Upgrade the cluster
This task upgrades a Firewall Threat Defense Virtual cluster to a new software version by updating the cloud instance template and performing a managed upgrade.
The cluster upgrade process involves updating both the cloud infrastructure template and the software package through the management center. The upgrade is performed one node at a time to maintain cluster availability.
Before you begin
-
Before you upgrade a cluster in the public cloud, copy the target version image to your cloud image repository and update the image ID in the cluster deployment template (we actually recommend replacing the existing template with a modified copy). This ensures that after the upgrade, new instances — for example, instances launched during cluster scaling — will use the correct version. If the marketplace does not have the image you need, such as when the cluster has been patched, create a custom image from a snapshot of a standalone Firewall Threat Defense Virtual instance running the correct version, with no instance-specific (day 0) configurations.
Follow these steps to upgrade a Firewall Threat Defense Virtual cluster:
Procedure
Step 1 | Upload the target image version to the cloud image storage. |
Step 2 | Update the cloud instance template of the cluster with the updated target image version.
|
Step 3 | Upload the target image version upgrade package to the Cloud-Delivered Firewall Management Center. |
Step 4 | Perform a readiness check on the cluster that you want to upgrade. |
Step 5 | After a successful readiness check, initiate the installation of the upgrade package. |
Step 6 | The Cloud-Delivered Firewall Management Center upgrades the cluster nodes one at a time. |
Step 7 | The Cloud-Delivered Firewall Management Center displays a notification after successful upgrade of the cluster. There is no change to the serial number and UUID of the instance after the upgrade. |