Traffic Flow and Inspection
Schedule maintenance windows when upgrade will have the least impact, considering any effect on traffic flow and inspection.
Traffic Flow and Inspection for Firewall Threat Defense Upgrades
Software Upgrade
Traffic is dropped while you upgrade. In a high availability deployment, you can minimize disruption by upgrading devices one at a time.
For the ISA 3000 only, if you configured hardware bypass for power failure, traffic is dropped during the upgrade but is passed without inspection while the device completes its post-upgrade reboot.
Software Revert (Major/Maintenance Releases)
Traffic is dropped while you revert. In a high availability deployment, revert is more successful when you revert both units simultaneously. Traffic flow and inspection resume when the first unit comes back online.
Traffic Flow and Inspection for Chassis Upgrades
Upgrading FXOS reboots the chassis. For FXOS upgrades to Version 2.14.1+ that include firmware upgrades, the chassis reboots twice—once for FXOS and once for the firmware.
Even in high availability deployments, you upgrade FXOS on each chassis independently. To minimize disruption, upgrade one chassis at a time; see Upgrade Order.
|
Firewall Threat Defense Deployment |
Traffic Behavior |
Method |
|---|---|---|
|
Standalone |
Dropped. |
— |
|
High availability |
Unaffected. |
Best Practice: Update FXOS on the standby, switch active peers, upgrade the new standby. |
|
Dropped until one peer is online. |
Upgrade FXOS on the active peer before the standby is finished upgrading. |
Traffic Flow and Inspection when Deploying Configurations
Restarting the Snort process briefly interrupts traffic flow and inspection on all devices, including those configured for high availability. When you deploy without restarting Snort, resource demands may result in a small number of packets dropping without inspection.
Snort typically restarts during the first deployment immediately after the upgrade. It does not restart during other deployments unless, before deploying, you modify specific policy or device configurations.

Feedback