Upgrade ASA zero downtime

I have a pair of ASA-5585-X in a failover active-standby configuration.  They are running the version of the software 8.4.3.  I'm looking to upgrade to 9.1.1.  From the release notes, I understand that, in order to perform an upgrade "no interruption of service", I need to spend the last minor version in a major release for the next major release.  On this basis, my understanding is that the upgrade would require three steps: Version 8.4.5, 9.0.1, 9.1.1.  Is this correct?

Is it possible to go directly from 8.4.3 to 9.1.1 and if so, what are the operational considerations of this upgrade?  My reading of the release notes is not to indicate any special procedure that will be followed either by performing the steps in upgrade.  I suppose there may be a period of service interruption, but I could see not any special requirements to perform a direct upgrade.

All information on the dangers of a direct upgrade are appreciated.  Operational experience (such as "it my network on fire and killed three kittens") much appreciated.  Save the kittens!

Thanks,-Ed

You can directly upgrade from 8.4 (3) 9.1 (1). Yes the release notes recommend to go via 8.4 (5) and 9.0 (1), but it is not really necessary.

Standard procedure. In short:

  • load the image on disk0 two units:
  • change the initialization variable
  • Save the config change
  • the active unit, "failover reload-standby.
  • wait for successful reload and verify the configuration is synced OK. You expect a message that mate version of the software is different.
  • "no failover active" on the active unit
  • Connect to the newly active unit and "failover reload-standby.
  • wait for top-up meet and verify the configuration is synced OK. Both units are now on 9.1 (1).

Optionally, change your main unit to on if that bothers you. I would like to delete the old image once things are OK after a few days. You must also update your ASDM image (and the varaible pointing to it) while you're there.

No kittens are harmed in this process.

Tags: Cisco Security

Similar Questions

  • Upgrade ASA 5510 7.0 (6) 8.2 (5)

    Hi, I want to upgrade my ASA 5510 version 7.0 (6) 8.2 (5).  Read the release notes for 8.2 (5) it is said that the requirement of DRAM is 256 MB unless you have high CPU utilization. He also says that I have to upgrade through the main version of 7.0 (x) to 7.1 (x) and 7.1 (x) to 7.2 (x) and 7.2 (x) to 8.2 (x).  The questions are:

    -My ASA has 256 MB of RAM and 68% of free memory, if you think it will run version 8.2 (5) without any problems?

    -When you make upgrades to major releases, are there considerations concerning the configuration file? Or the versions to use for versions 7.1 and 7.2?

    -Would you recommend doing all the updates in a single window of maintanance?  How long might take?

    -It should not be a problem with 256 MB when you run version 8.2.x unless the SAA is in the way of a high traffic load. However, if you have decided to upgrade to version 8.3 and above all in the future, it requires certainly 1 GB of DRAM on ASA 5510.

    -There are minor changes to configuration of version 7.0 to 8.2. However, if you are running SSL VPN on version 7.x, then the customer should be changed to AnyConnect SSL VPN. However, if you have decided to upgrade to version 8.3 and above, there are major code changes.

    -I do not see a problem of upgrade under a maintenance window. How long it might take is something that I could not answer. It really depends on your environment and as you know with any updates/changes, it can go smoothly or can go horribly wrong, so I can't estimate on your behalf. If all goes well, I can't be too long, basically, download the software at the ASA, change the boot image and reload. And you have to apply to all the release mentioned in the release notes. Normally, I would estimate over shorter time (to give you enough time to restore, just in case it won't).

    I hope this helps.

  • Upgrade asa 8.0.4

    Hello

    We have a problem with a software upgrade to our cisco asa 5510. The version of the asa is 8.0.4.

    It is very strange, remote users can connect through the vpn to the asa, but she tries to make a RDP session fails. Telnet to port 3389 is ok. After downgrading back to asa 7.2.4 version it works again.

    I was looking through the bugs, but can't find anything about it.

    Is - this known issue?

    Best regards

    Jörg

    8.0.4 is an early deployment release - are you surprised?

    I advised that keep the releases of large-scale deployment.

