This information in this article applies to SourceFire 3D appliances, Cisco FirePOWER products and the next generation firewall product family, ASA 5508-X, 5516-X and 5585-X with FirePOWER service enabled. We’ll cover step-by-step process how to upgrade SourceFire FirePOWER FireSIGHT Management Center here.

First you need to find out what software versions your system is running and what new version you are upgrading to. The latest FirePOWER 6.0 has come out with a lot of shinning new features.

However I must caution you against it. Cisco Firepower 6.0 doesn’t support FireSIGHT high availability. This means if you have two managers configured in a HA cluster, you should stay on 5.4 and wait for the 6.01 patch scheduled to be released. Besides it still has a lot of bugs unfixed. At time of this article was written, I upgraded to the latest 5.4.x code train for greatest stability. The general process of upgrading applies to any future code releases as well. Let’s get started and upgrade SourceFire FirePOWER FireSIGHT Management Center.

Most Popular Product Family

Cisco ASA5506-X with FirePOWER integrated

Upgrade SourceFire FirePOWER FireSIGHT Management Center

FirePOWER Appliance 7010

Upgrade SourceFire FirePOWER FireSIGHT Management Center

FirePOWER Appliance 8130

Upgrade SourceFire FirePOWER FireSIGHT Management Center

FirePOWER Appliance 8350
Upgrade SourceFire FirePOWER FireSIGHT Management Center

How to Upgrade SourceFire FirePOWER FireSIGHT Management Center

Before we proceed to upgrade, it is always a good idea to clean up the disk space and make enough room for the new code to be installed. You are probably reading this article because you received a warning message that the disk is getting full. The information here applies to you and you can follow the same instruction to clean up the disk space.

Local backups will not get pruned by the pruning process. They must be deleted by the user manually.

There is feature to configure remote backups, which is recommended. You can configure it by following the instruction at Help > Online

Prune 3D SourceFire FirePOWER Sensor local disk

Patches for old software versions can be deleted. If you are managing the FirePOWER sensors through the FireSIGHT Management Center, formally called Defense Center, you’ll need to login to each sensor and delete the backup files and patches. Go to Devices > Device Management, you’ll find a list of FirePOWER sensor IPs.

Upgrade FirePOWER SourceFire (9)

You can login each individual box by going to https://IP/ .

On 3D Software Version 5.x, navigate to System > Updates, and click the Delete button to the right of any old patches you would like to delete.

  • Local Backups

Backups which have been copied to another device can be safely deleted.

On 3D Software Version 5.x, navigate to System > Tools > Backup/Restore, check any old backup files and click the Delete button.

  • Software Updates

Upgrade FirePOWER SourceFire (1)

Backup SourceFire Defense Center Firepower Management Center

It is always a good idea to obtain a backup of your FirePOWER Management Center (FMC) because all the policies and rules are configured and pushed through the FMC. It is the brain of the whole operation. You can always recover a sensor through the FMC if one ever crashes.

Upgrade SourceFire FirePOWER FireSIGHT Management Center

I covered this topic in greater details here: How to Backup and Restore SourceFire Defense Center Firepower Management Center

Sequential Upgrade is Important

The FireSIGHT Management Center can only manage one version older than the version it is running. If your FirePOWER version was 5.3 or lower, it would no longer be able to manage any FirePOWER sensor 5.4 and greater. Once again, it is important to read the release notes, which states to upgrade all FirePOWER appliances to 5.3 before taking your FMC to 5.4 and newer. To save your time, I have compiled an upgrade path after I’ve read all the lengthy release notes.

  • Step 1: Upgrade FirePOWER sensors to 5.2.0.3, then 5.3.0 then 5.3.0.2
  • Step 2: Upgrade FireSIGHT Management Center (FMC) to 5.3.0.2 then5.3.1 then 5.4.0 then 5.4.1.5
  • Step 3: Upgrade FirePOWER sensors to 5.3.0.2 then 5.4.0 then 5.4.0.6

If you want to go to the latest 6.0.x code, you have two more steps:

  • Step 4: Upgrade FirePOWER sensors to 6.0.0.0 then 6.0.0.1
  • Step 5: Upgrade FireSIGHT Management Center (FMC) to 6.0.0.0 then 6.0.0.1

It is crucial to follow the sequence while upgrade. Failing to do so you may lose the connectivity to the remote sensors or even cause production outage.

Note: If you are upgrading from one major release to another, the “download updates” feature on management console will not pull major releases. You must download the code directly from Cisco.com and upload it through the management console.

Download updates from Cisco.com

To upgrade SourceFire FirePOWER FireSIGHT Management Center, we cannot download different major release updates within the FirePOWER management console itself.  We need to download the files from Cisco.com manually. To download upgrades and patches for the sensors and FirePOWER Management Center, use keyword “FirePOWER” to search for download on Cisco.com/go/support. Find the appropriate downloads to match the product you have.

For the FirePOWER 3D 7110 appliances and the Management Center I have, here are my download options.

Upgrade SourceFire FirePOWER FireSIGHT Management Center Upgrade SourceFire FirePOWER FireSIGHT Management Center

Files downloaded for FirePOWER sensors

Upgrade SourceFire FirePOWER FireSIGHT Management Center

Files downloaded for FirePOWER Management Center

Upgrade SourceFire FirePOWER FireSIGHT Management Center

When I tried to upgrade the Management Center from 5.3.0.2 to 5.4.0, it gave me this error message. I had to download and install the 5.3.1 upgrade package first.

Upgrade SourceFire FirePOWER FireSIGHT Management Center

Please note you need the “Upgrade” package instead of “Patch” when jumping to a different major release.

Start Upgrading FirePOWER sensors and the Management Center

Important: You must follow the correct order mentioned in the previous session. The sequence is important, or you either unable to upgrade or lose connectivity to one or more devices.

Click on install icon in Updates page. If no other issues present, the upgrade will start and you can view the status in the job queue. The device will need to reboot when upgrading to major releases. I witnessed about 30 seconds of network connectivity loss while the sensor reboots, even they are configured “fail-open”. FirePOWER Management Center reboot does not cause network outage.

Upgrade SourceFire FirePOWER FireSIGHT Management Center

The upgrade job will go through file integrity checks, DB verification and etc. The entire process per major release upgrade took me about 30-40 minutes to complete. If you were upgrading to the latest code and have to go through a few intermediate major releases, make sure you plan at least 2 to 4 hours of maintenance window.

If you are using ASDM to upgrade the sensors, the process is the same. You’ll find the UI is the same as well. I recommend upgrading the sensors by going to its own browser based management console directly at https://IP/ The ASDM is just a nice wrapper around it and can add delay and potential issues.

In this session I walked though how to upgrade SourceFire FirePOWER FireSIGHT Management Center and the sensors. As you have seen, the key is to follow the correct order upgrading to one or more intermediate major releases and work towards the final version you want to get to. You cannot jump across major releases.

Continue reading:

Configure and Manage ASA FirePOWER Module using ASDM

Configure and Manage ASA FirePOWER Module using Management Center

How to Backup and Restore FirePOWER Management Center

I have written a quick start guide setting up Cisco’s next-generation ASA-X with FirePOWER service. You can download the configuration template and modify to your needs in matter of minutes.

Cisco ASA 5506-X FirePOWER Configuration Example