In this tutorial, we will update two ASA firewall 5585-X from CLI.
Actual version 9.8.4.20
Target version 9.8.4.44
Note: Perform these steps on the active unit
Step 1 – On the active unit in privileged EXEC mode, copy the ASA software to the active unit flash memory:
asa/pri/act# copy ftp://MyUser:MyPassword@10.2.29.4/asa984-44-smp-k8.bin disk0:/asa984-44-smp-k8.bin
data:image/s3,"s3://crabby-images/edbaa/edbaa15530f713cfa210c9fca30ac60b1d42e5bb" alt=""
Step 2 – Copy the software to the standby unit; be sure to specify the same path as for the active unit:
asa/pri/act# failover exec mate copy /noconfirm ftp://MyUser:MyPassword@10.2.29.4/asa984-44-smp-k8.bin disk0:/asa984-44-smp-k8.bin
data:image/s3,"s3://crabby-images/84fc2/84fc26639ea2b7911f03c4acec0404a0f00d9bcb" alt=""
Step 3 – Access global configuration mode:
asa/pri/act# configure terminal
Step 4 – Show the current boot images configured:
asa/pri/act(config)# show running-config boot system
boot system disk0:/asa984-20-smp-k8.bin
boot system disk0:/asa964-36-smp-k8.bin
data:image/s3,"s3://crabby-images/d0151/d01510a3b6d449f6c7039a7378a54061968dfae3" alt=""
Step 5 – Remove any existing boot image configurations so that you can enter the new boot image as your first choice:
asa/pri/act(config)# no boot system disk0:/asa984-20-smp-k8.bin
asa/pri/act(config)# no boot system disk0:/asa964-36-smp-k8.bin
data:image/s3,"s3://crabby-images/a19f7/a19f75090d7be56dc4f13e4dc8e94e162d4e6ecd" alt=""
Step 6 – Set the ASA image to boot and save the new settings to the startup configuration::
asa/pri/act(config)# boot system disk0:/asa984-44-smp-k8.bin
pri/act(config)# write memory
Building configuration…
Cryptochecksum: a54401f5 14357f54 e3455251 eb1a3ef0
129373 bytes copied in 1.330 secs (129373 bytes/sec)
[OK]
These configuration changes are automatically saved on the standby unit.
data:image/s3,"s3://crabby-images/8d0ba/8d0babffda50fa6b4b31b7b0f4182430c2076674" alt=""
Step 7 – Reload the standby unit to boot the new image:
asa/pri/act(config)# failover reload-standby
data:image/s3,"s3://crabby-images/57c23/57c23d5600e60b5b1d84da0e038bad174bd834cf" alt=""
In the Standby unit will appear this message:
data:image/s3,"s3://crabby-images/407e0/407e0fb9bb435dd57368e9210aaff3cdc11a5518" alt=""
Wait for the standby unit to finish loading. The Active unit will display a message that the firmware version does not match:
data:image/s3,"s3://crabby-images/2c7c1/2c7c1cfebd819eaa8cecefc3053819a78113764e" alt=""
Use the show failover command to verify that the standby unit is in the Standby Ready state.
data:image/s3,"s3://crabby-images/dea50/dea50a6a21aed95e02455485110a12ec77af64da" alt=""
Step 8 – Force the active unit to fail over to the standby unit.
asa/pri/act(config)# no failover active
data:image/s3,"s3://crabby-images/77e0b/77e0bb336ce85c5588492e8a7d49192fd4b8a9f6" alt=""
If you are disconnected from your SSH session, reconnect to the main IP address, now on the new active/former standby unit.
data:image/s3,"s3://crabby-images/fe0f5/fe0f530b334d5947c83e03f1a4cb983880645ded" alt=""
Step 9 – From the new active unit, reload the former active unit (now the new standby unit).
asa/sec/act(config)# failover reload-standby
data:image/s3,"s3://crabby-images/2e79a/2e79afbb4bb92710d772171fd67a4a088bcd24ea" alt=""
Step 10 -Lastly, validate with the show failover command that versions be the same on both ASA:
data:image/s3,"s3://crabby-images/38486/384867b3ef1b10755d9c219383c37c5d4d839173" alt=""
Regards!
Reference: