06-04-2020 01:47 AM
Hello, after trying to upgrade ftd 2130 from version 6.2.2 to 6.3.0 in a pair of high availability, one device was successfully updated, the second showed an error.
entries from the update log on a failed device:
admin@firepower:/ngfw/var/log/sf/Cisco_FTD_SSP_FP2K_Upgrade-6.3.0$ more status.log
state:running
ui:Upgrade has begun.
ui:[ 1%] Running script 000_start/000_check_update.sh...
ui:[ 2%] Running script 000_start/100_start_messages.sh...
ui:[ 3%] Running script 000_start/105_check_model_number.sh...
ui:[ 4%] Running script 000_start/106_check_HA_sync.pl...
ui:[ 4%] Running script 000_start/107_version_check.sh...
ui:[ 5%] Running script 000_start/109_check_HA_MDC_status.pl...
ui:[ 7%] Running script 000_start/113_EO_integrity_check.pl...
ui:[ 7%] Fatal error: Error running script 000_start/113_EO_integrity_check.pl. For more details see /ngfw/var/log/sf/Cisco_FTD_SSP_FP2K_Upgrade-6.3.0/000_start/113_EO_integrity_check.pl.log on the devic
e being upgraded.
At the end of the log 113_EO_integrity_check.pl.log entry:
Total errors: 1
EOIC failed
One error was found in the text of the log 113_EO_integrity_check.pl.log:
Checking type: CustomServiceDecoderModule
Checking 972dd32e-81f9-46a4-ac9a-c5a98347ba33
ERROR found!
Before updating, the device was checked install_update.pl --detach --readiness-check /var/sf/updates/upgrade_package_name:
admin@firepower:/ngfw/var/log/sf/Cisco_FTD_SSP_FP2K_Upgrade-6.3.0$ more status.log.202005290651
state:running
ui:Upgrade has begun.
ui:[ 0%] Running script 000_start/000_check_platform_support.sh...
ui:[ 3%] Running script 000_start/000_check_sign_type.sh...
ui:[ 7%] Running script 000_start/100_start_messages.sh...
ui:[10%] Running script 000_start/101_run_pruning.pl...
ui:[14%] Running script 000_start/102_check_sru_install_running.pl...
ui:[17%] Running script 000_start/105_check_model_number.sh...
ui:[21%] Running script 000_start/106_check_HA_updates.pl...
ui:[24%] Running script 000_start/107_version_check.sh...
ui:[28%] Running script 000_start/108_check_sensors_ver.pl...
ui:[31%] Running script 000_start/109_check_HA_MDC_status.pl...
ui:[34%] Running script 000_start/110_DB_integrity_check.sh...
ui:[38%] Running script 000_start/111_FS_integrity_check.sh...
ui:[41%] Running script 000_start/112_CF_check.sh...
ui:[45%] Running script 000_start/113_EO_integrity_check.pl...
ui:[48%] Running script 000_start/250_check_system_files.sh...
ui:[52%] Running script 000_start/410_check_disk_space.sh...
ui:[55%] Running script 200_pre/001_check_reg.pl...
ui:[59%] Running script 200_pre/002_check_mounts.sh...
ui:[62%] Running script 200_pre/003_check_health.sh...
ui:[66%] Running script 200_pre/005_check_manager.pl...
ui:[69%] Running script 200_pre/006_check_snort.sh...
ui:[72%] Running script 200_pre/007_check_sru_install.sh...
ui:[76%] Running script 200_pre/009_check_snort_preproc.sh...
ui:[79%] Running script 200_pre/011_check_self.sh...
ui:[83%] Running script 200_pre/015_verify_rpm.sh...
ui:[86%] Running script 200_pre/100_log_version.sh...
ui:[90%] Readiness Check completed successfully.
ui:Upgrade has completed.
state:finished
What should be our next steps for a successful update?
Solved! Go to Solution.
06-04-2020 06:19 AM
Since your production environment is degraded you might want to raise your TAC case priority to P2. That will get you quicker assistance and, if necessary, requeue to an available engineer.
06-15-2020 10:54 PM
06-04-2020 04:48 AM
I'd recommend opening a TAC case. There could be file or database corruption on the failed unit.
06-04-2020 05:43 AM
06-04-2020 06:19 AM
Since your production environment is degraded you might want to raise your TAC case priority to P2. That will get you quicker assistance and, if necessary, requeue to an available engineer.
06-04-2020 07:44 AM
06-05-2020 05:11 AM
06-15-2020 10:54 PM
01-25-2021 01:42 AM
Hello for everybody.
Can you share your guide or describe how did you update the software on your HA 2130? We are going to try to update firmware from 6.4.0 to 6.6.1 on HA Firepower 1140. But on youtube and cisco.com i found only instructions for updating 4100/9300 devices... If i understood correctly, ftd 1000 series is the same like ftd 2100.
01-25-2021 05:11 AM
Hi! Im updated my ftd device through FMC:
01-25-2021 07:14 AM
Devices were updated in this order:
1) update secondary ftd
2) make updated secondary device active
3) update the remaining device
or simultaneously?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide