Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

Upgrade a Single FDM-Managed Device

Want to summarize with AI?

Log in

Learn how to upgrade a single FDM-managed device in Security Cloud Control Firewall Managementusing images from the Cisco repository or your own repository, schedule or perform the upgrade, and monitor upgrade progress.


Before You Begin

Be sure to read through the FTD Upgrade Prerequisites, Firepower Software Upgrade Path, and the Supported Devices, Software, and Hardware by Security Cloud Control before you upgrade.

This document covers any requirements and warnings you should know prior to upgrading to your desired version of Firepower software.


Upgrade A Single FDM-Managed Device with Images from Security Cloud Control's Repository

Use the following procedure to upgrade a standalone FDM-managed device using a software image that is stored in Security Cloud Control's repository:

Procedure

1.

In the navigation bar, click Security Devices.

2.

Click the Devices tab to locate your device..

3.

Click the FTD tab.

4.

Select the device you want to upgrade.

5.

In the Device Actions pane, click Upgrade.

6.

In step 1, click Use Security Cloud Control Image Repository to select the software image you want to upgrade to, and click Continue. You are only presented with choices that are compatible with the device you can upgrade.

7.

In step 2, confirm your choices and decide whether you only want to download the images to your device or copy the images, install them, and reboot the device.

8.

Click Perform Upgrade when you are ready. From the Security Devices page, devices that are upgrading have a "Upgrade in Progress" configuration status.

Warning

If you decide to cancel the upgrade while it is in progress, click Abort Upgrade from the Upgrade page. If you cancel the upgrade after it has started, Security Cloud Control does not deploy or check for changes from the device and the device does not roll back to the previous configuration. This may cause the device to enter an unhealthy state. If you experience any issues during the upgrade process, contact Cisco TAC.

9.

Alternatively, if you want Security Cloud Control to perform the upgrade later, select the Schedule Upgrade check box. Click the field to select a date and time in the future. When you are done, click the Schedule Upgrade button.

10.

Look at the notifications tab for the progress of the bulk upgrade action. If you want more information about how the actions in the bulk upgrade job succeeded or failed, click the blue Review link and you will be directed to the Jobs page .

11.

Upgrade the system databases. You must do this step in Firewall Device Manager. See "Updating System Databases" in Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager, Version 6.4in for more information.


Upgrade a Single FDM-Managed Device with Images from your own Repository

Use the following procedure to upgrade a standalone FDM-managed device using a URL protocol to locate a software image:

Procedure

1.

In the left pane, click Security Devices.

2.

Click the Devices tab to locate your device..

3.

Click the FTD tab.

4.

Select the device you want to upgrade.

5.

In the Device Actions pane, click Upgrade.

6.

In step 1, click Specify Image URL to select the software image you want to upgrade to, and click Continue. You are only presented with choices that are compatible with the device you can upgrade.

7.

In step 2, confirm your choices and decide whether you only want to download the images to your device or copy the images, install them, and reboot the device.

8.

Click Perform Upgrade when you are ready. From the Security Devices page, devices that are upgrading have a "Upgrade in Progress" configuration status.

Warning

If you decide to cancel the upgrade while it is in progress, click Abort Upgrade from the Upgrade page. If you cancel the upgrade after it has started, Security Cloud Control does not deploy or check for changes from the device and the device does not roll back to the previous configuration. This may cause the device to enter an unhealthy state. If you experience any issues during the upgrade process, contact Cisco TAC.

9.

Alternatively, if you want Security Cloud Control to perform the upgrade later, select the Schedule Upgrade check box. Click the field to select a date and time in the future. When you are done, click the Schedule Upgrade button.

10.

Look at the notifications tab for the progress of the bulk upgrade action. If you want more information about how the actions in the bulk upgrade job succeeded or failed, click the blue Review link and you will be directed to the Jobs page .

11.

Upgrade the system databases. You must do this step in Firewall Device Manager. See Updating System Databases in Cisco Firepower Threat Defense Configuration Guide for Firepower Device Manager, Version 6.4 for more information.


Monitor the Upgrade Process

You can view the progress of your single device by selecting that device on the Security Devices page and clicking the upgrade button. Security Cloud Control takes you to the Device Upgrade page for that device.

If the upgrade fails at any point, Security Cloud Control displays a message. Security Cloud Control does not automatically restart the upgrade process.

Warning

Upgrading devices that have self-signed certificates may experience issues; see New Certificate Detected for more information