Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

Bulk FDM-Managed devices upgrade

Want to summarize with AI?

Log in

Learn how to upgrade multiple FDM-managed devices in Security Cloud Control Firewall Management, including reviewing prerequisites, selecting compatible images from the Cisco repository or your own repository, scheduling upgrades, and monitoring upgrade progress.


Before You Begin

Be sure to read through the FDM-Managed Device Upgrade Prerequisites, Firepower Software Upgrade Path, and the Supported Devices, Software, and Hardware supported by Security Cloud Control before you upgrade.

This document covers any requirements and warnings you should know prior to upgrading to your desired version of Firepower software.

Note

You can only bulk upgrade FDM-managed devices if they are all upgrading to the same software version.


Upgrade Bulk FDM-Managed Devices with Images from Security Cloud Control's Repository

Use the following procedure to upgrade multiple FDM-managed devices using a software image that is stored in Security Cloud Control's repository:

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab to locate your devices.

3.

Click the FTD tab.

4.

From the filtered list of devices, select the devices you want to upgrade.

5.

In the Device Actions pane, click Upgrade.

6.

On the Bulk Device Upgrade page, the devices that can be upgraded are presented to you. If any of the devices you chose are not upgradable, Security Cloud Control gives you a link to view the not upgradable devices.

7.

Alternatively, if you want Security Cloud Control to perform the upgrade later, select the Schedule Upgrade check box. Click the field to select a date and time in the future. When you are done, click the Schedule Upgrade button.

8.

In step 1, click Use Security Cloud Control Image Repository to select the software image you want to upgrade to. You are only presented with choices that are compatible with the devices you can upgrade. Click Continue.

9.

In step 2, confirm your choices and decide whether you only want to download the images to your device or copy the images, install them, and reboot the device.

10.

Click Perform Upgrade when you are ready. From the Security Devices page, devices that are upgrading have a "Upgrade in Progress" configuration status.

Warning

If you decide to cancel the upgrades while in progress, click Abort Upgrade from the Upgrade page. If you cancel the upgrades after it has started, Security Cloud Control does not deploy or poll for changes from the devices. Devices do not roll back to the previous configuration after a canceled upgrade, either. This may cause the devices to enter an unhealthy state. If you experience any issues during the upgrade process, contact Cisco TAC.

11.

Look at the notifications tab for the progress of the bulk upgrade action. If you want more information about how the actions in the bulk upgrade job succeeded or failed, click the blue Review link and you will be directed to the Jobs page .

12.

Upgrade the system databases. You must do this step in Firewall Device Manager. See Updating System Databases in Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager, for the version your device is running.


Upgrade Bulk FDM-Managed Devices with Images from your own Repository

Use the following procedure to upgrade multiple FDM-managed devices using a URL protocol to locate a software image:

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab to locate your devices.

3.

Click the FTD tab.

4.

From the filtered list of devices, select the devices you want to upgrade.

5.

In the Device Actions pane, click Upgrade.

6.

On the Bulk Device Upgrade page, the devices that can be upgraded are presented to you. If any of the devices you chose are not upgradable, Security Cloud Control gives you a link to view the not upgradable devices.

7.

Alternatively, if you want Security Cloud Control to perform the upgrade later, select the Schedule Upgrade check box. Click the field to select a date and time in the future. When you are done, click the Schedule Upgrade button.

8.

In step 1, click Specify Image URL to select the software image you want to upgrade to, and click Continue.

9.

In step 2, confirm your choices and decide whether you only want to download the images to your devices or copy the images, install them, and reboot the device.

10.

Click Perform Upgrade when you are ready. From the Security Devices page, devices that are upgrading have a "Upgrade in Progress" configuration status.

Warning

If you decide to cancel the upgrades while in progress, click Abort Upgrade from the Upgrade page. If you cancel the upgrades after it has started, Security Cloud Control does not deploy or poll for changes from the devices and the devices do not roll back to the previous configuration. This may cause the devices to enter an unhealthy state. If you experience any issues during the upgrade process, contact Cisco TAC.

11.

Look at the notifications tab for the progress of the bulk upgrade action. If you want more information about how the actions in the bulk upgrade job succeeded or failed, click the blue Review link and you will be directed to the Jobs page .

12.

Upgrade the system databases. You must do this step in Firewall Device Manager. See "Updating System Databases" in Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager, Version 6.4 in for more information.


Monitor the Bulk Upgrade Process

You can view the progress of a single device that was included in the bulk upgrade by selecting that device on the Security Devices page and clicking the upgrade button. You can also view the progress details by clicking Jobs in the left pane and expanding the bulk operation.

If the upgrade fails at any point, Security Cloud Control displays a message. Security Cloud Control does not automatically restart the upgrade process.