  • Editions

    All,

    I read on the notion of basic redefinition edition available for Oracle 11.2 function. According to my understanding it applicable only to the upgraded application. Can online patchwork (editing concept) function can be used for the upgrade of database?

    for example upgade 11.2 to 12 DB

    or go to 11.2.0.3.0 to 11.2.0.40

    Appreciate help on this.

    Thank you.

    user07118719, your understanding of such function as confirmed by Srini and Aman was correct, then that is what you try to lead you to ask this question?  You try to perform an upgrade of zero downtime?

    - -

    In my opinion, there is no such thing, but you can minimize the failure.  Most of the downtime minimal methodologies involve some type of database replication.  Available tools include Data Guard, Golden Gate, materialized, views triggers of table line, rman restore to a new server with application no cancelled recovery logs archived, etc...

    - -

    HTH - Mark D Powell.

  • Upgrade of the UCS Manager

    Hi all

    I have my UCS Manager and I need to do an upgrade, my question is the VMS, I executed what I need to move them from one device to the other? or I can do the upgrade with no downtime?

    Can someone give me a procedure on how I do this?

    Thank you all.

    Hello

    An upgrade is usually done in two parts:

    (1) infrastructure (IOM, UCSM, fabric interconnection networks)

    (2) blades (BIOS, adapters, CIMC, Controller Board, Flexflash, etc.)

    During upgrade infrastructure, you will need to restart the fabric connects one at a time. When you make one of your two fabrics will be down for about 20 minutes. If you have redundant vNIC/vHBAs in all of your tissues A and B, it should ask only degraded services in the environment. However, a maintenance window is always recommended. When you upgrade the blades, you will need to restart. This is probably where you should move your virtual machines. After that you upgrade the blades make sure you update your OS drivers as well!

    UCS firmware update as follows:

    http://www.Cisco.com/c/en/us/support/servers-unified-computing/UCS-manag...

    Download the firmware:

    https://software.Cisco.com/download/release.html?mdfid=283853163&flowid=...

    Compatibility matrix:

    http://www.Cisco.com/c/en/us/support/servers-unified-computing/unified-c...

    I hope this helps.

    Justin

  • The ASA 5510 IOS version

    Hi.I have a small question. I just got an ASA 5510 7.0 update and on the accompanying CD, there is what is called an ASA 7.2 update but it's only 5 large Mbs while on the SAA is also great 5 Mbs.

    As I've never worked with a firewall which is a valid version of IOS and if so how can I upgrade ASA with her? Thanks in advance for any help.

    Igor

    It is likely that it is a valid version of the image for the SAA. I have an image for 7.1.2 is slightly more than 6 MB and an image for 7.2.2 who is a little more than 8 MB. To upgrade the image you put the image of the CD on a TFTP server TFTP image of the SAA. You may need to configure a start-up on the SAA statement to point to the new image. Save the config and reload. He should come to run the new image.

    HTH

    Rick

  • Options for Non disruptive upgrades

    Apart from two-way replication using Oracle Golden Gate, there are other options that can help make upgrades without interruption (upgrades with no downtime)? This question is for Oracle 12 c.

    Thank you

    Aerts

    Hello

    When you migrate a database, there is no method doesn't provide 0 time solutions.

    Even in two-way replication of golden gate, you will have to do it level by level and when I consider the module by module, module should be reduced to one end OR we will terminate connection, so there are lost connection... But we can expect very close 0 solution to migration of downtime with the Golden Gate

    any other method will be kept more then this downtime...

  • VMware Sphere standard vs. advanced by HA

    Buon giorno, sto leggendo proposed due delle versioni in oggetto, my non mi è chiaro it ventilconvettore di HA gia nella present standard edition utulizzato senza need tolerance advanced e della he vmotion che assicurano very it massimo della sicurezza

    Quello che I like realizzare in departure, e una soluzione a uno storage be server substitutes per i dati snapshot regular ed.

    I manage i tre server substitutes pensando di installare Server distributed virtuali su tutti e tre, e avere tell che in caso di di macchine virtuali face vcenter essere spostati evitando limitando o tramite uno it downtime down

    Quello che non capisco appunto, e is gia soluzione VSphere Standard + Vcenter mi allows di farlo (slab figure in rete vedo che in caso di down the HA only sull'altro) my non mi è chiaro is lo fa automatically, is invece e comunque manuale it downtime al traffico e solo spostamento del server.

    Gestione del fault tolerance e quindi del zero downtime assoluto the lasciare como l'eventuale wants to upgrade e sviluppo del progetto.

    Currently mi interested solo virtualizzare a series of macchine e fare in modo che is TR break how UN virtuali published nothing monitorate e macchine spostate Reed manualmente knew another server.

    By the l'eventuale risposta grazie

    http://www.VMware.com/products/vSphere/buy/editions_comparison.html

    Secondo me if

  • Disable an entry to build the table according to the user input

    Hello

    I'm using labview to perform a mass spectrometer.  I made a program to monitor up to five masses, where it sends mass to mass spec (DAC) and then receives data (analog signal) and the locations / records, it is then repeated for the next four masses before returning to the first.

    I have five controls on the front panel, where the user can enter and then the five masses that they wish to follow.

    My problem is how to disable some of the masses, if I only want to follow masses 1,2,3 or 4 instead of five.  Because obviously, it takes more time to complete each cycle with the masses more.  How can I disable the entries if the user upgrades to zero for example?  Or have a way to control the masses to follow.  Who will stop the five tensions sent through DAC and send only 1,2,3 or 4 depending on what is selected?

    I enclose my vi.

    I don't see a Structure of the event in your vi. It is the best and easiest way to capture the change event and manipulate. Search Help on the Structures of the event and you will find many examples. You need the full version of LabView to have access to the Structure of the event.

  • Best approach to replace the storage of an ASM diskgroup nondisruptive?

    Hi Experts,

    Please advise what the best approach is to replace the storage of ASM diskgroup without downtime, or minimal service interruption?

    Thanks in advance.

    RAJ_KUMAR wrote:

    Hi Experts,

    Please advise what the best approach is to replace the storage of ASM diskgroup without downtime, or minimal service interruption?

    Thanks in advance.

    New drive for fixation to the BONE

    Add the new disk to the selected disk group

    Wait for rebalancing complete

    remove old disk of selected disk group.

    Wait for rebalancing complete

    I just finished the migration to an all new SAN with zero downtime.

  • Remote centres of work and HA?

    Hi all

    I have this situation:

    -A customer has three different work centers. One of them (lets call him he has) shops of LES and the server, and other databases (B and C) are currently working on this issue through TCP/IP connections.

    -The Center has sometimes suffer from power outages to B and C centres are not able to work.

    -Managers want from a centre to work on the data, even if one or two other centers of failure.

    I've had but on Vmware and mix with replication NAS HA. A NAS at each Center so if one goes down, B can take control and continue to work against B NAS. However, I can't figure out how or where to start, and even if the HA is the most apropriated approach... maybe DRS?, do I need any hardware specific storage for this?.

    Explanation: They do need zero downtime, minutes are ok.

    Note 2: What Storage Appliance?

    Thanks in advance.

    ... Center has sometimes suffer from power outages...

    In order to clarify. Are these planned interruptions or not? How time will it last they these downtime? A suitable UPS would be an option?

    If the downtime is unplanned, there is always a risk of data loss or corruption and concerning the features of vSphere you mentioned, it is HA that initiates a restart of a virtual computer crashed. However, to be able to restart the virtual machine, shared storage must be available. If you need a storage solution that ensures synchronization (synchronous if possible). Most storage vendors main to provide such a solution. With most of the solutions you must activate the mirror, he can access, which may not work with HA. There are also other solotions as left (now HP P4000) that provide a failover to transparaent.

    According to your needs, SLA and your budget, you must decide what will be the solution that suits you best.

