cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1748
Views
10
Helpful
4
Replies

Upgrade FMC to 6.7, what will happen to 6.2.3 FTD devices?

mhmservice
Level 1
Level 1

Hi

I want to upgrade our FMC to 6.7 to upgrade our DC FTDs to 6.7 leverage the new IPSEC VTI functionality which was sorely missing,

However, i've found that FTD 6.2.3 is no longer supported to be managed by FMC 6.7. We have 30+ devices which are on 6.2.3 and cannot be upgraded further.

If I upgrade our FMC to 6.7, what will happen, will they get disconnected?

Thanks

4 Replies 4

Hi @mhmservice 

Well the FMC 6.7 release notes states "Version 6.7.x FMC can manage Version 6.3.0 through 6.7.x devices." so one can imagine that yes FTD's running version 6.2.3 or older will be disconnected and therefore no longer manageable from FMC 6.7

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/compatibility.html

Anthony Hove
Level 1
Level 1

You need to make sure the FTD are on version 6.2.3 then upgrade your FMC from version 6.2.3 to 6.6.x which is the supported direct upgrade.

FMC 6.6.x can manage the FTD 6.2.3 but you will need to upgrade the FTD to same version as FMC in this case 6.6.x which is managed by FMC 6.7.x

When you upgrade to cisco FMC 6.7.x you will still be able to manage the FTD 6.6.x devices.
note: If you upgrade the FMC without upgrading the FTD you will lose management capabilities to the devices running FTD 6.2.3 version

If the FMC is managing any 6.2x devices it simply won't allow the upgrade until you either upgrade the FTDs/FirePOWER services modules to 6.3+ or remove the devices from FMC.  I tried the other day and as I have a couple of ASA5506's with FirePOWER services 6.2.3x it just stopped when checking prerequisites and wouldn't allow the upgrade.

Andy

harmesh88
Level 1
Level 1

Hi, 

 

You need to upgrade FTD with Compatible version and then only need to upgrade FMC .

 

I would like to request you to follow  cisco recommendation . If you are not getting downtime for FTD you need to wait but please upgrade both device and then leverage latest feature of 6.7 version.

 

Find below URL for your reference .which having all information .

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html

 

Search   .Can Manage: Device Version

 

I hope you can understand .

 

 

Review Cisco Networking for a $25 gift card