Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Community Member

Upgrading PIX 535s

I am upgrading a failover set, two 535s from 6.1(4) to 6.3.3. My Secondary is licensed to run in failover secondary mode only. I concerned that if I take both devices down and disconnect the failover links the Secondary will become a toaster when it boots. TAC has told me that I have 24 hours before my Secondary will hose without talking to the Primary. If anyone has some insight please pass it along. I would hate to be hit with cold reality at 4 AM.


Re: Upgrading PIX 535s


Cisco probably does not recommend this but you asked for some insight so here it goes. Depending on the location on the firewalls, in the past I have uploaded the IOS to the primary PIX. After that is done, Upload the IOS to the failover PIX. At this point, both firewalls have the correct IOS there just waiting to be rebooted. Reeboot the primary, the failover takes over and starts passing traffic. Wait about 15 or 20 seconds and reboot the failover. Just about that time the primary will come back up and be running the new IOS. A few seconds later the failover comes back and has the new IOS. If you time it correctly (or if you have a console to the primary PIX) your downtime should be very little and both your firewalls will be upgraded. Like I said before, this probably is not recommended by Cisco but you wanted some insight.

Hope that helps.

Re: Upgrading PIX 535s

Great advice and definetly recommended. More or less a modified version of option #2 in the following document:


PS - We are working on some methods to upgrade a failover pair of PIX's with no downtime. Stay tuned.

CreatePlease to create content