cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1907
Views
5
Helpful
15
Replies

PIX upgrade from 6.3(5) to 7.2(2)

kmkrause2
Level 1
Level 1

I have a pair of 515e devices configured in failover. The system has been working fine, however I tried to upgrade from 6.3(5) to 7.2(2) using Monitor mode, as I have PDM installed.

The problem is that whenever I enter monitor mode and apply an IP address to the inside interface, I have problems keeping a reliable connection to the TFTP server.

From Montior mode I enter the folowing commands:

Interface 1

Address 192.168.10.10

Server 192.168.10.137

At this point, I try to ping the TFTP server at 192.168.10.137 and my results are varied. Return success rate is typically 20-60%. On a rare attempt I can get 100%.

Since this is a failover configuration, I don't want to enter the IP address for this interface that it would normally use while in service, as this IP is now running on the standby PIX. Normally, I would think that there were some network issues happening, however the same network cable, switch port and switch port settings are in use during the upgrade attempt as are in use during production. Is there something different going on with the network connection in monitor mode vs normal mode? During the upgrade attempt, I noticed that the switch port this interface connects to starts getting Receive Drop errors that don't occur while the device is in production.

TIA,

Ken

15 Replies 15

Fred,

You don't have a reading problem. You do, however need to know how cisco documentation is laid out. Take this sentence for example:

"If you are upgrading from a PIX 515 or a PIX 535 with PDM already installed, you must upgrade from monitor mode."

This sentence says nothing about the PIX 515E. The 515 and 515E are two different devices, thus are always mentioned seperatly. Take this sentence for example:

"The PIX Security appliance Version 7.0 runs on PIX 515/515E, PIX 525, and PIX 535, but is not supported on the PIX 501 or PIX 506/506E platforms at this time."

Notice that the 515 and 515E are both mentioned. In the previous quote, only the 515 is mentioned. This is how cisco writes their documents.

Bottom line: you can upgrade a 515E from either basic or monitor mode. I recommend basic because its, well, basic :o)

You will find the upgrade instructions here:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_sw/v_70/pix_upgd/pixupgrd.htm#wp1921265

Please rate if this helps!

Bryan

Review Cisco Networking for a $25 gift card