Guest

Cisco Email Security Appliance

WSA/ESA Local Upgrade Process

Document ID: 117804

Updated: Jun 12, 2014

Contributed by Jaki Hasan and Robert Sherwin, Cisco TAC Engineers.

   Print

Introduction

This document describes the process that is used in order to upgrade the Cisco Web Security Appliance (WSA) and the Cisco Email Security Appliance (ESA) locally.

Prerequisites

Requirements

Cisco recommends that you have knowledge of the Cisco WSA and ESA standard (online) upgrade procedures.

Components Used

The information in this document is based on these software versions:

  • AsyncOS Versions 6.0 and later, and Versions 5.7 and earlier

The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, make sure that you understand the potential impact of any command. 

Background Information

At times, when the network is congested, attempts to upgrade the WSA or the ESA via the Internet might fail. For example, if there is an available upgrade for an appliance, the AsyncOS downloads it and installs it simultaneously. However, if the network is congested, the download might hang and the upgrade fails. In scenarios such as these, one available option is to upgrade the WSA or the ESA locally.

Upgrades for Appliances that Run AsyncOS Versions 6.0 and Later

In order to upgrade appliances that run AsyncOS Versions 6.0 and later, you must download the AsyncOS upgrade and then apply it to the appliance.

Download the AsyncOS Upgrade

Complete these steps in order to download the AsyncOS upgrade:

  1. Navigate to the Fetch a Local Upgrade Image page.

  2. Enter the appropriate serial number(s). Separate the serial numbers with commas if there are more than one.

  3. In the Base Release Tag field, enter the current version of the appliance with this format:

    • For the WSA: coeus-x-x-x-xxx (coeus-6-0-0-544, for example)
    • For the ESA: phoebe-x-x-x-xxx (phoebe-6-0-0-544, for example)
  4. Click Fetch Manifest in order to view a list of the possible upgrades for the specified serial number(s).

  5. In order to download the upgrade, click the release package of the version to which you want to upgrade your appliance.

    Note: This package contains the necessary XML file inside of the zip file that is prepared for the serial number(s) that you entered.

  6. Extract the downloaded package on your HTTP server.

  7. Verify that the directory structure is accessible and looks similar to this:

    For the WSA

    asyncos/coeus-6-0-1-006/app/default/1
    asyncos/coeus-6-0-1-006/distroot/default/1
    asyncos/coeus-6-0-1-006/hints/default/1
    asyncos/coeus-6-0-1-006/scannerroot/default/1
    asyncos/coeus-6-0-1-006/upgrade.sh/default/1

    For the ESA

    asyncos/phoebe-6-0-1-006/app/default/1
    asyncos/phoebe-6-0-1-006/distroot/default/1
    asyncos/phoebe-6-0-1-006/hints/default/1
    asyncos/phoebe-6-0-1-006/scannerroot/default/1
    asyncos/phoebe-6-0-1-006/upgrade.sh/default/1

Note: In this example, 6.0.1-006 is the target version. You are not required to browse the directory at your HTTP server.

Upgrade the Appliance

Complete these steps in order to apply the upgrade:

  1. In order to configure the local server, enter the updateconfig > setup command into the CLI.

    Note: Enter the complete path to the XML file. For example, http://localupgrade.server/asyncos/coeus-6-0-1-006.xml or  http://localupgrade.server/asyncos/phoebe-6-0-1-006.xml for the manifest location.

  2. Some changes to the XML file itself are required. The XML file contains references to updates.ironport.com. Replace those references with the IP address of the local server.

  3. Enter the IP address or hostname and the appropriate port from your local HTTP server.

    Note: The directory structure on the local HTTP server must begin with /asyncoslocalupgrade.server:80.

Upgrades for Appliances that Run AsyncOS Versions 5.7 and Earlier

In order to upgrade appliances that run AsyncOS Versions 5.7 and earlier, you must download the AsyncOS upgrade and then apply it to the appliance.

Download the AsyncOS Upgrade

Complete these steps in order to download the AsyncOS upgrade:

  1. Download the appropriate image from the IronPort Upgrades Server and save it on your local server.

    Note: The serial number(s) is required in order to view the available upgrade.

  2. Once the image is downloaded, save the web page from which you downloaded the image as index.html.

  3. Modify the correct link on the saved index.html file so that it points to the location in which the image is saved on the local server.

 

Upgrade the Appliance

Complete these steps in order to apply the upgrade:

  1. In order to configure the local server, enter the updateconfig > setup command into the CLI.

    Note: Enter the complete path to the index.html file. For example, http://localupgrade.server/asyncos/index.html.

  2. Point the WSA or the ESA to the index.html page in order to upgrade.
Updated: Jun 12, 2014
Document ID: 117804