cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4369
Views
40
Helpful
7
Replies

FMC Upgrade rollback 6.6 to 6.4

Luis Seyler
Level 1
Level 1

Hi! I'm planning a firepower upgrade from 6.4 to 6.6 and need to add a rollback procedure, and was wondering if I needed to re-image the device or there is something easier like uninstalling a patch?

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Only since 6.7 and higher releases (and only for FDM) do we have the option to rollback a minor or major release upgrade.

https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_uninstall-an-update.html#Cisco_Concept.dita_f85c578d-c536-4f3c-af7d-7b4ae8f4448b

So in the case of a 6.6 upgrade, rollback would require a lot of work - reimaging in the case of a hardware appliance.

If it is a VM, you could shutdown the server and snapshot it prior to upgrade.

View solution in original post

7 Replies 7

Marvin Rhoads
Hall of Fame
Hall of Fame

Only since 6.7 and higher releases (and only for FDM) do we have the option to rollback a minor or major release upgrade.

https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_uninstall-an-update.html#Cisco_Concept.dita_f85c578d-c536-4f3c-af7d-7b4ae8f4448b

So in the case of a 6.6 upgrade, rollback would require a lot of work - reimaging in the case of a hardware appliance.

If it is a VM, you could shutdown the server and snapshot it prior to upgrade.

That what I was afraid of, hopefully it won't come to that as I have a hardware appliance.

Thanks!

Thanks for answer Marvin! but won't taking a snapshot for virtual FMC cause an issue to the existing one like what happens to ISE for example? just asking to see if that's the case?

 

Thanks!

Marvin Rhoads
Hall of Fame
Hall of Fame

@Jordan-s snapshots don't "break" FMC like they often do with ISE. FMC uses a different db under the covers. ISE uses Oracle vs. FMC which uses SAP (formerly Sybase) SQL Anywhere plus my SQL (and Monet db in newer releases).

If you want to be extra careful, you can shutdown the server first and then snapshot the VM.

Thanks for the answer and the suggestion.

Thanks!

There is a rollback script - "upgrade_rollback.sh" - that you can run from the FMC in expert mode. I am not sure from what version this function was availible, but I recently reverted a failed 6.6.5 upgrade back to 6.4, using this script.

 

/Chess

Thanks for your feedback. I will look into it.

Review Cisco Networking products for a $25 gift card