background image

 

12

Upgrade/Downgrade Guide, Cisco ACE 4700 Series Application Control Engine Appliance

OL-25719-01

Upgrading Your ACE Software in a Redundant Configuration

Before You Begin

Before you upgrade your ACE software, be sure that your ACE configurations meet the upgrade 
prerequisites in the following sections: 

Changing the Admin Password

Changing the www User Password

Removing the duplex Command from the ACE Configuration

Removing the Underscore Character from a Hostname

Creating a Checkpoint

 

Consideration for a Startup Configuration with Optimization Concurrent Connections

Checking Your Configuration for FT Priority and Preempt

Consideration for a Startup Configuration with Optimization Concurrent Connections

Note

To upgrade from software version A1(8a) to A4(1.0) or later, you must first upgrade software version 
A1(8a) to A3(2.6). Then, upgrade software version A3(2.6) to A4(1.0) or later.

Note

If you are upgrading a redundant configuration from software version A3(2.x) or A4(1.0) to software 
version A4(2.0) or later, while the two ACEs are in split mode with the earlier software version running 
on the active ACE and software version A4(2.0) running on the standby, config sync is disabled because 
of a license incompatibility. If you make any configuration changes on the active ACE during this time, 
your changes are not synchronized to the standby and are lost. After you complete the upgrade, config 
sync is automatically reenabled. We recommend that you do not make any configuration changes while 
the two ACEs are in split mode.

Changing the Admin Password

Before you upgrade to ACE software version A3(1.0) or higher, you

 must

 change the default Admin 

password if you have not already done so. Otherwise, after you upgrade the ACE software, you will be 
able to log in to the ACE only through the console port.

Caution

If you do not change the Admin password prior to upgrading to ACE software version A3(1.0) or higher, 
configuration synchronization may fail and the context may not be in the STANDBY_HOT state.

For details on changing the default Admin password, do one of the following:

From the CLI, see Chapter 1, Setting Up the ACE, in the 

Administration Guide, Cisco ACE 

Application Control Engine

From the Device Manager GUI, see Chapter 1, Overview, in the 

Device Manager Guide, Cisco ACE 

4700 Series Application Control Engine Appliance

.

Note

If your ACE is managed by the Cisco Application Networking Manager (ANM) software, you 

must

 

change the Admin password on the ANM in the Primary Attributes page instead of the ACE CLI. From 
the ANM, click the 

Change Password

 button on the Primary Attributes page (

Config > Devices > 

System > Primary Attributes

). 

Summary of Contents for ACE-4710-1F-K9

Page 1: ... Appliance For information on the ACE features and configuration details see the ACE appliance documentation located on www cisco com at http www cisco com en US products ps7027 tsd_products_support_series_home html This guide contains the following sections Upgrade Scenarios Based on Licenses in Software Release A4 1 1 A3 2 7 and Earlier Upgrade Scenarios Based on Software Release A4 2 0 and Late...

Page 2: ...on limited by device throughput 7500 SSL TPS 20 VCs ACE 4710 0 5F K9 0 5 Gbps throughput 100 Mbps compression 100 SSL TPS 5 VCs Throughput upgrade only Start upgrade with ACE 4710 BUN UP1 1 Gbps throughput 500 Mbps compression 5000 SSL TPS 5 VCs ACE 4710 1F K9 1 Gbps throughput 500 Mbps compression 5000 SSL TPS 5 VCs Increased SSL compression and or VCs Software upgrade to version A4 2 0 1 Gbps th...

Page 3: ...ut upgrade only Upgrade with ACE 4710 BUN UP3 4 Gbps throughput 2 Gbps compression 7500 SSL TPS 5 VCs ACE 4710 4F K9 4 Gbps throughput 2 Gbps compression 7500 SSL TPS 5 VCs Increased VC only possible option everything else is maximized Software upgrade to version A4 2 0 2 Gbps throughput 2 Gbps compression 7500 SSL TPS 20 VCs ACE 4710 A La Carte Licenses ACE4710 with 1 Gbps throughput ACE AP 01 LI...

Page 4: ... Upgrade with ACE AP 04 UP1 4 Gbps throughput Retains previous combination of feature licenses ACE4710 with 2 Gbps throughput ACE AP 02 LIC Any combination of feature licenses Increased SSL compression and or VCs Software upgrade to version A4 2 0 2 Gbps throughput 2 Gbps compression 7500 SSL TPS 20 VCs ACE4710 with 2 Gbps throughput ACE AP 02 LIC Any combination of feature licenses Throughput upg...

Page 5: ...bps throughput 500 Mbps compression 5000 SSL TPS 5 VCs Increased SSL compression and or VCs Software upgrade to version A4 2 0 1 Gbps throughput Up to 2 Gbps of compression limited by device throughput 7500 SSL TPS 20 VCs ACE 4710 1F K9 1 Gbps throughput 500 Mbps compression 5000 SSL TPS 5 VCs Throughput upgrade only Start upgrade with ACE 4710 BUN UPG2 2 Gbps throughput Up to 2 Gbps of compressio...

Page 6: ...sion A4 2 0 4 Gbps throughput 2 Gbps compression 7500 SSL TPS 20 VCs ACE 4710 A La Carte Licenses ACE4710 with 1 Gbps throughput ACE AP 01 LIC Any combination of feature licenses Increased SSL compression and or VCs Software upgrade to version A4 2 0 1 Gbps throughput Up to 2 Gbps of compression limited by device throughput 7500 SSL TPS 20 VCs ACE4710 with 1 Gbps throughput ACE AP 01 LIC Any combi...

