Cisco Support Community
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

AIP-SSM upgrade

going to upgrade from 6.0(1)E1 to

IPS IPS-K9-6.1-1-E2.pkg

we run 2 asa in active/active for 2 context. wd like to upgrade one SSM first and run it for a week with new signatures then upgrade the other. this means one module will have 6.0(1)E1 and not the latest. will this cause any issue?

also my output shows data plane DOWN. any ideas what may cause it and how to fix it

od Card Type Model Serial No.

--- -------------------------------------------- ------------------ -----------

1 ASA 5500 Series Security Services Module-20 ASA-SSM-20 JAF11025147

Mod MAC Address Range Hw Version Fw Version Sw Version

--- --------------------------------- ------------ ------------ ---------------

1 0019.e82b.d238 to 0019.e82b.d238 1.0 1.0(11)2 6.0(1)E1

Mod SSM Application Name Status SSM Application Version

--- ------------------------------ ---------------- --------------------------

1 IPS Up 6.0(1)E1

Mod Status Data Plane Status Compatibility

--- ------------------ --------------------- -------------

1 Up Down


Re: AIP-SSM upgrade

The two units in a failover configuration must have the same hardware configuration. They must be the same model, have the same number and types of interfaces, the same amount of RAM, and, for the ASA 5500 series security appliance, the same SSMs installed (if any).So both SSM should be of the same version always.

CreatePlease to create content