cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

2591
Views
35
Helpful
19
Replies
Highlighted
Beginner

Re: Firepower rulee update

Hi Marvin,

If we upgrade from 5.4.1 to 6.2.2 , it will not effect the ASA traffic right ? ( currently set to monitor-only )

It require atleast 4 hour to upgrade to 6.2.2 ?

Thank you

 

 

Highlighted
Hall of Fame Guru

Re: Firepower rulee update

If your ASA Firepower service module is at 5.4.1 and being used in monitor-only mode, then an upgrade (or even uninstall) will not affect traffic through the ASA. 

 

It it would be easier to de-register it from FMC, upgrade FMC to the current 6.2.3 release (that will take several hours by itself) and then re-image the module to 6.2.3, re-register it and re-deploy the policies. 

Highlighted
Beginner

Re: Firepower rulee update

Thank you Marvin,
De-register FMC, upgrade FMC and reimage module require to access server or only can be done at GUI ( i done have server access ESXi).
Kindly advise step to redeploy policy.
Highlighted
Hall of Fame Guru

Re: Firepower rulee update

You don't need console (ESXi) access to FMC to upgrade it. You do need to be able to transfer files you have downloaded from cisco.com onto a PC to the server via the web interface. 

 

You do need console (ssh) access to the Firepower (sfr) service module to reimage it. If you upgraded it step-by-step instead you can do it all via the FMC but it will take most of an entire day (assuming it all goes well) vs. about 2 hours to reimage.

 

I really recommend you read the documentation on the above steps. It's all covered there - upgrading, re-imaging, registering, deploying policy etc. There are many good free presentations available on Cisco Live as well. You should understand the basics before logging into any production system and making significant changes.

Highlighted
Contributor

Re: Firepower rulee update

I set rule updates for daily during non-business hours. I have never had a problem.