cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2684
Views
0
Helpful
13
Replies

Upgrade FWSM from 3.1(4) to 4.0(10)

Hi all:

I have to upgrade a FWSM from 3.1 to 4.0(10). I have some doubts to this respect:

1. May I do it directly or I need an intermediate jump before (let's say 4.0(0))?.

2. Once I upload the new version and reboot the appliance, it will detect the newest version and boot with it? (in that moment there will be 2 versions on the fw), I don't see the boot command like routers to specify.


2. If the appliance behaviour is not the expected once done the upgrade (it's a critical firewall), how can I back to the previous scenario?. Of course, I'll do a configuration backup but the commands nomenclature from 3.1 to 4.0. Do I must load the previous config file and erase the new version from flash?.

Thanks a lot,

Francisco

2 Accepted Solutions

Accepted Solutions

For the questions to pkampana, you can find 3.1.4 here http://www.cisco.com/cgi-bin/tablebuild.pl/cat6000-fwsm

For the question to kusankar, when you boot to a new partition you will need to copy the config since each partition has its own config. So, the 3.1 config will be converted to 4.0 and each of your partition will have the right version with the corresponding config.

I hope it helps.

PK

View solution in original post

Yes,

I would make sure both cf:4 and cf:5 have the same 3.1.4 code. Your config which is in version 3.1.4 will be in both cf:4 and cf:5. Either copy and paste or tftp the file.

The you upgrade either cf:4 or cf:5 to 4.x and when that partition loads 4.x it will automatically convert the config to 4.x

when you boot cf:4 - you will have 3.x image and 3.x config

when you boot cf:5 - you will have 4.x image and  4.x config

-KS

View solution in original post

13 Replies 13

francisco_1
Level 7
Level 7

Yes, you can upgrade from 3.1 to 4.0.

Do you have a failover pair?

Also to downgrade, you can  save a copy of your 3.x configuration if you later want to downgrade.

http://www.cisco.com/en/US/docs/security/fwsm/fwsm31/configuration/guide/swcnfg_f.html#wp1044236http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/release/notes/fwsmrn40.html#wp161551

Ok, thanks. Yes there is a failover pair. I have already read that part and the config guide 4.0 but I dont understand how exactly to do the downgrade. Once I copy the new version, the old one is erased or not. If not, the downgrade steps are to load the 3.x configuration and erase the 4.0 version?

There is a procedure in the url below on how to upgrade failover pairs..

See http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/swcnfg_f.html#wp1042136

I've already read all relationed about upgrading/downgrading FWSM on that document. After to do it, I don't have clear the question 2 and 3 from my first post.

Regards

2. There is only one image stored in flash, when you copy the new one you can only boot to that one.

You can save the 3.x config in your flash and if you go to 4.0 and there are problems you can revert back to 3.x and just copy the save config from 3.2 to the running config.

I hope it helps.

PK

There are 2 application partitions in the blade. cf:4 and cf:5 are the application partitions on the FWSM.

Some people load 4.x in one and 3.x in the other. So, you can have both codes on the same blade.

You just have to issue the command

hw-module module mod_num reset cf:4

or

hw-module module mod_num reset cf:5

to boot into which ever image you want to.

http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/swcnfg_f.html#wp1048848

-KS

pkampana, if there are problems with the new version, how can I to load the 3.1(4) version again?, it's not available on downloads section. Does it exist any way to save it before upgrading?.

kusankar, I know about partitions on FWSM but I dont have clear the next, once loaded the new version on cf:5 partition, how can I load the configuration stored on cf:4 partition, as well, the commands on 3.1(4) are differents on 4.1(10).

Thanks a lot for your support

For the questions to pkampana, you can find 3.1.4 here http://www.cisco.com/cgi-bin/tablebuild.pl/cat6000-fwsm

For the question to kusankar, when you boot to a new partition you will need to copy the config since each partition has its own config. So, the 3.1 config will be converted to 4.0 and each of your partition will have the right version with the corresponding config.

I hope it helps.

PK

Thanks for the link kampana. The only doubt I have is...imagine I reload the FWSM with cf:5 partition and load on it the new version, the next step is to paste the config, how could I do it?, from the flash?, from a TFTP/FTP/HTTP server?.

Thanks so much,

Francisco

Yes,

I would make sure both cf:4 and cf:5 have the same 3.1.4 code. Your config which is in version 3.1.4 will be in both cf:4 and cf:5. Either copy and paste or tftp the file.

The you upgrade either cf:4 or cf:5 to 4.x and when that partition loads 4.x it will automatically convert the config to 4.x

when you boot cf:4 - you will have 3.x image and 3.x config

when you boot cf:5 - you will have 4.x image and  4.x config

-KS

All is clear now.

Thanks for your attention,

Francisco

I havent been looking at a fwsm irl for a while so sorry for a perhaps stupid question...

Bit, is cf:3 and cf:4 two different compact flash-cards on the module? In that case, can I prepare the config by (during uptime) remove the cf-cards and manipulate/change the boot files and then re-insert them? And then during maintenance-time just reboot them?

If so, can I swap between 3.x-code (and its corresponding config) on one cf-card and 4.x-code (and itś config) on another card by swapping the cards and do a reboot?

I guess these cf-cards are plain fat32?

Or are they all internal on-board so they are impossible to reach without ejecting the fwsm-module from the chassi?

Br Jimmy

Jimmy,

If the flash goes bad, we can't even RMA just the flash. We RMA the entire blade.

So, what you are thinking to do is not possible.

-KS

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card