    André

  • Provide fault tolerant for a small business

    Here's what I want to do:

    The place of customers, I want to have a host, with a virtual machine running SBS 2008 server with Exchange 2007. I want to create a site to site VPN to a remote location where a second host. I want this second host to be passive and have a VM to exact date of the SBS server and serve as a backup to provide the company with zero downtime in the case of a hardware failure. Also in the case of a power outage to customers, the server at the remote location will always receive emails, so no emails are lost.

    I need to know the components of VMware, I need this and the requirements of bandwidth for the WAN connection on the two sites of archives.

    Thank you all the entries are greatly appreciated.

    It isn't anytyhing in a VMware product that would give you directly to continuous availability through a WAN. There are products like Neverfail http://neverfailgroup.com/.

  • Cluster of Noob absolute questioning

    I put VmWare ESX 3.5 server in place. It currently houses 3 servers windows 2003 K (13:00, 1 trade, 1 Citrix). We have just experienced a situation where this server crashed (power pulled the MB) and we have been down for a week. It is a small handful of users (total 20-30 user). If we ask what would be the best way to go to try to get zero downtime for these virtual servers. There has been discussions about adding a SAN and another virtual server with a kind of failover cluster. Being not very familure with VMware, I wam wonder if is no longer kill him for this small of a set to the top.

    So I was wondering if anyone had any suggestions or ideas for the best way get times of reliable operation with minimal to zero downtime.

    Welcome to the Forums - take a look at VMware HA - requires at least 2 ESX host and SAN/NAS device, it will allow an automatic restart of virtual machines that was running on an ESX Server that crashes - they should come back online with 2-5 minutes

    If you find this or any other answer useful please consider awarding points marking the answer correct or useful

  • Update Firmware on vSphere MD3000i

    Hello

    We currently have several without MD3000i which must obtain an updated firmware updated (RAID controller and physical disk firmware) for the latest versions (07352261 for the RAID controller).  Those without are connected to the PowerEdge 2950 runs the last environment vSphere.  I did a little research and from what I understand, the key is really:

    -Back up all your data.

    -Stop the vSphere physical servers.

    -Use the crossgeneration utility provided to upgrade the San.

    Does anyone have any experience or advice related to the MD3000i San upgrade? Advice would be appreciated.  Thanks in advance.

    Gene

    It depends on if you want to continue your virtual machines to be connected, so plan accordingly, you will have a good upgrade without interruption of service, I've done was 15 x 400 GB MD3000i firmware upgrade to version xx 7. but a cheap shared storage of NFS/iSCSI using OpenFiler to promote and use Storage VMotion to move VMS as intermediate destination.  Once the upgrade complete, migrate their return and delete or recycle your Openfiler or keep it low key development servers.  You can move to a local disk if you want to just for temporary, but can not do any VMotion/HA if.  You can use the demo as network SANmelody or left virtual storage to improve performance and reason for portability.  Otherwise, if you drive to power that run them just a quick upgrade with scheduled downtime should be fine.  Good luck.

    If you found this information useful, please consider awarding points to 'Correct' or 'useful '. Thank you!!!

    Kind regards

    Stefan Nguyen

    VMware vExpert 2009

    iGeek Systems Inc.

    VMware, Citrix, Microsoft Consultant

  • Can we patch Applications (ADPATCH) without interruption using physical standby

    Hello

    Because I know I can physical standby database user to a database upgrade with minimal downtime. Can I use the same with Oracle application fixes using adpatch.

    In other words we can patch application (using Adpatch) without interruption using physical standby.

    Thanks in advance.


    Best regards

    In other words we can patch application (using Adpatch) without interruption using physical standby.

    N °

    Business Continuity for Oracle Applications Release 11i, database release 9i and 10g [ID 216212.1] - Section 4: apply an application Patch
    Business Continuity for Oracle Applications release 12 on the basis of data of exit 10 gr 2 - Single Instance and RAC [ID 452056.1] - 4.4 procedure - Application of Patch E-Business Suite
    Business Continuity for Oracle E-Business release 12 using Oracle 11 g physical Standby Database [ID 1070033.1] - Section 7: Oracle eBusiness Suite interview with Standby Database

    Thank you
    Hussein

Maybe you are looking for