cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1397
Views
20
Helpful
3
Replies

fmc upgrade effect on the managed devices?

baselzind
Level 6
Level 6

I need to upgrade my fmc from 6.4 to 6.6.4 , can i do it during production? will the upgrade affect the managed devices operation or configuration?

1 Accepted Solution

Accepted Solutions

@baselzind you can do it during production if you wish. The FTDs will continue to function, you will be unable to make changes to the FTDs and no logs will be received by the FMC whilst it's being upgraded. If you only have 1 FMC and you are using AMP, you will be unable to perform any cloud lookups.

View solution in original post

3 Replies 3

@baselzind you can do it during production if you wish. The FTDs will continue to function, you will be unable to make changes to the FTDs and no logs will be received by the FMC whilst it's being upgraded. If you only have 1 FMC and you are using AMP, you will be unable to perform any cloud lookups.

Are you upgrade just your FMC or also the FTDs?

If it is just the FMC, this can be done in production.  The only thing that will be affected is the ability to perform changes, but traffic goes through the FTDs so this will be fine.

If you are also upgrading FTDs, and even if they are in HA setup, I would strongly suggest doing this in a service window.  I have seen some issues with upgrading FXOS when going from 6.4 to 6.6.  So depending on if these are FTD4000 series or FTD 2000 make sure you perform the FXOS manual checks after upgrading the first FXOS before upgrading the second on FTD4000.  The FTD software upgrade will be successful but since FXOS is offline traffic will not flow until this is corrected.

Upgrading FTD2000 there were no issues with FXOS but version 6.6.1 has an SNMP bug which caused traffic drops (for me at least).  But you should be going to a newer release than 6.6.1 so you should not hit this issue.

--
Please remember to select a correct answer and rate helpful posts

Chakshu Piplani
Cisco Employee
Cisco Employee

There is no affect to the managed devices from the upgrade of FMC, FTDs will continue to process traffic, this can be done during production hours, the only downside is that user to IP mapping will not work, logs from FTD to FMC will not flow and will be stored on the FTD device, once the tunnel is re-established post upgrade the logs will be moved to FMC.

 

Regards,

Chakshu

 

Do rate helpful posts!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: