Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Alex-
MVP Silver
MVP Silver

Upgrade Spark 15x5 from R81.10.17 to R82.00.10 - impact on policy

I upgraded today two Spark Pro from R81.10.17 to R82.00.10 build 2279.

 

First unit: 1535 in remote location, locally managed, certificate-based VPN to central location: no issues

Second unit: 1555 in internal location, centrally managed: Changed version in SC to R82, publish, log in WebUI, upgrade. Update went fine but upon reboot, the Spark was on initial policy mode, waiting for policy installation. All others settings including SIC were preserved.

After policy installation, it was correctly applied and kept being so after updating the default image and rebooting.

I don't know if it's a known issue or a glitch with such upgrades in centrally managed 15x5, but PSA in case you plan this upgrade path.

0 Kudos
4 Replies
Lesley
MVP Platinum
MVP Platinum

Sorry I dont understand what went wrong? 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
Tom_Hinoue
Advisor
Advisor

Are you saying that the policy reverted to [Initial Policy] after major version upgrade? (R81 -> R82)
Then, I think this is by design for centrally managed mode since the installed policy package will be incompatible after upgrade. 

0 Kudos
Alex-
MVP Silver
MVP Silver

That might be so, I never noticed until now.

0 Kudos
PhoneBoy
Admin
Admin

Just to review, when a gateway boots, it needs a policy.
Usually, the gateway will attempt to fetch the latest policy from the management server.
If that fails for some reason, the gateway will attempt to use the last installed policy (stored on the gateway).
If this is not available/incompatible, then the gateway enforces "InitialPolicy" that is fairly restrictive, but should allow for a policy to be installed by management later.

In an upgrade scenario with central management, the last installed policy (either on management or cached on the gateway) is likely from the previous version.
The only option is for the gateway to enforce InitialPolicy until a policy compiled against the correct version is applied.

Which means, this is expected behavior.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events