Forum Discussion

HHeredia_36237's avatar
HHeredia_36237
Icon for Nimbostratus rankNimbostratus
Jan 29, 2013

Upgrading ASM

 

 

 

 

Hi guys,

 

 

I'm usually a "LTM guy" but this time I Have the task of upgrading a couple 3600 ASM boxes. I'm really concerned about the information backup since almost all business operations go through this array of controllers (you know how this stuff work).

 

 

Before I proceed with any normal (LTM) upgrade, I like to review the architecture and configuration in order to identify problems that could arise during the window.Also, I ALWAYS do a backup of the current configuration (each controller), but this time (ASM), I'm not sure what to backup!!!.

 

 

Obviously first I have to backup the config via the system>archives procedure but what else should I backup?

 

 

I was thinking about about policies and signatures, Am I right? Any recommendations, ideas, thoughts, experience, jokes?

 

 

Any comment is welcome

 

 

and thanks in advanced!!!

 

 

 

HH

 

5 Replies

  • HH,

     

    I have few questions.

     

     

    What version is running currently and what version are going to?

     

     

    How many application policies do you have?

     

     

    Do any of your policies have XML profile?

     

     

    Do you have any ASM specific iRules?

     

     

    Taking an archive will back up all your ASM policies along with the rest of your configuration. If you are really nervous about this though you can also (depending on how many policies you have) export each of the policies and save them off too.

     

     

    I have been managing ASMs since they were TrafficShield and have gone through a few major rev upgrades. It is not all that different than LTM, in fact during my last upgrade I think I had 2 ASM policy issues and the rest were LTM related bugs that I ran into. I am happy to help where I can.
  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus
    HH,

     

    To add to Mike's post I can agree that this upgrade is similar to the LTM upgrade. Although I took both an Archive and a Policy Export I actually setup the LTM bit from scratch and then exported / imported the existing ASM security policy. The only issue I had with the ASM policy import was because I was going from v9 to v11 we had a Validation error - but this was more to do with how we had one particular setting setup that v9 was happy with but not v11. Application Security - Overview - Summary detailed what we needed to do for the ASM to be happy.

     

     

    Hope this helps,

     

    N
  • Pascal_Tene_910's avatar
    Pascal_Tene_910
    Historic F5 Account

     

     

    http://support.f5.com/kb/en-us/solutions/public/11000/300/sol11318.html?sr=26995633

     

    There is an "ASM consideration" section which may be of use if at some point you need to use the saved archives.

     

    there is also a link for v9.x and v11.x. above link is for 10.x

     

     

    Thanks,

     

    P.
  • Thanks Guys!!!,

     

     

    It's good to know ASM upgrade should be an "LTM-like" procedure. The configuration is not big enough to avoid exporting policies so I'd prefer to do that, just for the case something happens.

     

     

    We're going from 10.2.x to 10.2.4 because the platform it's been experimenting failover (couple times in the last 3 months) , so we filled a support ticket, and while f5 hasn't yet tell us the root cause of the problem, it's recommendation was to do this minor upgrade in order to solve some bug about swapping.

     

     

    We're programming the upgrade this next thursday , if I am still alive I 'll let you know how was it :).

     

     

    Gracias!

     

    P.S. The provisioning thing it's a good tip, thanks!
  • Hi Guys,

     

     

    Just to let you know that everything went OK. It was like an LTM upgrade, as you suggested. The controllers' disk-formatting scheme were already volumes so I just had to install online (stby unit) and then boot in the installed partition. After the big-ip went up it took like 5 minutes to load ASM module.I noticed that when I clicked the ASM>Overview menu and got something like BIG-IP ASM wasn't loaded. Almost died but it was only a matter of time to get things work perfect.

     

     

    Thanks everybody again for the support!!!

     

     

    HH