Add More Cluster Nodes

Add or replace the threat defense cluster node in an existing cluster. When you add a new cluster node in FXOS, the management center adds the node automatically.

Note

The FXOS steps in this procedure only apply to adding a new chassis; if you are adding a new module to a Firepower 9300 where clustering is already enabled, the module will be added automatically.

Before you begin

  • In the case of a replacement, you must delete the old cluster node from the management center. When you replace it with a new node, it is considered to be a new device on the management center.

  • The interface configuration must be the same on the new chassis. You can export and import FXOS chassis configuration to make this process easier.

Procedure


Step 1

If you previously upgraded the threat defense image using the management center, perform the following steps on each chassis in the cluster.

When you upgraded from the management center, the startup version in the FXOS configuration was not updated, and the standalone package was not installed on the chassis. Both of these items need to be set manually so the new node can join the cluster using the correct image version.

Note

If you only applied a patch release, you can skip this step. Cisco does not provide standalone packages for patches.

  1. Install the running threat defense image on the chassis using the System > Updates page.

  2. Click Logical Devices and click the Set Version icon (Set Version icon). For a Firepower 9300 with multiple modules, set the version for each module.

    The Startup Version shows the original package you deployed with. The Current Version shows the version you upgraded to.

  3. In the New Version drop-down menu, choose the version that you uploaded. This version should match the Current Version displayed, and will set the startup version to match the new version.

  4. On the new chassis, make sure the new image package is installed.

Step 2

On an existing cluster chassis chassis manager, click Logical Devices.

Step 3

Click the Show Configuration icon at the top right; copy the displayed cluster configuration.

Step 4

Connect to the chassis manager on the new chassis, and click Add > Cluster.

Step 5

For the Device Name, provide a name for the logical device.

Step 6

Click OK.

Step 7

In the Copy Cluster Details box, paste in the cluster configuration from the first chassis, and click OK.

Step 8

Click the device icon in the center of the screen. The cluster information is partly pre-filled, but you must fill in the following settings:

Cluster Information
Cluster Information
Interface Information
Interface Information
Settings
Settings
  • Chassis ID—Enter a unique chassis ID.

  • Site ID—For inter-site clustering, enter the site ID for this chassis between 1 and 8. This feature is only configurable using the management center FlexConfig feature.

  • Cluster Key—Enter the same cluster key.

  • Management IP—Change the management address for each module to be a unique IP address on the same network as the other cluster members.

  • Fully Qualified Hostname—Enter the same hostname.

  • Password—Enter the same password.

  • Registration Key—Enter the same registration key.

Click OK.

Step 9

Click Save.

The chassis deploys the logical device by downloading the specified software version and pushing the bootstrap configuration and management interface settings to the application instance. Check the Logical Devices page for each cluster member for the status of the new logical device. When the logical device for each cluster member shows its Status as online, you can start configuring the cluster in the application. You may see the "Security module not responding" status as part of the process; this status is normal and is temporary.