Upgrade the Secure Firewall 3100/4200 Chassis
Use this procedure to upgrade the chassis on the Secure Firewall 3100/4200 in multi-instance mode with the upgrade wizard.
For the Secure Firewall 3100/4200 in multi-instance mode, any upgrade can require a chassis upgrade. Although you upgrade the chassis and firewall separately, one package contains the chassis and firewall upgrades, and you perform both from the Firewall Management Center. It is possible to have a chassis-only upgrade or a firewall-only upgrade.
As you proceed, the system displays basic information about your selected chassis, as well as the current upgrade-related status. This includes any reasons why you cannot upgrade.
If you navigate away from the upgrade wizard, your progress is preserved and other users cannot start a new upgrade workflow for any chassis you have already selected. (Exception: if you are logged in with a CAC, your progress is cleared 24 hours after you log out.) To return to your workflow, choose .
Upgrade does not start until you complete the wizard and click Start upgrade. All steps up to that point can be performed outside of a maintenance window, including copying upgrade packages and choosing upgrade options.
![]() Caution |
Do not deploy configuration changes during upgrade. Even if the chassis or its devices appear inactive, do not manually reboot or shut down. Do not restart an upgrade in progress. You could place the system in an unusable state and require a reimage. The chassis may reboot multiple times during the upgrade. This is expected behavior. If you encounter issues with the upgrade, including a failed upgrade or unresponsive chassis or device, contact Cisco TAC. |
Before you begin
Make sure you are ready to upgrade:
-
Determine if you can run the target version: Compatibility
-
Plan your upgrade path: Upgrade Path
-
Review upgrade guidelines: Upgrade Guidelines
-
Check infrastructure and network: Network and Infrastructure Checks
-
Check configurations, tasks, and overall deployment health: Configuration and Deployment Checks
-
Perform backups: Backups
Procedure
|
Step 1 |
On the Firewall Management Center, choose . The Product Upgrades page provides an upgrade-centered overview of your deployment—how many devices you have, when they were last upgraded, whether there is an upgrade in progress, and so on. If the Firewall Management Center has internet access, it lists upgrades that apply to you, with suggested releases specially marked. |
||
|
Step 2 |
(Optional) Get upgrade packages onto the Firewall Management Center, or put them on an internal server. Skip this step if your devices can get upgrade packages directly from the internet. For other options, see Managing Upgrade Packages with the Firewall Management Center. |
||
|
Step 3 |
Launch the upgrade wizard. Click Upgrade next to the target version. If you are given a drop-down menu, choose Chassis.
|
||
|
Step 4 |
Select chassis to upgrade. To help you select chassis to upgrade, the upgrade wizard allows you to search and filter based on various useful criteria. The Ready to proceed filter shows all selected chassis that are currently eligible for upgrade. Before proceeding with any upgrade step, the Selected number should match the Ready to proceed number. If they don't match, use the Not candidates filter to see why. You don't have to remove ineligible chassis, but they are automatically excluded from upgrade. |
||
|
Step 5 |
(Optional) Remove unneeded upgrade packages from your selected chassis. You must manually manage chassis upgrade packages. Right now is a good time to clean up. The Details column indicates which chassis have packages that might not be needed. If any do:
|
||
|
Step 6 |
Copy upgrade packages. Click Copy Upgrade Package and wait for the transfer to complete. Where the package comes from depends on your deployment and previous configurations. For more information, see Copying Upgrade Packages to Devices. |
||
|
Step 7 |
Choose upgrade order.
|
||
|
Step 8 |
Reconfirm you are ready to upgrade. We recommend revisiting the configuration and deployment health checks you performed earlier: Configuration and Deployment Checks. |
||
|
Step 9 |
Click Start upgrade and confirm your choice. For information on traffic handling during the upgrade, see Traffic Flow and Inspection for Chassis Upgrades. |
||
|
Step 10 |
Monitor the upgrade. The wizard shows your overall upgrade progress. For more information, see Monitor Firewall Threat Defense Upgrades. |
||
|
Step 11 |
Verify success. After the upgrade completes, verify success on . |
||
|
Step 12 |
(Optional) Examine configuration changes. Before you upgrade Firewall Threat Defense, you may want to review the changes made by the chassis upgrade:
|
||
|
Step 13 |
(Optional) In high availability deployments, examine device roles. Depending on how you performed the upgrade, high availability instances may have switched roles. Keeping in mind that any subsequent Firewall Threat Defense upgrade will also switch device roles, make any desired changes. |
What to do next
-
(Optional) Clear the wizard by clicking Clear upgrade information. Until you do this, the page continues to display details about the upgrade you just performed. After you clear the wizard, use the Upgrade tab on the Device Management page to see last-upgrade information, and the Advanced Deploy screens to see configuration changes.
-
Back up again: Backups

Feedback