Tuesday, October 23, 2018

Cisco FireSIGHT 5.4 to 6.2.3 Upgrade

I'm looking to get some help on upgrading our FireSIGHT and FirePOWER devices from 5.4 to 6.2.3.

Here's my current state:

FireSIGHT VM: 5.4.1.11

3D7030: 5.4.0.10

2x ASA5516-X with FirePOWER: 5.4.1.10

I've heard the horror stories about upgrades. I inherited these devices when they were at 5.3, so I've done my share up upgrades and seen the failures. I attempted the 6.0 upgrade on FMC and it failed horribly (thank you VM snapshot).

So I'd like to build a new FMC at either 6.1 or 6.2.

My question is how do I import all my configs and licenses into the new FMC? Can I just take a backup on 5.4.1.11 and import it straight into 6.1 or 6.2?

And my next question, how do I manage the sensor upgrades? Because 6.2 can't manage 5.4 devices. So should I go to FMC 6.1, import my sensors and then re-image them? Or go straight to 6.2.3, re-image my sensors and then add the sensors to FMC?

I've done some Googling and read the Cisco forums but I can't find a straight answer for this scenario. I'm sure I'm not the first person to go through this. Everyone just says build a new FMC and re-image the sensors but I can't find these specific steps.

Anyone else go through this FirePOWER nonsense!?

And I guess, what version should I land on? I just saw the post that said 6.2.3.6 is buggy. Cisco recommends 6.2.3.5. Or should I stay on 6.2.3?



No comments:

Post a Comment