Page 7: ...m an earlier version you may obtain new feature capabilities maximum limits for compression SSL TPS and the number of virtual contexts depending on your current license levels without having to buy new software licenses After you have upgraded to software version A4 2 0 if you need to downgrade to an earlier software version the earlier software version reverts to the earlier feature limits that y...

Page 8: ...follow the instructions that direct you to the following Cisco com website If you are a registered user of cisco com go to the following location http www cisco com go license If you are not a registered user of cisco com go to the following location http www cisco com go license public Step 3 Enter the Product Authorization Key PAK number found on the Software License Claim Certificate as your pr...

Page 9: ...fore you upgrade your ACEs to software version A4 2 0 and later In software version A4 2 0 and later the maximum number of concurrent connections for optimization is reduced to 100 connections If the ACE startup configuration contains the concurrent connections command in optimize configuration mode consider the following If you upgrade the ACE to version A4 2 0 or later the ACE software ignores t...

Page 10: ...ate configuration mode is disabled on the standby ACE and configuration and state synchronization continues A failover from the active ACE to the standby ACE based on priorities and preemption can still occur while the standby is in the STANDBY_WARM state When redundancy peers run on different version images the SRG compatibility field of the show ft peer detail command output displays WARM_COMPAT...

Page 11: ...ACE Software Version A3 2 1 A3 2 2 A3 2 3 A3 2 4 A3 2 5 A3 2 6 A3 2 7 A4 1 0 A4 1 1 A4 2 0 A4 2 1 A4 2 2 A5 1 0 A3 2 1 C C WC WC WC WC WC WC WC WC WC WC WC A3 2 2 C C WC WC WC WC WC WC WC WC WC WC WC A3 2 3 WC WC C WC WC WC WC WC WC WC WC WC WC A3 2 4 WC WC WC C WC WC WC WC WC WC WC WC WC A3 2 5 WC WC WC WC C WC WC WC WC WC WC WC WC A3 2 6 WC WC WC WC WC C WC WC WC WC WC WC WC A3 2 7 WC WC WC WC W...

Page 12: ...atibility If you make any configuration changes on the active ACE during this time your changes are not synchronized to the standby and are lost After you complete the upgrade config sync is automatically reenabled We recommend that you do not make any configuration changes while the two ACEs are in split mode Changing the Admin Password Before you upgrade to ACE software version A3 1 0 or higher ...

Page 13: ...grade procedure Step 1 Use the no form of the duplex command in interface configuration mode to remove the duplex configuration from all configured Gigabit Ethernet ports Step 2 Use the copy running config startup config command to save the changes from the running configuration file to the startup configuration file After you complete the upgrade procedure you can update the duplex settings for t...

Page 14: ...to creating a checkpoint of the running configuration of each context in your ACE we also strongly recommend that you use the copy startup config command to copy the startup configuration of each context to either The disk0 file system on your ACE An TFTP FTP or SFTP server Having a backup of the startup configuration of each context ensures that you can recover your ACE should an issue arise duri...

Page 15: ...T variable image c4710ace t1k9 mz A5_1_0 bin Configuration register is 0x1 Step 7 Remove the existing image from the boot variable on ACE 1 by entering the no boot system image ACE_image command in configuration mode For example to remove the A3 2 1 image enter ACE 1 Admin configure Enter configuration commands one per line End with CNTL Z ACE 1 Admin config no boot system image c4710ace t1k9 mz A...

Page 16: ...ecovered to a STANDBY_HOT state If the standby ACE is running software version A3 2 2 or later the state is STANDBY_WARM Step 12 Perform a graceful failover of all contexts from ACE 1 to ACE 2 by entering the ft switchover all command in Exec mode on ACE 1 ACE 2 becomes the new active ACE and assumes control of all active connections with no interruption to existing connections ACE 1 Admin ft swit...

Page 17: ...timization is reduced to 100 connections If your startup configuration contains the concurrent connections command in optimize configuration mode and you downgrade the ACE from software version A4 2 0 this command is removed from the startup configuration You must reconfigure it after the downgrade process is completed If your ACE includes the 0 5 Gbps bundled license ACE 4710 0 5F K9 that is avai...

Page 18: ...rtup configuration file you may observe a few errors if you did not roll back the configuration to a checkpoint These errors are harmless and occur because the ACE software does not recognize the A4 2 0 or later commands in the startup configuration file Note Dynamic incremental sync is automatically disabled while the active ACE is running software version A4 2 0 or later and the standby ACE is r...

Page 19: ...g and bridging virtualization and so on Cisco ACE Application Control Engine Troubleshooting Wiki Describes the procedures and methodology in wiki format to troubleshoot the most common problems that you may encounter during the operation of your ACE Command Reference Cisco ACE 4700 Series Application Control Engine Provides an alphabetical list and descriptions of all CLI commands by mode includi...

Page 20: ...n protocol and HTTP deep packet inspection TCP IP normalization and termination parameters Network Address Translation NAT Server Load Balancing Guide Cisco ACE Application Control Engine Describes how to configure the following server load balancing features on the ACE Real servers and server farms Class maps and policy maps to load balance traffic to real servers in server farms Server health mo...

Page 21: ...m go trademarks Third party trademarks mentioned are the property of their respective owners The use of the word partner does not imply a partnership relationship between Cisco and any other company 1005R Any Internet Protocol IP addresses used in this document are not intended to be actual addresses Any examples command display output and figures included in the document are shown for illustrativ...

Page 22: ...22 Upgrade Downgrade Guide Cisco ACE 4700 Series Application Control Engine Appliance OL 25719 01 Obtaining Documentation and Submitting a Service Request ...

Reviews: