Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX 515 FO pull to test upgrade

My boss wants me to pull the 515 failover from production to test the upgrade to the latest release.

I had thought I'd run across something somewhere saying something about whether it's ok or not ok but I cannot find that information again.

Anyone know if there would be a problem running the latest OS using a FO license? (If the FO has no issue we will upgrade the UR and place the FO back to replicate from the UR to continue normal operation.)

thank you

New Member

Re: PIX 515 FO pull to test upgrade

This is feasable, but the FO device will have unpredicting behavior.

Also to make a UR/FO pair work together both pix must have identical hardware and software packages. So when the one of the 2 pix will have a newer IOS, the failover fonction will cease workink.

Personnaly I would upgrade the primary pix and prepare a backup-plan in case of a return back to the older IOS. (Save the old configuration in a lock vault)


New Member

Re: PIX 515 FO pull to test upgrade

Thanks fo rhte reply.

Wouldn't it be possible to run the FO upgrade scenerio and then if all is good with our current config with the new IOS, upgrade the primary, clear the FO and pair it with the primary to replicate the config?

I guess I could pull the primary and leave the FO device up. From what I understand the only issue with FO as stand-alone is that it will restart every 24 hours However, if the primary has a UR license and a failover was detected then the FO device will work normally unless it's manually rebooted.

I can power down and upgrade the IOS on the primary and be sure the config is error free then move on from there I guess.

We are running 6.3(3) all 6 interfaces used.

Failover cable only, no stateful or lan based failover.

Thanks again


New Member

Re: PIX 515 FO pull to test upgrade

Hi Adriana,

I cannot argue w/ you the way to proceed and to be fair with you, the planning you have made is good.

So if you wish to proceed the FO as first step, you'll only need to push the newest config to the UR.