This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Version 9.406-3 upgrade

Hi,

we have Sophos SG330 with High Availability.

Current firmware version: 9.404-5
Latest available firmware version: 9.406-3

When upgrading to latest version should I first upgrade to 9.405-5?

Should I remove the HA if i want upgrade to check on one appliance? If i remove HA, the slave will perform factory reset and shutdown. Then I can upgrade master. But after upgrade what are procedures to bring slave back to production?



This thread was automatically locked due to age.
  • If you upgrade to latest the appliance will automatically also install the updates in between the current one and the latest one.

    You can setup to reserve a node when doing an upgrade. The slave will then NOT update automatically and stay on the previous version. You can then after testing also update the slave manually.

    Be aware though that any configuration changes you make before you update the slave will not be applied to the slave so if you need to revert back then you may have to make those changes again.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.

  • So if i will click update to the latest version it will update the production (master) appliance and slave leaves in previous version? But the reboot is required after update, so in a reboot slave kicks in and after master reboots with new firmware it takes over again? Is there a way to update just a slave so to avoid two failovers?

  • Why I need to setup reverse?(You mean switch MASTER?) Because two appliances are equal configuration, firmware, etc, what is the purpose?

    Are you sure SLAVE will not update? Because I think SLAVE will update first and then change the role to MASTER.

    I need a solution to update one member of HA and test it for few days. Should I break HA?

  • Not reverse, but reserve. There's an option in Management > High availability > Configuration called: "Keep node(s) reserved during Up2Date"

    If you enable that, your slave will NOT automatically upgrade and only 1 node will upgrade. The node that upgrades will become the new master. After some days if you have seen that everything is okay, you can manually update the second (reserved) node.


    Managing several Sophos firewalls both at work and at some home locations, dedicated to continuously improve IT-security and feeling well helping others with their IT-security challenges.