cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
995
Views
0
Helpful
13
Replies

WSA Upgrade from 14.5.0-537 to 15.2.3-007 – What to check before

Zaza1
Level 1
Level 1

Hi Cisco Community,

I'm planning to upgrade our **Cisco Web Security Appliance (WSA)** from **AsyncOS 14.5.0-537** to **15.2.3-007**.

Should anyone tell me the best practices and what to check before the upgrade?

Looking for advice on:
1. Any **critical prerequisites** before upgrading from 14.5 to 15.2?
2. What changes should I expect in **policies or SSL inspection** in 15.2?
3. Do I need to re-join AD or reimport certificates after the upgrade?
4. How long is the typical upgrade + reboot process?

Would appreciate any experience or lessons learned from those who have done a similar upgrade.

Thanks!

13 Replies 13

I haven’t done this specific upgrade but I’ve done MANY up to 14.x, when we moved to Umbrella SIG.

1. Check the release notes for all of the 14.x versions and 15.x versions in between… if the upgrade gui page shows you 15.2, you don’t have to do any upgrades in between.
2. Again, the release notes
3. Not usually. I have had to rejoin AD, but it wasn’t every upgrade…
4. If you download first, the upgrade/reboot is probably ~20 minutes…


balaji.bandi
Hall of Fame
Hall of Fame

1. take backup un encrypted first.

2. If you using SMA, then upgrade SMA first 

3. If you using the you need to change Configuration Manager to 15

4. I believe 14.5 directly check the matrix :

https://www.cisco.com/c/dam/en/us/td/docs/security/security_management/sma/sma_all/web-compatibility/index.html

5. read the release notes and understand the caveats :

https://www.cisco.com/c/en/us/td/docs/security/wsa/wsa-15-2/release-notes/release-notes-for-wsa-15-2.html

6. the rollback should be automatic, in case any issue you need to roleback check is the rollback available, you need to use command line for rollback.

7. Once success upgrade, make sure take back up fresh copy.

 

 

 

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Zaza1
Level 1
Level 1

@balaji.bandi Thank you for the answer!

Yes I'm using SMA and can you tell me please how to upgrade SMA and the best practices for this process?

Thanks in advance!

as i mentioned most of the steps please follow the steps as guided.

One thing not mentioned was, what is the Model of the Device (or appliance) some appliance can not upgrade to 15.X

matrix will help you what SMA version to be before you upgrade WSA to 15.X code

while upgrading in the process, suggest to freeze the changes doing while you complete upgrade SMA and WSA ad using new configuration manager.

All  upgrade process are automate and eligibility of upgrade only version shown when you go to upgrade.

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Zaza1
Level 1
Level 1

@balaji.bandi The model of the WSA is Cisco S695.

S695 seems to be ok for your upgrade again read matrix.

Also check EOL :

https://www.cisco.com/c/en/us/products/collateral/security/web-security-appliance/secure-web-x95-hardware-app-eol.html

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Zaza1
Level 1
Level 1

@balaji.bandi Why I need to check the EOL, what can affect this?

that is guide lines for future use,  since New Model  696 released so.

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

amojarra
Cisco Employee
Cisco Employee

Hello @Zaza1 

technically when we are upgrading you need to check the : 

[1] release notes:

[1-1] What is new : 

For example: In AsyncOS 15.2 and later releases, Smart Software License is mandatory

[1-2] Changes in Behavior 

For Example: After upgrading to 15.2.2-009, you can no longer enable Dynamic Conetent Analysis (DCA) feature from Secure Web Appliance.

[1-3] Known/fixed Issues 

Here are the links to the relevant release notes:

 

[2] If you are managing your WSAs with an SMA, we recommend reviewing the compatibility matrix to ensure seamless integration:

 

[3] If you have integrated the WSA with Cisco ISE, kindly check the compatibility Matrix as well:

https://www.cisco.com/c/en/us/td/docs/security/wsa/ise-matrix/ise-compatability-matrix-for-swa.html

 

 

Spoiler
If you also have a Secure Email Appliance (ESA) in your environment, it is crucial to ensure that the ESA is compatible with your SMA version before proceeding with any upgrades. Compatibility issues between ESA and SMA can lead to unexpected behavior or disruptions.

 

Regards,

Amirhossein Mojarrad

+++++++++++++++++++++++++++++++++++++++++++++++++++

++++     If you find this answer helpful, please rate it as such    ++++

+++++++++++++++++++++++++++++++++++++++++++++++++++

Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++

Zaza1
Level 1
Level 1

Now after the WSA upgrade I have slow performance.

Can somebody tell me why and how to resolve it?

 

Zaza1
Level 1
Level 1

Hello @balaji.bandi ,

I am facing an issue after SMA and WSA upgrade.

Issue is when I want to update Custom Categories on SMA and apply changes, we receive login page for WSA_SANDBOX I appreciate your help on fixing it.

SMA and WSA versions are as below:

SMA M195 version is 16.0.2-088

WSA S695 version is 15.0.0-355

Configuration Manager version is 15.0

amojarra
Cisco Employee
Cisco Employee

@Zaza1 

kindly check this defect please : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq41875

 

Regards,

Amirhossein Mojarrad

+++++++++++++++++++++++++++++++++++++++++++++++++++

++++     If you find this answer helpful, please rate it as such    ++++

+++++++++++++++++++++++++++++++++++++++++++++++++++

 

 

Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++

amojarra
Cisco Employee
Cisco Employee

@Zaza1 for the Slowness issue, 

 

kindly add these performance parameters to the Accesslogs: 

https://www.cisco.com/c/en/us/support/docs/security/secure-web-appliance-virtual/220456-configure-performance-parameter-in-acces.html

 

and open a TAC case, above fields will gives us more visibility on the WSA's internal process time.

 

Regards,

Amirhossein Mojarrad

+++++++++++++++++++++++++++++++++++++++++++++++++++

++++     If you find this answer helpful, please rate it as such    ++++

+++++++++++++++++++++++++++++++++++++++++++++++++++

 

 

Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++