04-25-2024 12:29 PM
hello
We have a old fire power that I have no idea how to upgrade. The actual device is a Cisco Firepower 2130 Threat Defense (77) Version 7.0.4 . Cisco Adaptive Security Appliance Software Version 9.16(3)18. and we have a FMC that is Cisco Firepower Management Center for VMware v7.0.4. Is the ASA on the actual physical box? I am not understanding what I have to upgrade. Do i have to upgrade the actual fire power itself first and then the FMC?
Solved! Go to Solution.
04-29-2024 10:43 AM
@teamdv6199 the FMC and FTD use different upgrade packages. Upgrade to 7.2.6 to resolve the latest critical bug.
Upgrade the FMCv to 7.2.6 using the image:-
Cisco_Secure_FW_Mgmt_Center_Upgrade-7.2.6-168.sh.REL.tar - https://software.cisco.com/download/home/286259687/type/286271056/release/7.2.6
Upgrade the FTD to FTD 7.2.6 on the 2130 hardware using the image:-
Cisco_FTD_SSP_FP2K_Upgrade-7.2.6-167.sh.REL.tar - https://software.cisco.com/download/home/286312107/type/286306337/release/7.2.6
04-25-2024 12:35 PM
@teamdv6199 no, you must upgrade the FMC before you upgrade the FTD's. Upgrade procedure:-
FYI, 7.2.5 is the current recommended version.
https://software.cisco.com/download/home/286259687/type/286271056/release/7.2.5
https://software.cisco.com/download/home/286312107/type/286306337/release/7.2.5
04-26-2024 01:22 AM
While 7.2.5 is the current Suggest Release ("Gold Star"), I would recommend 7.2.6 due to the recently announced "ArcaneDoor" vulnerabilities.
05-09-2024 02:49 PM - edited 05-09-2024 07:01 PM
7.2.6 has been removed from download. 7.2.7 is now the preferred download if you are running 7.2.x I just upgraded from 7.2.4 to 7.2.7 without any issues for the FMC and FTDs
04-29-2024 09:36 AM
So how do I upgrade the FTD then? from the link you sent me it looks like its just upgrading FMC.
04-29-2024 09:52 AM
Upgrade FMC first. Then upgrade the FTDs (which is done via FMC).
When you upgrade FTD, it will include the built-in components that are referred to as "ASA". Reference: https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/compatibility/threat-defense-compatibility.html#id_67425
04-29-2024 10:34 AM - edited 04-29-2024 10:45 AM
Sorry Marvin I have never updated this before and If it seems like I am asking, stupid questions forgive me. So, once I go to the FMC system > update> and upload the Cisco_Secure_FW_Mgmt_Center_Patch-7.2.5.1-29.sh.REL.tar FROM Software Download - Cisco Systems. Is there another FTD package I need to download? If so is it from the same link?
Also I thought ASA is different from FMC.
04-29-2024 10:43 AM
@teamdv6199 the FMC and FTD use different upgrade packages. Upgrade to 7.2.6 to resolve the latest critical bug.
Upgrade the FMCv to 7.2.6 using the image:-
Cisco_Secure_FW_Mgmt_Center_Upgrade-7.2.6-168.sh.REL.tar - https://software.cisco.com/download/home/286259687/type/286271056/release/7.2.6
Upgrade the FTD to FTD 7.2.6 on the 2130 hardware using the image:-
Cisco_FTD_SSP_FP2K_Upgrade-7.2.6-167.sh.REL.tar - https://software.cisco.com/download/home/286312107/type/286306337/release/7.2.6
05-09-2024 07:02 PM
7.2.6 has been removed from download. 7.2.7 is now the preferred download if you are running 7.2.x I just upgraded from 7.2.4 to 7.2.7 without any issues for the FMC and FTDs
04-29-2024 10:45 AM
From 7.0.4 to 7.2.5.1 you would first go to 7.2.5 and then patch to 7.2.5.1 (or you you just go to 7.2.6) - on FMC.
Once your FMC is upgraded you then add the FTD upgrade files to your FMC and install then on the managed 2130. The 2130 upgrade files can be found here: https://software.cisco.com/download/home/286312107/type/286306337/release/7.2.5
04-29-2024 12:59 PM - edited 04-30-2024 06:46 AM
Thank you I am updating it now!
04-30-2024 07:46 AM - edited 04-30-2024 07:50 AM
I get this now for the FTD. Am I supposed to find the snort version somewhere and update it?
RECOVERY MESSAGE: Snort minimum version required for upgrade: 2.9.20. Device is running: 2.9.18.4. Deploy configurations to the device and try again.
on the FMC it looks like its already on version 2.9.20:
Version 2.9.20.6 GRE (Build 6102)
'''' By Martin Roesch & The Snort Team: http://www.snort.org/contact#team
Copyright (C) 2014-2021 Cisco and/or its affiliates. All rights reserved.
Copyright (C) 1998-2013 Sourcefire, Inc., et al.
Using libpcap version 1.9.1 (with TPACKET_V3)
Using PCRE version: 8.44 2020-02-12
Using ZLIB version: 1.2.11
04-30-2024 11:23 AM
What is the exact current version and target version you are upgrading to for FTD? Table here here: https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/compatibility/threat-defense-compatibility.html#id_67425 says Snort 2.9.18.x would be included in FTD 7.0.x which should be compatible to upgrade to 7.2.x.
05-02-2024 06:52 AM
Thank you Marvin, I think the GUI just needed some time to sync up? I did not do anything, and it let me upgrade the FTD.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide