About Upgrade Paths: Can I Upgrade?
Your upgrade path is a detailed plan for what you will upgrade and when. In general, you upgrade the Firepower Management Center, then its managed devices. However, in some cases you may need to upgrade devices first. If you have assessed your deployment—that is, you know what you have and what you want—you are ready to build your upgrade path.
![]() Tip |
Upgrade paths that require intermediate versions can be time consuming. Especially in larger deployments where you must alternate FMC and device upgrades, consider reimaging older devices instead of upgrading. First, remove the devices from the FMC. Then, upgrade the FMC, reimage the devices, and re-add them to the FMC. |
Answer 'Yes' to Two Important Questions
You must answer 'yes' to both of these questions, every time you upgrade either an FMC or a device:
If the answer to either question is 'no,' your upgrade path is invalid.
Is Direct Upgrade Possible?
You can often upgrade from several versions back. However, if you are far "behind," you may require intermediate upgrades or strategic reimaging. These tables summarize upgrade capabilites for Firepower Management Centers and their managed devices. For more detailed upgrade paths for each appliance type, see the upgrade chapters: Upgrade Firepower Appliances.
![]() Note |
Patches change the fourth digit only. For example, you must be running Version 6.4.0 to patch to Version 6.4.0.1. You cannot jump directly to a patch level from any earlier major or maintenance release. |
Direct Upgrades from Version 6.2.3 through 6.6.0
This table summarizes valid upgrade targets if you are currently running Version 6.2.3 or later.
Current Version |
Target Version: Direct Upgrade Supported |
||||
---|---|---|---|---|---|
to 6.7.0/6.7.x |
6.6.0/6.6.x |
6.5.0 |
6.4.0 |
6.3.0 |
|
from 6.6.0/6.6.x |
YES |
— |
— |
— |
— |
6.5.0 |
YES |
YES |
— |
— |
— |
6.4.0 |
YES |
YES |
YES |
— |
— |
6.3.0 |
YES |
YES |
YES |
YES |
— |
6.2.3 |
— |
YES |
YES |
YES |
YES |
Direct Upgrades from Version 5.4 through 6.2.2
This table summarizes valid upgrade targets if you are currently running Version 5.4 through 6.2.2.
Current Version |
Target Version: Direct Upgrade Supported |
||||||||
---|---|---|---|---|---|---|---|---|---|
to 6.4.0 |
6.3.0 |
6.2.3 |
6.2.2 |
6.2.1 |
6.2.0 |
6.1.0 |
6.0.1 |
6.0.0 |
|
from 6.2.2 |
YES |
YES |
YES |
— |
— |
— |
— |
— |
— |
6.2.1 |
YES |
YES |
YES |
YES |
— |
— |
— |
— |
— |
6.2.0 |
YES |
YES |
YES |
YES |
— |
— |
— |
— |
— |
6.1.0 |
YES † |
YES † |
YES |
— |
— |
YES |
— |
— |
— |
6.0.1 |
— |
— |
— |
— |
— |
— |
YES |
— |
— |
6.0.0 |
— |
— |
— |
— |
— |
— |
— |
YES |
— |
5.4.x |
— |
— |
— |
— |
— |
— |
— |
— |
YES * |
Direct Upgrades by Minimum Version to Upgrade
To put it another way, to directly upgrade to the target version in the left column, you must be running at least the version in the right column.
Target Version |
Minimum Current Version for Direct Upgrade |
---|---|
6.7.0 or any 6.7.x maintenance release |
6.3.0 |
6.6.0 or any 6.6.x maintenance release |
6.2.3 |
6.5.0 |
6.2.3 |
6.4.0 |
6.1.0 † |
6.3.0 |
6.1.0 † |
6.2.3 |
6.1.0 |
6.2.2 |
6.2.0 |
6.2.1 |
Upgrades to Version 6.2.1 are not supported. |
6.2.0 |
6.1.0 |
6.1.0 |
6.0.1 |
6.0.1 |
6.0.0 |
6.0.0 |
5.4.0.2 or 5.4.1.1 |
* You must be running at least Version 5.4.0.2/5.4.1.1 to upgrade to Version 6.0.
† Due to operating system incompatibilies, you cannot upgrade directly from Version 6.1 → 6.4 on a Firepower 4100/9300 series device. For similar reasons, we recommend that you not upgrade from Version 6.1 → 6.3. If you are running Version 6.1, we recommend upgrading to Version 6.2.3 on FXOS 2.3.1, and proceeding from there.
Can I Maintain FMC-Device Version Compatibility?
A Firepower Management Center must run the same or newer version as its managed devices. This means:
-
You can manage older devices with a newer FMC, usually a few major versions back.
For example, a Version 6.7.0 FMC can manage a Version 6.3.0 device.
-
You cannot upgrade a device past the FMC.
