cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6394
Views
0
Helpful
3
Replies

Out of compliance in FMC

Hi Everyone.

I am planning to upgrade FMCv form 6.5.0 to 6.6.0 version. 

FMCv manages Multiple FTD's Instance.  I see in smart license : "Out of Compliance" message. if I proceed for upgrading FMCv without procuring license, is there any impact or issue ? Please let me know. 

 

Thank you

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

You can upgrade the FMC but, depending on what is out of compliance, you may not have the right do do so under the terms and conditions of the End User Licensing Agreement (EULA). If your FMC is licensed and under support then you have full rights to upgrade.

Any managed devices with out-of-compliance Smart licenses will not be able to deploy any policies that may use the unlicensed features. Even if you make no change to the policies that use those features, it is recommended to sync policy etc. from FMC to all managed devices following an upgrade.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

You can upgrade the FMC but, depending on what is out of compliance, you may not have the right do do so under the terms and conditions of the End User Licensing Agreement (EULA). If your FMC is licensed and under support then you have full rights to upgrade.

Any managed devices with out-of-compliance Smart licenses will not be able to deploy any policies that may use the unlicensed features. Even if you make no change to the policies that use those features, it is recommended to sync policy etc. from FMC to all managed devices following an upgrade.

Hi Marvin.

 

Thank you. 

Before i go to FTD upgrade. Would like to upgrade FMC to 6.6.x or 6.7.x. Can someone please help me with steps to upgrade FMCv via GUI and CLI. 

 

We have Firepower 4145 model running 2.7(1.106) (2*4145 , 8 FTD instance are deployed in HA)(FTD version 6.5.0.115)

We have Firepower 4115 running 2.7(1.106)(2*4115 , 6 FTD instance are deployed in HA)(FTD version 6.5.0.115).

 

Please help any documents which contains upgrade procedure for FTD's. 

 

I think, I have to upgrade - 

1. FMCv

2. FXOS + FTDs instance

 

 

Yes - FMCv, then FXOS (including firmware) and then FTD instances. Only the firmware is done in the cli. All others are done in the FMC or FCM GUI.

FMC Upgrade: Cisco_Firepower_Mgmt_Center_Upgrade-6.6.4-59.sh.REL.tar
https://software.cisco.com/download/home/286259687/type/286271056/release/6.6.4

FX-OS image for Firepower: fxos-k9.2.10.1.159.SPA
https://software.cisco.com/download/home/286306179/type/286287263/release/2.10.1.159

Also install the latest firmware to address a recent Field Notice:

https://www.cisco.com/c/en/us/support/docs/field-notices/720/fn72077.html

Firmware image v. 1.0.19 for Firepower 4000 Series.
fxos-k9-fpr4k-firmware.1.0.19.SPA

You upload it via FCM (it won't appear in the GUI after uploaded but can be seen in the cli) and then install it via cli.

https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/firmware-upgrade/fxos-firmware-upgrade.html#id_109996

FTD Upgrade: Cisco_FTD_SSP_Upgrade-6.6.4-59.sh.REL.tar
https://software.cisco.com/download/home/286306179/type/286306337/release/6.6.4

Review Cisco Networking for a $25 gift card