This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

New SG 430 Firewall with different firmware

Hello

a follow up. 
the new firewall has arrived to replace the faulty primary of the HA pair. 
The existing secondary firewall has firmware 9.706-9

The new firewall has firmware version 9705. 
What is the best and safest approach and how would I upgrade the new firewall to match the existing firewalls version. 
Thanks all. 



This thread was automatically locked due to age.
Parents
  • Haigh Darren and welcome to the UTM Community!

    Here're the instructions I give to my clients:

        1. If needed, do a quick, temporary install so that the new device can download Up2Dates.
        2. Apply the Up2Dates to the same version as the current unit, do a factory reset and shutdown.
        3. On the current UTM in use, on the 'Configuration' tab of 'High Availability':
            a. Disable and then enable Hot-Standby
            b. Select eth3 as the Sync NIC
            c. Configure it as Node_1
            d. Enter an encryption key (I've never found a need to remember it)
            e. Select 'Enable automatic configuration of new devices'
            f. I prefer to use 'Preferred Master: None' and 'Backup interface: Internal'
        4. Cable eth3 to eth3 on the new device.
        5. Cable all of the other NICs exactly as they are on the original UTM.
        6. Power up the new device and wait for the good news. Wink

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thanks Bob

    my existing sync nic is 8 so that’s what I will use. 
    Do you have some tips to do a temp install. 
    I tried today using a Lan cable but had issues. 
    I was using the factory IP of the unit 192.168.1.1

    Cheers 

  • You'll want to disconnect your PC from the network, Darren, and assign it an IP like 192.168.1.11 before you connect it directly to the new unit.  Or was there another issue?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • You'll want to disconnect your PC from the network, Darren, and assign it an IP like 192.168.1.11 before you connect it directly to the new unit.  Or was there another issue?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data