Cisco Cisco Web Security Appliance S360 User Guide

Page of 432
 
21-32
Cisco AsyncOS for Web User Guide
 
Chapter 21      Perform System Administration Tasks
  Reverting to a Previous Version of AsyncOS for Web
Reverting to a Previous Version of AsyncOS for Web
AsyncOS for Web supports the ability to revert the AsyncOS for Web operating system to a previous 
qualified build for emergency uses. 
Note
You cannot revert to a version of AsyncOS for Web earlier than version 7.5.
Configuration File Use in the Revert Process
Effective in version 7.5, when you upgrade to a later version, the upgrade process automatically saves 
the current system configuration to a file on the Web Security appliance. (However, Cisco recommends 
manually saving the configuration file to a local machine as a backup.) This allows AsyncOS for Web to 
load the configuration file associated with the earlier release after reverting to the earlier version. 
However, when it performs a reversion, it uses the current network settings for the management 
interface.
Reverting AsyncOS for an Appliance Managed by the SMA
You can revert AsyncOS for Web from the Web Security appliance. However, if the Web Security 
appliance is managed by a Security Management appliance, consider the following rules and guidelines:
When Centralized Reporting is enabled on the Web Security appliance, AsyncOS for Web finishes 
transferring the reporting data to the Security Management appliance before it starts the reversion. 
If the files take longer than 40 seconds to transfer to the Security Management appliance, AsyncOS 
for Web prompts you to continue waiting to transfer the files, or continue the reversion without 
transferring all files.
You must associate the Web Security appliance with the appropriate Configuration Master after 
reverting. Otherwise, pushing a configuration from the Security Management appliance to the Web 
Security appliance might fail.
Reverting AsyncOS for Web to a Previous Version
Warning
Reverting the operating system on a Web Security appliance is a very destructive action and destroys 
all configuration logs and databases. Reversion also disrupts web traffic handling until the appliance 
is reconfigured. Depending on the initial Web Security appliance configuration, this action may 
destroy network configuration. If this happens, you will need physical local access to the appliance 
after performing the reversion.
Before You Begin
Contact Cisco Quality Assurance to confirm that you can perform the intended reversion.
Back up the following information from the Web Security appliance to a separate machine:
System configuration file (with passwords unmasked).
Log files you want to preserve.
Reports you want to preserve.