Cisco APIC Installation and ACI Upgrade and Downgrade Guide

PDF

Cisco APIC Installation and ACI Upgrade and Downgrade Guide

Upgrade or downgrade Cisco APIC from release 6.2 or later

Want to summarize with AI?

Log in

Configure Cisco APIC upgrades or downgrades using the enhanced streamlined process available from release 6.2 or later.


Starting with Cisco ACI release 6.2(1), the APIC upgrade process has been enhanced with a streamlined and orchestrated processing compared to the previous upgrade process with each APIC node upgrading semi-individually without a central orchestration point. Optimized APIC reboot process enables faster upgrade experience.

Note

Downgrading Cisco APICs from Cisco APIC 6.2 or newer releases to a release older than 6.2(1) is not supported. See Best practice for downgrade checklists and procedures for details.

The pre-upgrade validation step was also enhanced with the additional rules that can be imported separately, which always provides the latest and greatest rule sets.

In the new process, APIC 1 acts as the central orchestration point of the entire cluster for the upgrade. For this reason, to perform the APIC cluster upgrade, you must be on the APIC1's user interface.

See ACI Upgrade or Downgrade Architecture section for the details of the upgrade processes behind the scenes.

External Validation Rules

Prior to ACI release 6.2(1), it was recommended for users to manually download and run the python script from ACI Pre-Upgrade Validation Script. This script should be used in addition to, and separately from, the built-in validations performed during the upgrade workflow in the APIC GUI

Starting with ACI release 6.2(1), the upgrade workflow in the APIC GUI can load the additional external rules equivalent to ACI Pre-Upgrade Validation Script and run them along with the built-in rules.

There are two options to load the external rules.

  • Manually download the rule bundle image (a tar ball file) from cisco.com and upload it by following the instructions in Download APIC, APIC CIMC, switch and additional rules for pre-upgrade validation on APICs section. APIC looks for the image during the upgrade workflow.

  • Integrate and fetch the script directly from Intersight.

    During the upgrade workflow, APIC automatically tries to download the rule bundle image (a tar ball file) from Cisco Intersight if the APIC is claimed by Cisco Intersight and has IP reachability. See Cisco APIC and Intersight Device Connector for details about the connectivity to Cisco Intersight.

    You must have the external rule bundle image from either option to proceed with the actual upgrade.

During the pre-upgrade validation step in the APIC upgrade workflow, APIC always attempts to use the Cisco Intersight option first. If it can download the external rules, it compares the version to any other external rules in its local firmware repository and uses the latest version. Using Cisco Intersight is highly recommended, as it ensures your APIC always has the most up-to-date rules without requiring you to manually check cisco.com.

Before you begin

Ensure that you check and follow these guidelines:

Follow these steps to upgrade or downgrade Cisco APIC from release 6.2 or later:

Procedure

1.

Go to the Admin > Firmware section in the APIC user interface.

2.

Select Controllers from the navigation pane.

The Controller & CIMC upgrade tab is pre-selected, which allows you to upgrade components based on your selection.
3.

In the Upgrade Component area, choose either Controller.

4.

To upgrade or downgrade the main firmware, select Regular Upgrade, choose the desired firmware image from the Firmware Image drop-down.

5.

The Step 2 - Validation view appears.

APIC runs the built-in pre-upgrade validations along with the external validation rules. Make sure that all validations are passed or make sure that appropriate actions were performed for the failed validations. If there is a validation that failed with severity Catastrophic, you must fix it to proceed to the next step.

As mentioned in the step above, you can select the external validation rules. External validations are additional checks to your cluster and the rules are curated by your organization. External validation must be authored by your organization, and Cisco APIC only runs external rules.

6.

Click Next to proceed to the installation.

7.

The Step 3 - Installation view appears.

Click Install to start the installation process.

8.

You can monitor the upgrade or downgrade status in the Step 4 - Status view.

  1. From the Step 4 - Status view, you can also monitor the upgrade logs.

  2. To view the upgrade history, click the History tab.

    Note

    You can view the history only for the upgrade or downgrade from Cisco ACI 6.2(1) release and later releases.

All controllers in the cluster are upgraded or downgraded to the target firmware version. The APIC cluster becomes fully fit and operational on the new release.

What to do next

After completion, verify cluster health and review upgrade logs or audit trails for any additional actions or validations.