Cisco Cisco Firepower Management Center 2000

Página de 38
15
FireSIGHT System Release Notes
Installing the Update
Installing the Update
Before you begin the update, you must thoroughly read and understand these release notes, especially 
.
To update Defense Centers running at least Version 5.4.1 to version 5.4.1.3, Cisco ASA with FirePOWER Services running 
at least Version 5.4.1 to version 5.4.1.3, and managed devices and ASA FirePOWER modules running at least Version 
5.4 of the FireSIGHT System to Version 5.4.0.4, see the guidelines and procedures outlined below:
Caution:
 Do not reboot or shut down your appliances during the update until you see the login prompt. The system may 
appear inactive during the pre-checks portion of the update; this is expected behavior and does not require you to reboot 
or shut down your appliances.
When to Perform the Update
Because the update process may affect traffic inspection, traffic flow, and link state, Cisco strongly recommends you 
perform the update in a maintenance window or at a time when the interruption will have the least impact on your 
deployment.
Installation Method
Use the Defense Center’s web interface to perform the update. Update the Defense Center first, then use it to update 
the devices it manages.
Order of Installation
Update your Defense Centers before updating the devices they manage.
Installing the Update on Paired Defense Centers
When you begin to update one Defense Center in a high availability pair, the other Defense Center in the pair becomes 
the primary, if it is not already. In addition, the paired Defense Centers stop sharing configuration information; paired 
Defense Centers do not receive software updates as part of the regular synchronization process.
To ensure continuity of operations, do not update paired Defense Centers at the same time. First, complete the update 
procedure for the secondary Defense Center, then update the primary Defense Center.
Installing the Update on Clustered Devices
When you install an update on clustered devices, the system performs the update on the devices one at a time. When 
the update starts, the system first applies it to the secondary device, which goes into maintenance mode until any 
necessary processes restart and the device is processing traffic again. The system then applies the update to the primary 
device, which follows the same process.
Installing the Update on Stacked Devices
When you install an update on stacked devices, the system performs the updates simultaneously. Each device resumes 
normal operation when the update completes. Note that:
If the primary device completes the update before all of the secondary devices, the stack operates in a limited, 
mixed-version state until all devices have completed the update. 
If the primary device completes the update after all of the secondary devices, the stack resumes normal operation 
when the update completes on the primary device.
Installing the Update on Cisco NGIPS for Blue Coat X-Series
Updating the Cisco NGIPS for Blue Coat X-Series reloads the affected VAPs. If your FireSIGHT Software for X-Series 
device is deployed inline and you are using multi-member VAP groups, Cisco recommends that you update the VAPs 
one at a time. This allows the other VAPs in the group to inspect network traffic while the VAP that is being updated 
reloads.