06-23-2022 10:33 AM
Just trying to make sure as this will be me doing it for the first time.
Scenario:
Device: FPR 1120
Interface Managment 1/1 : unassigned/shut
ASA cli accessible via data interface ip address.
Problem Statement:
FPR 1120 is running :
Cisco Adaptive Security Appliance Software Version 9.13(1)2
SSP Operating System Version 2.7(1.107)
Device Manager Version 7.13(1)
Target code: AS 9.16.2.x
What would be the best/correct upgrade procedure, from ASA cli or FXOS cli ?
(a) While in ASA cli, Can i boot ASA into new image after uploading it to Disk0: within ASA ?
or
(b) While in ASA cli, i can connect to FXOS cli with "connect fxos admin".
Since the managment interface is not configured, is my only option to upload the image is USB?
thanks for clarification in advance.
Solved! Go to Solution.
06-25-2022 09:20 PM
The ASA images available for the Firepower 1120 model and others in that series are the SPA type (signed package including FXOS bundled). When the reload for upgrade occurs the necessary and bundled FXOS upgrade will also install. The 9.16(2.x) images will include FXOS 2.10.1.175.
06-23-2022 11:41 AM
Simply follow what you mention in (a) and it will work fine.
06-23-2022 12:09 PM
06-24-2022 01:26 AM
By "the literature" I assume you are talking about the Cisco guides (e.g., https://www.cisco.com/c/en/us/td/docs/security/asa/upgrade/asa-upgrade/firepower-4100-9300.html). Those were written by the team that builds FXOS appliances so they focus on the tools they have developed. However it is as easy (or, I would argue, easier) to use the tried and true ASA native method.
06-24-2022 05:31 AM - edited 06-24-2022 05:36 AM
Thanks Marvin,
(a) will work with file name : "asa9-16-2-14-lfbff-k8.SPA" ? assumingly it will just do the asa upgrade and skip the rest?
Is it also the case that the "SSP Operating System Version 2.7(1.107)" is compatible with ASA 9.16.2.x.
If it "wasnt" i would have to upgrade the underlying SSP OS before i could upgrade ASA code, thus the need to do it via the fxos cli (b). Which is done via the package file "asa9-16-2-14-lfbff-k8.SPA" ?
I dont have a unit to play around with and i be doing this remotly so as in to avoid breaking anything or re-imaging it.
regards
06-24-2022 10:54 AM
For ASA 9.16x, Cisco requires FXOS 2.10(1.159)+.However the lower end platforms (1100, 2100 and 3100 series) bundle the ASA software with the associated FXOS.
On a higher end platform (Firepower 4100 or 9300 series) you would upgrade the FXOS first and then the ASA software.
06-24-2022 02:14 PM - edited 06-24-2022 02:14 PM
Thanks Mr Rhoads,
I think we are almost at the end of this discussion.
I have not checked for the image files for higher models but i thought SPA is the bundle file and it does FXOS first ( if needed ) then the ASA image.
If we do the boot via ASA cli then the FXOS has no chance to be upgraded, does it ?
So, in my case, doing (a) via asa cli is fine as fxos is compatible and like you said, may be also coz 11xx untill 3xxx asa cli + SPA file takes care of both ( FXOS and ASA ) ( not sure how but lets assume it does ).
Ok, i will go in for a test upgrade , thank you for your time.
Cant't believe that this not being put in simple words in any documentation by mighty cisco.
06-25-2022 09:20 PM
The ASA images available for the Firepower 1120 model and others in that series are the SPA type (signed package including FXOS bundled). When the reload for upgrade occurs the necessary and bundled FXOS upgrade will also install. The 9.16(2.x) images will include FXOS 2.10.1.175.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide