NAC firmware upgrade from 4.1.3 to 4.7 or 4.8, anyone?

I currently have 1 CAS 3310 Failover Bundle for Wireless user, and 1 CAM Lite Failover Bundle for management.
ACAS, CAM and Clean Access Agents are running 4.1.3. We are considering an upgrade in particular because some end-users machine are soon to be Windows 7. Our authenticaion for users is provided by AD SSO.
I would like to know your experience when doing such a major jump (4.1.3 to 4.8.1). Looking for gotchas and known issues. Also what the incremetal upgrade path look like.
I was thinking we can go 4.1.3 -> 4.6.1-> 4.8.1. Any other way or recommendation. CIsco is highly recommending we go to 4.8.1 if all possioblem.
I am also aware that we need to create new root  certificates.
Appreciate input.
Thanks,
Rosa

Hi,
Yes, that is the correct upgrade path: 4.1.3 -> 4.6.1 -> 4.8.1.
I would recomend you to go through the Release notes for 4.6.1 and 4.8.1 for all the known gotchas and detailed upgrade process.
Gotchas/changes/upgrade process for 4.6.1: http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/461/461rn.html#wp65900.
Gotchas/changes/upgrade process for 4.8.1:http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/48/481rn.html#wp65900.
Regarding the certificates, you should not use the self signed certs due to security reasons, and they should only be used for lab purposes.
This means that it still works with the self signed, but you need to import the CAS cert into the CAM trusted certification authorities and vice-versa, so that the CAM trusts the CAS cert and vice-versa.
HTH,
Tiago
If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

Similar Messages

  • Firmware upgrade from 2.1(3a) to 2.1(3b).

    I don't find any documentation on the web for firmware upgrade from 2.1(3a) to 2.1(3b)..
    is it wise to follow this link http://www.cisco.com/en/US/docs/unified_computing/ucs/sw/upgrading/from1.4/to2.1/b_UpgradingCiscoUCSFrom1.4To2.1.html
    Any best practices ?

    I would consult
    http://www.cisco.com/en/US/docs/unified_computing/ucs/sw/firmware-mgmt/gui/2.1/b_GUI_Firmware_Management_21.pdf
    Cisco UCS B-Series GUI Firmware Management Guide, Release 2.1First Published:
    Last Modified: July 12, 2013November 16, 2012

  • SPA112 firmware upgrade from 1.0.1 to 1.2.1 kills the SPA

    I took a brand-new, unconfigured SPA112 out of the box, plugged it into DHCP-enabled network, noted it was running v1.0.1 firmware and attempted a firmware upgrade to 1.2.1 via the web management utility.
    After reporting a successful upgrade there was no further response from the SPA112 to HTTP requests, neither was there any response to pings. ARP requests are responded to successfully. The IVR works (as well as the IVR ever works) until I selected to perform a factory reboot at which point the IVR stopped responding as well. Holding the reset button for 20sec does nothing useful. It's dead, Jim.
    I've had this experience on another SPA112 as well under similar circumstances although there is nothing in the Release Notes for v1.2.1 to say that such an upgrade does not work.
    My questions:
    1)Is there any way of recovering these devices or do I need to send them back to Cisco?
    2) How am I supposed to perform such a firmware upgrade?

    Hi Matthew,
    I tried upgrading the firmware upgrade from v1.0.1 to v 1.2.1 and I had the same problem. The device just stopped responding. I tried that in a lab and I figured out what exactly to do when you get in to a problem like that. So lets start off once again.
    Snce SPA112 must get an IP first through a DHCP on WAN port. Connect the SPA 112 device according to the instructins told in this article till the step 3.
    http://www6.nohold.net/CiscoSB/Loginr.aspx?login=1&pid=4&app=search&vw=1&articleid=2775
    Once you access the web GUI of SPA112 follow the contents of the following article and upgrade the firmware
    http://www6.nohold.net/CiscoSB/Loginr.aspx?login=1&pid=4&app=search&vw=1&articleid=2676
    In your case I believe the window got stucked at the point when it says "The upgrade is successful" and then there was no further response to HTTP requests.
    Restart the device and see if it works or not. If it does not then log in to the router web GUI and navigate to the ARP table and see what are the VLAN assigned to the IP address.
    NOTE: Both the router and SPA should be in the same VLAN. This way only the device will respond to the HTTP requests. If they are in a different VLAN's, navigate to the VLAN and disable the LAN memberships. For example there are two VLAN ID 1 and 100. Disable the LAN ports for the ID 100 and only enable it for 1.
    Navigate to the ARP table again and refresh it. Both the IP addresses should be in the same VLAN. If yes. Access the SPA112 with an IP address assigned to it again and navigate to Administration > Firmware Upgrade. You will see the firmware of the device has been upgraded.
    (optional) Upgrade the firmware again. This time, it will go through and the device will restart.
    Let me know if you still need any help. 

  • How the heck do i get a firmware upgrade from my computer to the router?

    I went to this site here to try and make my router work. It is a WRT54GS wireless router, and I saw where i could download some firmware upgrade, so I clicked on it and saved it to my desktop. It is a .bin file. Now how do I get that file to the router?????
    The router was working until today and now it isn't sending out a wireless signal. However, it is still connecting my computer to the internet through its wire (modem to router, router to computer with cable). But when I open the Easylink software, it says that the internet connection is not working, even though the little green light is on for "wireless" on the front of the router.
    But anyway, how do I get this downloaded file onto the router??? There isn't any usb ports on the router to connect to it. There isn't anything in the Easylink software that gives me that option, or if there is they hid it pretty good. They really should explain how to do this, or do they expect everyone to have a degree in networking or computers or something? I need some help here 

    As sabretooth suggested,Open an Internet Explorer browser page on a computer hard wired to the router...In the address bar type - 192.168.1.1...Leave the Username blank & in Password use admin in lower case...Click on the 'Administration' tab- Then click on the 'Firmware Upgrade' sub tab- Here click on 'Browse' and browse the .bin firmware file and click on "Upgrade"...
    Wait for few seconds until it shows that "Upgrade is successful"  After the firmware upgrade, click on "Reboot" and you will be returned back to the same page OR it will say "Page cannot be displayed".
    Now,Press and hold the reset button for 30 seconds...Release the reset button...Unplug the power cable from your router, wait for 30 seconds and re-connect the power cable...Now re-configure your router...

  • Cisco Nac 3310 Upgrade From 4.1.6 to 4.7.2

    Hi,
    I've to upgrade the NAC Enviroment from 4.1.6 version to 4.7.2 version.
    This is the scenario.
    2 CAM
    2 CAS
    on 3310 Platform in HA-Pairs.
    On Cisco WebSite i found that upgrading to 4.7.2 is possible by this way: 4.1.6 --> 4.1.8 --> 4.5.1 --> 4.7.2. I think that the direct upgrade 4.1.6 --> 4.5.1 is possible. Can you confirm me that?
    Well, I've some questions about this upgrade.
    1) If the upgrade fails, is there any rollback task to do? Reinstall the CAM/CAS and restore the backup or what?
    2) Can you tell me the downtime for the upgrade 4.1.8 --> 4.5.1?
    3) The downtime for the upgrade 4.5.1 --> 4.7.2 ?
    Thanks in advance for the support!!!

    Thanks you very much, really appreciate your help!
    I will follow the procedures that Cisco indicates and i hope that everything will work fine!
    http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/418/418rn.html#wp75888
    http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/45/45rn.html#wp75888
    http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/47/472rn.html#wp75888
    I noticed that the tar.gz for the 4.7.2 frome 4.5.x upgrade is an ISO file. Is this the correct file?
    The attach image shows the content of the file: cca_upgrade-4.7.2-from-4.5.x-4.6.x.tar.gz
    Is right?

  • NAC version upgrade from 4.5.x to 4.7.1-in different geographical location

    I have more than fifteen CAS’s in different geographical location (state) and controlled by CAM HA that is located in another location (state). I’m currently running NAC version 4.5 and planning to upgrade to 4.7.1. due to Windows 7 compatibility problem. My question is that, what is the easiest way to upgrade to 4.7.1  without visiting each location to upgrade CAS’s? Is there away to push the new version from the CAM? Visiting each location is not that convenient. Please let me know.
    Thanks,

    Dereje,
    Unfortunately for upgrading to this version you need the CD in the box and to reboot from that CD. Reason is that we're changing the underlying OS from Fedora Core to CentOS and that requires a complete re-install of a lot of RPMs which isn't possible without booting from the CD.
    HTH,
    Faisal

  • BEFW11S4 v4 firmware upgrade from 1.45.3 to 1.52.02 failing

    I've been having some problems with my router resetting so I decided to upgrade the firmware.  I'm currently on version 1.45.3, Jul 1 2003 and I wanted to update to 1.52.02  4/07/2005.  I downloaded befw11s4_v4_v1.52.02_000_FCC_code.bin from Linksys' site and selected it at http://192.168.1.1/Upgrade.htm.  The progress bar will start to move and when it reaches about 75% I'm redirected to http://192.168.1.1/Upgrade.cgi which is a blank white screen .  If I go back to http://192.168.1.1/ and check the firmware version I see 1.45.3 still. Does anyone have any idea what is going wrong?
    Solved!
    Go to Solution.

    So I just went ahead and called the dreaded customer service.....turns out the filename just needs to be changed. There are 3 easy steps to fix this problem.
    1. If its on your desktop the name should appear as BEFW11S4-v4_v1.52.02_fw,0 change it to befw11s4_v4_1.52.02_000_FCC_code.bin
    2. Go to your upgrade firmware screen, click browse to get the file with the new name
    3. Click upgrade and be happy that it worked!!

  • ASA firmware upgrade from console - tftp error

    Have an asa 5510, trying to upgrade the firmware via console.
    I have a tftp program installed on my PC but get an error running the command, any idea what I'm doing wrong?                  
    asa# copy tftp flash
    Address or name of remote host [142.xx.xx.xx]?  ------------> IP of my PC
    Source filename [asa912-k8.bin]?
    Destination filename [asa912-k8.bin]?
    Accessing tftp://142.xx.xx.xx/asa912-k8.bin...
    %Error opening tftp://142.xx.xx.xx/asa912-k8.bin (No such device)

    Hi,
    You really cant upload files through the Console connection. Its not a network connection.
    Your PC might have an IP address configured but that would be configured in its network interface card which has nothing to do with the console cable connection.
    So you will have to configure one of the ASAs network interfaces with IP address and other basic settings. Then you need to configure the PCs network interface cards settings to match the IP address/subnet configured on the ASA. Then you will have an connection between the ASA and the PC and should be able to load the software to ASA.
    For example
    interface Management0/0
    nameif management
    security-level 100
    ip address 10.10.10.1 255.255.255.0
    no shutdown
    and the configure the PC with IP address 10.10.10.100 and mask 255.255.255.0 for example and then load the software from the PCs IP address of 10.10.10.100.
    - Jouni

  • WLC firmware upgradation from 6.0.196.0 to 7.0.98.0

    Hi,
    I have not come across to upgrade the IOS of WLC at any time .
    Right now , I have WLC 6.0.196.0 and it is working fine but still if in case I need to upgrade to 7.0.98.0 or whichever is latest , What is the procedure ?
    How to go about it ?
    kindly suggest me for the same.

    Hi Vinod,
    Sorry for the late reply.. this forum thingy is messed up.. suddenly this throws me off!! hav to re-login.. strange!! ok lemme get back..
    Main image = The image helps you in getting the GUI and helps you in configuring through the CLI..
    Boot  Loader image = Is almost equal to ROMMON version on switches!! ok lemme  explain u in WLC world.. When you reboot ur WLC, while rebooting if u  hit "Escape" then  you can see something like the Intial WLC config  wizard.. or while doing the PASSWORD recovery we select options 1 to 5..  this is called as Boot loader version..
    The complex explanation is.. A boot loader, also called a boot  manager, is a small program that places the Operating System (OS) of a  computer into Memory. When a computer is powered-up or restarted, the  basic functions performs some initial tests.
    lemme know if this answered your question and mark it as answered if so!!
    Regards
    Surendra
    ====
    Please dont forget to rate the posts which answered your question and mark it as answered or was helpfull

  • Firmware upgrades from Nokia Updater

    Guys !
    Hello Again
    I was unable to update latest firmware through Nokia updator
    when I had 11.0.034 firmware. I consistantly got this message "Your software is up todate" though 20.0.058 software was released. Will Nokia tell us why this ia happening ?
    If my post has helped you please click the white star on the right

    23-Nov-2006 12:38 AM babdi wrote: Guys ! Hello Again I was unable to update latest firmware through Nokia updator when I had 11.0.034 firmware. I consistantly got this message "Your software is up todate" though 20.0.058 software was released. Will Nokia tell us why this ia happening ?
    Your post is unclear. The main reason for this is that you do not mention which phone you're using. Anyow, things such as this can happen because of two (2) reasons:1. You have a branded phone, which contains software customised by your operator
    2. You have a CV-variant, where CV stands for Country Version or Country Variant.
    If the former is the case, you will need to wait until your operator releases the firmware for your specific model; Nokia's responsibility ends here.If the latter is the case, you will have to wait a bit longer, as not all CV's have been added to the database yet. To find out whether you have a CV or not, post the FULL output you have when you press *#0000# on this board (in this topic), and e-mail your product code to Nokia (you may choose to also post your product code on the board.
    V3.0704.1.0.1
    19-01-2007
    RM-133 Nokia N73(57.01) Product Code:0539338

  • Iomega StorCenter NHDD2 Firmware Upgrade from v1.27?

    I hope you can help me;
    I have an old Iomega NAS device that has performed flawlessly for as long as I can remember (2006 I believe?) but having attached a USB HDD to the rear it is only allowing read only access. Would a firmware update solve this?
    If so, how would I go about it as the device does not show up in the LenovoEMC Storage Manager (v1.4.4.14439).
    Thanks in advance,
    Mac

    Hello macaulay576
    Is this a HMNHD? or HMNHD CE (2)?  Could I have you provide the first two digits of the unit's serial number so I can confirm the correct device type?
    If it is one of the HMNHD variants you should be able to modify the connected external drive's access permissions via the web interface.  
    If this is a device older than the HMNHD devices, you should still check the web interface for access permission options for the connected drive (it usually will show up as a share even on the older units)  Firmware may help, but depending on the device an update may not be available any longer.
    LenovoEMC Storage manager should be able to detect most legacy StorCenter devices, if it doesn't the unit may be too old to be detected correctly.  you should then use your router or a network scan to detect the unit's ip address.  the " arp -a " command will work in Windows and OSX to scan your local network and list the detected devices and their ip and mac/physical addresses.
    You may also want to check here to see if there is any further suggestions on the forums.
    LenovoEMC Contact Information is region specific. Please select the correct link then access the Contact Us at the top right:
    US and Canada: https://lenovo-na-en.custhelp.com/
    Latin America and Mexico: https://lenovo-la-es.custhelp.com/
    EU: https://lenovo-eu-en.custhelp.com/
    India/Asia Pacific: https://lenovo-ap-en.custhelp.com/
    http://support.lenovoemc.com/

  • Firmware upgrade from Verizon has caused errors.

    I am unable to see contacts or use the phone.  Contacts: application people (process com.android.htc contacts) has stopped unexpectedly.  Phone: process android.process.acor has stopped unexpectedly.

    Hard Reset is suggested....
    http://community.vzw.com/t5/Android-Apps/After-the-Update-Somthing-to-consider/td-p/642367

  • Firmware upgrade crash

    I've recently acquired my first BB, a Curve 9320 and when I linked it to the Desktop Software was enticed into carrying out a firmware upgrade from v7.1 bundle 1319 to v7.1 bundle 2039
    After automatically running another backup, the upgrade crashed and bricked the device, which has had to be replaced under warranty. The replacement has the original firmware version on it!
    Should I be tempted to try the upgrade again, or play it safe and keep what I've got?

    Hey Sawbones,
    Welcome to the BlackBerry® Support Community Forums.
    I would suggest doing the update from a PC using the BlackBerry® Desktop Software, let me know if you need any assistance.
    Thanks.
    -HB
    Come follow your BlackBerry Technical Team on twitter! @BlackBerryHelp
    Be sure to click Kudos! for those who have helped you.Click Solution? for posts that have solved your issue(s)!

  • WRT45G firmware upgrade

    The WRT45G operated flawlessly until a firmware upgrade from 3.0 to 4.2.1.1
    Periodically, usually after a reboot - Internet (external) access is blocked, and attempts to adjust firewall settings, or restore saved settings fail to correct.
    The only resolution I found - restore to factory settings - allows access to Internet.
    NOTHING else is changed. Nothing has changed on the system except for the firmware update.
    Any ideas how to roll back or to force the router to use the save settings appreciated.
    Its XP - Linksys router and Cablemodem and router set to factory settings.
    Firewall through XP

    What is the exact version number of the router?  Check on the bottom.  Also after all firmware upgrades you are to fully hard reset the router by pressing the reset button on back for 30 seconds and release.  Wait 10 seconds and power cycle the router.  Now you must reconfigure the router from scratch, no backup files.

  • DMS 5.0 DMP Firmware Upgrade

    I'm trying to use DMM 5.0.2 to push a DMP firmware upgrade from the server. I have done it before, but for some reason now when I go to create the "firmware upgrade" job I can't check the image on the list of "Available Assets". The checkbox just physically doesn't work. I have tried a couple of different browsers, to make sure it wasn't something browser-specific.
    Anybody else seen this one? Is it just me?
    Thanks!
    Mike

    I have the same issue.  I have a DMM running 5.2.1, and I just installed a new DMP, out of the box with 5.1.  So I tried the same thing.... First I went to DMP - Adv Tasks - Sys tasks, & created a new app for the firmware update, but it will not let me check the new firmware file that is sitting in the assets.  I am new, and previously a firmware update had been done, and there is an App sitting there for the 5.2.1 update, but when I "edit" the application, it also shows no check in the box for the appropriate file.  I don't know what to do at this point... will have to put a TAC case in.  Let me know if you find the answer.

Maybe you are looking for

  • Moving ipod files onto a mac WITHOUT using a program

    My computer recently crashed and I have a good 30 songs that are new from the itunes store since the last time I backed up my music files. I have a mac formatted ipod and want to be able to put the music on it back onto the computer, but want to do s

  • Turnaround an Purchase Order  to a Sales Order in the same client

    hi,   can any one say me how to turnaround an purchase order(outbound) into a sales order(inbound).

  • How to identify a rehire candidate?

    Hi, Please let us know if you have worked on the following: 1) How can we identify in e-recruiting that an external candidate was a previous employee of the company at some point in time? OR how to identify that the candidate had a record in SAP PA i

  • HSI speed went from ~340kps to ~110kps! Need help!

    I've been a Verizon Customer for well over 10 years and this has never happend to me ever.  My internet service has been down before and after Hurricane Irene has hit NYC for about a month now.  About a week ago Verizon High Speed Internet was finall

  • Reading GEDCOM files

    Hey, there! I am trying to get my mini to be able to read GEDCOM files and can't get safari to do it. I tried to load Explorer in an effort to do it, but that one doesn't seem to do the trick either. Does anyone out there know what I need to do witho