07-23-2025 11:57 PM
Hi Cisco Community,
I'm planning to upgrade our **Cisco Web Security Appliance (WSA)** from **AsyncOS 14.5.0-537** to **15.2.3-007**.
Should anyone tell me the best practices and what to check before the upgrade?
1. Any **critical prerequisites** before upgrading from 14.5 to 15.2?
2. What changes should I expect in **policies or SSL inspection** in 15.2?
3. Do I need to re-join AD or reimport certificates after the upgrade?
4. How long is the typical upgrade + reboot process?
Would appreciate any experience or lessons learned from those who have done a similar upgrade.
Thanks!
07-24-2025 07:02 AM
07-24-2025 07:12 AM
1. take backup un encrypted first.
2. If you using SMA, then upgrade SMA first
3. If you using the you need to change Configuration Manager to 15
4. I believe 14.5 directly check the matrix :
5. read the release notes and understand the caveats :
6. the rollback should be automatic, in case any issue you need to roleback check is the rollback available, you need to use command line for rollback.
7. Once success upgrade, make sure take back up fresh copy.
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
07-25-2025 03:24 AM
@balaji.bandi Thank you for the answer!
Yes I'm using SMA and can you tell me please how to upgrade SMA and the best practices for this process?
Thanks in advance!
07-25-2025 04:11 AM
as i mentioned most of the steps please follow the steps as guided.
One thing not mentioned was, what is the Model of the Device (or appliance) some appliance can not upgrade to 15.X
matrix will help you what SMA version to be before you upgrade WSA to 15.X code
while upgrading in the process, suggest to freeze the changes doing while you complete upgrade SMA and WSA ad using new configuration manager.
All upgrade process are automate and eligibility of upgrade only version shown when you go to upgrade.
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
07-25-2025 04:29 AM
@balaji.bandi The model of the WSA is Cisco S695.
07-25-2025 05:03 AM
S695 seems to be ok for your upgrade again read matrix.
Also check EOL :
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
07-25-2025 06:07 AM
@balaji.bandi Why I need to check the EOL, what can affect this?
07-25-2025 06:15 AM
that is guide lines for future use, since New Model 696 released so.
=====Preenayamo Vasudevam=====
***** Rate All Helpful Responses *****
07-26-2025 08:03 AM
Hello @Zaza1
technically when we are upgrading you need to check the :
[1] release notes:
[1-1] What is new :
For example: In AsyncOS 15.2 and later releases, Smart Software License is mandatory
[1-2] Changes in Behavior
For Example: After upgrading to 15.2.2-009, you can no longer enable Dynamic Conetent Analysis (DCA) feature from Secure Web Appliance.
[1-3] Known/fixed Issues
Here are the links to the relevant release notes:
[2] If you are managing your WSAs with an SMA, we recommend reviewing the compatibility matrix to ensure seamless integration:
[3] If you have integrated the WSA with Cisco ISE, kindly check the compatibility Matrix as well:
https://www.cisco.com/c/en/us/td/docs/security/wsa/ise-matrix/ise-compatability-matrix-for-swa.html
Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++
07-28-2025 12:22 AM
Now after the WSA upgrade I have slow performance.
Can somebody tell me why and how to resolve it?
07-28-2025 04:13 AM - edited 07-28-2025 06:15 AM
Hello @balaji.bandi ,
I am facing an issue after SMA and WSA upgrade.
Issue is when I want to update Custom Categories on SMA and apply changes, we receive login page for WSA_SANDBOX I appreciate your help on fixing it.
SMA and WSA versions are as below:
SMA M195 version is 16.0.2-088
WSA S695 version is 15.0.0-355
Configuration Manager version is 15.0
07-28-2025 06:58 AM
kindly check this defect please : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq41875
Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++
07-28-2025 07:00 AM
@Zaza1 for the Slowness issue,
kindly add these performance parameters to the Accesslogs:
and open a TAC case, above fields will gives us more visibility on the WSA's internal process time.
Regards,
Amirhossein Mojarrad
+++++++++++++++++++++++++++++++++++++++++++++++++++
++++ If you find this answer helpful, please rate it as such ++++
+++++++++++++++++++++++++++++++++++++++++++++++++++
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide