09-16-2021 01:58 AM
I need to upgrade my fmc from 6.4 to 6.6.4 , can i do it during production? will the upgrade affect the managed devices operation or configuration?
Solved! Go to Solution.
09-16-2021 02:04 AM
@baselzind you can do it during production if you wish. The FTDs will continue to function, you will be unable to make changes to the FTDs and no logs will be received by the FMC whilst it's being upgraded. If you only have 1 FMC and you are using AMP, you will be unable to perform any cloud lookups.
09-16-2021 02:04 AM
@baselzind you can do it during production if you wish. The FTDs will continue to function, you will be unable to make changes to the FTDs and no logs will be received by the FMC whilst it's being upgraded. If you only have 1 FMC and you are using AMP, you will be unable to perform any cloud lookups.
09-16-2021 02:06 AM
Are you upgrade just your FMC or also the FTDs?
If it is just the FMC, this can be done in production. The only thing that will be affected is the ability to perform changes, but traffic goes through the FTDs so this will be fine.
If you are also upgrading FTDs, and even if they are in HA setup, I would strongly suggest doing this in a service window. I have seen some issues with upgrading FXOS when going from 6.4 to 6.6. So depending on if these are FTD4000 series or FTD 2000 make sure you perform the FXOS manual checks after upgrading the first FXOS before upgrading the second on FTD4000. The FTD software upgrade will be successful but since FXOS is offline traffic will not flow until this is corrected.
Upgrading FTD2000 there were no issues with FXOS but version 6.6.1 has an SNMP bug which caused traffic drops (for me at least). But you should be going to a newer release than 6.6.1 so you should not hit this issue.
09-16-2021 02:06 AM
There is no affect to the managed devices from the upgrade of FMC, FTDs will continue to process traffic, this can be done during production hours, the only downside is that user to IP mapping will not work, logs from FTD to FMC will not flow and will be stored on the FTD device, once the tunnel is re-established post upgrade the logs will be moved to FMC.
Regards,
Chakshu
Do rate helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide