Upgrade Firewall Threat Defense
Use this procedure to upgrade Firewall Threat Defense with the upgrade wizard.
As you proceed, the system displays basic information about your selected devices, as well as the current upgrade-related status. This includes any reasons why you cannot upgrade.
If you navigate away from the upgrade wizard, your progress is preserved and other users cannot start a new upgrade workflow for any devices you have already selected. (Exception: if you are logged in with a CAC, your progress is cleared 24 hours after you log out.) To return to your workflow, choose .
Upgrade does not start until you complete the wizard and click Start Upgrade. All steps up to that point can be performed outside of a maintenance window, including checking readiness, copying upgrade packages, and choosing upgrade options.
![]() Caution |
Do not deploy configuration changes during upgrade. Even if the device appears inactive, do not manually reboot or shut down. In most cases, do not restart an upgrade in progress. You could place the system in an unusable state and require a reimage. Devices may reboot multiple times during the upgrade. This is expected behavior. If you encounter issues with the upgrade, including a failed upgrade or unresponsive device, see Unresponsive and Failed Firewall Threat Defense Upgrades. |
Before you begin
Make sure you are ready to upgrade:
-
Determine if you can run the target version: Compatibility
-
Plan your upgrade path: Upgrade Path
-
Review upgrade guidelines: Upgrade Guidelines
-
Check infrastructure and network: Network and Infrastructure Checks
-
Check configurations, tasks, and overall deployment health: Configuration and Deployment Checks
-
Perform backups: Backups
-
Upgrade chassis, if required: Upgrade Chassis for Threat Defense 3100, 4100, 4200, 9300
Procedure
|
Step 1 |
On the Firewall Management Center, choose . The Product Upgrades page provides an upgrade-centered overview of your deployment—how many devices you have, when they were last upgraded, whether there is an upgrade in progress, and so on. If the Firewall Management Center has internet access, it lists upgrades that apply to you, with suggested releases specially marked. |
||
|
Step 2 |
(Optional) Get upgrade packages onto the Firewall Management Center, or put them on an internal server. Skip this step if your devices can get upgrade packages directly from the internet. For other options, see Managing Upgrade Packages with the Firewall Management Center. |
||
|
Step 3 |
Launch the upgrade wizard. Click Upgrade next to the target version. If you are given a drop-down menu, choose Threat Defense.
|
||
|
Step 4 |
Select devices to upgrade. To help you select devices to upgrade, the upgrade wizard allows you to search and filter based on various useful criteria. The Ready to proceed filter shows all selected devices that are currently eligible for upgrade. Before proceeding with any upgrade step, the Selected number should match the Ready to proceed number. If they don't match, use the Not candidates filter to see why. You don't have to remove ineligible devices, but they are automatically excluded from upgrade. You must upgrade the members of device clusters and high availability pairs together.
|
||
|
Step 5 |
Click Prepare for upgrade to immediately begin copying upgrade packages to devices and checking readiness. Where upgrade packages come from depends on your deployment and previous configurations. For more information, see Copying Upgrade Packages to Devices. Many readiness checks are based on current device health, but checks on devices currently running Version 7.6.x and earlier may take longer. Passing all checks greatly reduces the chance of upgrade failure. If the checks expose issues that you cannot resolve, do not begin the upgrade. Disable checks only at the direction of Cisco TAC. For more information, see Configuration and Deployment Checks.
|
||
|
Step 6 |
(Optional) Click Advanced settings to choose upgrade options. For information on why you might disable these options, see Upgrade Options for Firewall Threat Defense. |
||
|
Step 7 |
Click Start upgrade and confirm your choice. Devices operate in maintenance mode while they upgrade. For information on traffic handling during the upgrade, see Traffic Flow and Inspection. |
||
|
Step 8 |
Monitor the upgrade. The wizard shows your overall upgrade progress. For more upgrade monitoring options, including special considerations for monitoring high availability upgrades, see Monitor Firewall Threat Defense Upgrades. |
||
|
Step 9 |
Verify success. After the upgrade completes, choose and confirm that the devices you upgraded have the correct software version. |
||
|
Step 10 |
(Optional) In high availability or clustered deployments, examine device roles. The upgrade process switches device roles so that it is always upgrading a standby unit or data node. It does not return devices to the roles they had before upgrade. If you have preferred roles for specific devices, make those changes now. |
||
|
Step 11 |
Update intrusion rules and the vulnerability database. Although the upgrade often updates these components, there could be newer ones available. Note that when you update intrusion rules, you do not need to automatically reapply policies. You will do that later.
|
||
|
Step 12 |
Complete any required post-upgrade configuration changes. |
||
|
Step 13 |
Redeploy configurations to the devices you just upgraded. Snort typically restarts during the first deployment after upgrade. Restarting the Snort process briefly interrupts traffic flow and inspection on all devices, including those configured for high availability or clustering. For more information, see Traffic Flow and Inspection when Deploying Configurations. Before you deploy, you may want to review the changes made by the upgrade (as well as any changes you have made since upgrade):
|
What to do next
-
(Optional) Clear the wizard by clicking Clear upgrade information. Until you do this, the page continues to display details about the upgrade you just performed. After you clear the wizard, use the Upgrade tab on the Device Management page to see last-upgrade information, and the Advanced Deploy screens to see configuration changes.
-
Back up again: Backups


Feedback