Before you upgrade an FMC, make sure the upgraded FMC will be able to manage its current devices. For example, a Version 6.7.1 FMC could manage a Version 6.7.0 device, but not a Version 6.7.2 device.
Below, we list FMC versions and the devices they can manage. Find your current version in the first column, then read across to determine which devices you can manage. Remember, within a major version, the FMC must be running the same or newer maintenance (third-digit) release as its managed devices.
FMC Version |
Can Manage: Device Version |
|||||||||
---|---|---|---|---|---|---|---|---|---|---|
6.7.x |
6.6.x |
6.5.0 |
6.4.0 |
6.3.0 |
6.2.3 |
6.2.2 |
6.2.1 |
6.2.0 |
6.1.0 |
|
6.7.x |
YES |
YES |
YES |
YES |
YES |
— |
— |
— |
— |
— |
6.6.x |
— |
YES |
YES |
YES |
YES |
YES |
— |
— |
— |
— |
6.5.0 |
— |
— |
YES |
YES |
YES |
YES |
— |
— |
— |
— |
6.4.0 |
— |
— |
— |
YES |
YES |
YES |
YES |
YES |
YES |
YES |
6.3.0 |
— |
— |
— |
— |
YES |
YES |
YES |
YES |
YES |
YES |
6.2.3 |
— |
— |
— |
— |
— |
YES |
YES |
YES |
YES |
YES |
FMC Version |
Can Manage: Device Version |
|||||||
---|---|---|---|---|---|---|---|---|
6.2.2 |
6.2.1 |
6.2.0 |
6.1.0 |
6.0.1 |
6.0.0 |
5.4.1 |
5.4.0 |
|
6.2.2 |
YES |
YES |
YES |
YES |
— |
— |
— |
— |
6.2.1 |
— |
YES |
YES |
YES |
— |
— |
— |
— |
6.2.0 |
— |
— |
YES |
YES |
— |
— |
— |
— |
6.1.0 |
— |
— |
— |
YES |
YES |
YES |
YES * |
YES * |
6.0.1 |
— |
— |
— |
— |
YES |
YES |
YES * |
YES * |
6.0.0 |
— |
— |
— |
— |
— |
YES |
YES * |
YES * |
5.4.1 |
— |
— |
— |
— |
— |
— |
YES |
YES |
5.4.0 |
— |
— |
— |
— |
— |
— |
— |
YES |
* A device must be running at least Version 5.4.0.2/5.4.1.1 to be managed by a Version 6.0, 6.0.1, or 6.1 FMC.
Note that technically you can manage a patched device (fourth-digit release) with an unpatched FMC. However, we strongly recommend against it. You should always update your entire deployment. New features and resolved issues often require the latest release on both the FMC and its managed devices.
Where Do I Begin?
In most cases, you will upgrade the FMC first. You should upgrade as far as possible while still being able to maintain FMC-device compatibility. However, if the devices are too old, your first step is to upgrade the devices to the same major version as the FMC.
If you still do not know where to begin, refer to your deployment assessment and find your current FMC-device version combination below. These recommendations take into account direct upgrade capability as well as FMC-device compatibility.
This table assumes you want to upgrade to the latest major/maintenance release, which is currently Version 6.7.0/6.7.x.
Your Current Deployment |
Recommended First Step |
||
---|---|---|---|
FMC |
Devices |
Upgrade |
To |
6.7.x |
6.3.0 through 6.7.x |
FMC |
Any later 6.7.x maintenance release. |
6.6.x |
6.3.0 through 6.6.x |
FMC |
6.7.x |
6.2.3 |
Devices |
6.6.x |
|
6.5.0 |
6.3.0 through 6.5.0 |
FMC |
6.7.x |
6.2.3 |
Devices |
6.5.0 |
|
6.4.0 |
6.3.0 through 6.4.0 |
FMC |
6.7.x |
6.1.0 through 6.2.3 |
Devices |
6.4.0 |
|
6.3.0 |
6.3.0 |
FMC |
6.7.x |
6.1.0 through 6.2.3 |
Devices |
6.3.0 |
|
6.2.3 |
6.2.3 |
FMC |
6.6.x |
6.1.0 through 6.2.2 |
Devices |
6.2.3 |
|
6.2.2 |
6.1.0 through 6.2.2 |
FMC |
6.4.0 |
6.2.1 |
6.1.0 through 6.2.1 |
FMC |
6.4.0 |
6.2.0 |
6.1.0 through 6.2.0 |
FMC |
6.4.0 |
6.1.0 |
6.1.0 |
FMC |
6.4.0 |
5.4.0 through 6.0.1 |
Devices |
6.1.0 |
|
6.0.1 |
5.4.0 through 6.0.1 |
FMC |
6.1.0 |
6.0.0 |
5.4.0 through 6.0.0 |
FMC |
6.0.1 |
5.4.x |
5.4.x |
FMC |
6.0.0 |