cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2962
Views
1
Helpful
7
Replies

General upgrade queries for FPR-1120 with ASA image

Just trying to make sure as this will be me doing it for the first time.

Scenario:

Device: FPR 1120

Interface Managment 1/1 : unassigned/shut

ASA cli accessible via data interface ip address.

 

Problem Statement:

FPR 1120 is running :

Cisco Adaptive Security Appliance Software Version 9.13(1)2
SSP Operating System Version 2.7(1.107)
Device Manager Version 7.13(1)

 

Target code: AS 9.16.2.x

 

What would be the best/correct upgrade procedure, from ASA cli or FXOS cli ?

 

(a) While in ASA cli, Can i boot ASA into new image after uploading it to Disk0: within ASA ?

or

(b) While in ASA cli, i can connect to FXOS cli with "connect fxos admin". 

Since the managment interface is not configured, is my only option to upload the image is USB?

 

thanks for clarification in advance.

 

1 Accepted Solution

Accepted Solutions

The ASA images available for the Firepower 1120 model and others in that series are the SPA type (signed package including FXOS bundled). When the reload for upgrade occurs the necessary and bundled FXOS upgrade will also install. The 9.16(2.x) images will include FXOS 2.10.1.175.

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/compatibility/threat-defense-compatibility.html#id_67425

View solution in original post

7 Replies 7

Marvin Rhoads
Hall of Fame
Hall of Fame

Simply follow what you mention in (a) and it will work fine.

Thanks,
Would you be able to give a little insight into why (a) is the way to go though the literature mostly talks about (b) ?

By "the literature" I assume you are talking about the Cisco guides (e.g., https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/firepower-4100-9300.html). Those were written by the team that builds FXOS appliances so they focus on the tools they have developed. However it is as easy (or, I would argue, easier) to use the tried and true ASA native method.

Thanks Marvin,

 

(a) will work with file name : "asa9-16-2-14-lfbff-k8.SPA" ? assumingly it will just do the asa upgrade and skip the rest?

 

Is it also the case that the "SSP Operating System Version 2.7(1.107)" is compatible with ASA 9.16.2.x.

If it "wasnt" i would have to upgrade the underlying SSP OS before i could upgrade ASA code, thus the need to do it via the fxos cli (b). Which is done via the package file "asa9-16-2-14-lfbff-k8.SPA" ?

 

I dont have a unit to play around with and i be doing this remotly so as in to avoid breaking anything or re-imaging it.

 

regards

For ASA 9.16x, Cisco requires FXOS 2.10(1.159)+.However the lower end platforms (1100, 2100 and 3100 series) bundle the ASA software with the associated FXOS.

On a higher end platform (Firepower 4100 or 9300 series) you would upgrade the FXOS first and then the ASA software.

Thanks Mr Rhoads,

I think we are almost at the end of this discussion.

I have not checked for the image files for higher models but i thought SPA is the bundle file and it does FXOS first ( if needed ) then the ASA image.

If we do the boot via ASA cli then the FXOS has no chance to be upgraded, does it ?

So, in my case, doing (a) via asa cli is fine as fxos is compatible and like you said, may be also coz 11xx untill 3xxx asa cli + SPA file takes care of both ( FXOS and ASA ) ( not sure how but lets assume it does ).

Ok, i will go in for a test upgrade , thank you for your time.

 

Cant't believe that this not being put in simple words in any documentation by mighty cisco.

The ASA images available for the Firepower 1120 model and others in that series are the SPA type (signed package including FXOS bundled). When the reload for upgrade occurs the necessary and bundled FXOS upgrade will also install. The 9.16(2.x) images will include FXOS 2.10.1.175.

https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/compatibility/threat-defense-compatibility.html#id_67425

Review Cisco Networking for a $25 gift card