cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2387
Views
0
Helpful
4
Replies

Will FMC upgrade cause a network interruption with the ASA?

rweir0001
Level 1
Level 1

I'm going to upgrade my FireSIGHT Management Center and ASA to version 6.0.1. During my upgrade to 6.0.0 the longest part was the FMC upgrade which took a few hours. I was thinking of starting the FMC upgrade towards the end of the day to minimize the amount of extra time I have to spend in the office, and then upgrade my ASA after hours. Is there any risk of a network disruption with the ASA while I upgrade the FMC? Because it is a management server I'm assuming not but I don't want to cause a connectivity issue while users are still in the office.

1 Accepted Solution

Accepted Solutions

Veronika Klauzova
Cisco Employee
Cisco Employee

Hello,

during FMC upgrade procedure there is no impact on managed devices. Only disruption will be before upgrade and after, as you have to re-apply your Access control policy bundle before and after each upgrade otherwise upgrade itself would fail if policy is out of date. 

Best regards,

Veronika

View solution in original post

4 Replies 4

Veronika Klauzova
Cisco Employee
Cisco Employee

Hello,

during FMC upgrade procedure there is no impact on managed devices. Only disruption will be before upgrade and after, as you have to re-apply your Access control policy bundle before and after each upgrade otherwise upgrade itself would fail if policy is out of date. 

Best regards,

Veronika

Thanks, Veronika. There wasn't any connectivity issues while the FMC upgraded....but yes, like you said the only disruption is when the ASA itself rebooted during it's upgrade. 

Marvin Rhoads
Hall of Fame
Hall of Fame

I'd recommend going all the way to the (al)most current FMC 6.2.0.1 as part of a multi-step upgrade.

You will have to update your managed devices to 6.1 once your FMC is at that level and prior to moving on to 6.2 because FMC 6.2+ can only manage devices as far back as 6.1.

(6.2.1 is the absolute latest right now but currently only for FMC and 2100 series with FTD, but we expect 6.2.2 in a month or so to catch up the rest of the device types.)

Marvin,

Yes, that's my goal but between the FMC and two ASAs configured for redundancy the upgrades take several hours so I'm upgrading incrementally. 

Review Cisco Networking for a $25 gift card