cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
477
Views
0
Helpful
2
Replies

FWSM Aplication Software Upgrade

lm20ele
Level 1
Level 1

I'm getting confused with the procedure on "Upgrading Failover Pairs to a new Minor or Major Relase" on Step 1 where it says "Download the new software to both units". How can I complete this step?. It is my understanding that I need to be on the system execution space if I have multiple contexts, which is my case, in order to perform the upgrade. I can ssh to the Admin Context and move into the system execution space but that will only take care of the active fwsm. which means the standby fwsm will not have the new software loaded and won't have the new IOS after the reboot.

http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/configuration/guide/swcnfg_f.html#wp1042136

Help please.

Thanks

Luis

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

You should have access to both Active and Standby FWSM, whether it is through the switch "session slot proc 1" or if you SSH to both ip addresses of the fwsm (the active ip address, and the standby ip address).

In your case, you mentioned that you SSH to the active fwsm on the admin context, so you could do the same to the standby fwsm. Your configuration should have 2 ip addresses per interface.

For example:

interface vlan 200

     ip address 1.1.1.1 255.255.255.0 standby 1.1.1.2

So, 1.1.1.2 is the standby ip address that you can SSH to.

View solution in original post

2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

You should have access to both Active and Standby FWSM, whether it is through the switch "session slot proc 1" or if you SSH to both ip addresses of the fwsm (the active ip address, and the standby ip address).

In your case, you mentioned that you SSH to the active fwsm on the admin context, so you could do the same to the standby fwsm. Your configuration should have 2 ip addresses per interface.

For example:

interface vlan 200

     ip address 1.1.1.1 255.255.255.0 standby 1.1.1.2

So, 1.1.1.2 is the standby ip address that you can SSH to.

Hi halijenn,

You are absolutely right. I forgot I had configured that second IP address for the standby. I now understand.

Thanks

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card