on how many devices you are managing it may be easier to unregister the the devices, update your FMC to 6.2.2, re-image the sensors to 6.2.2 and then re-register / deploy policies. then finally deploy the 6.2.2.1 patch
02-04-2018 02:09 AM
Hello,
Although its recommended to keep the FMC and managed devices at parallel versions, it's unavoidable to have both at same versions since upgrade of FMC precedes the upgrade of managed devices.
To check the compatibility, you should check the release notes of the version to which you are planning to upgrade. For example, in your case, you should check the release notes for next release like FMC 6.0 version.
Now, FMC 6.0 version release notes will indicate if you can upgrade from current version and also if it can support the current managed device(till you upgrade them as well).
HTH
AJ
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide