Forum Discussion
BigIP TMOS upgrades through BigIQ
Like Nikoolayy1 said, testing is always the best way to proceed of you can.
But indeed, I don't remember there beeing an option to perform a "full DSC group upgrade" in BIG-IQ, and even if there was I would be very weary about using it. Do you *really* want to upgrade all devices without testing traffic in the new version? Having an asymmetric cluster allows you to rollback in a very short time in case you find any issues after the upgrade of the first device.
My upgrade process in a 2-device cluster is always like this:
1. Upload images and prepare boot volumes, take backups.
2. Single traffic group? Go to step 4.
3. Multiple traffic groups and active/active config? Force active TGs to standby so that one of the devices is fully on standby.
4. Take the standby device and force it offline.
5. Upgrade the standby device.
6. Get the newly upgraded device online, force TGs to standby on the other one.
7. Test traffic - and this is up to your requirements... I'm used to ISPs asking for about 24 hours on this step.
8. Get the other device offline, upgrade it, get it online.
9. In case of multiple TGs, distribute active/standby as required.
So, you see... BIG-IQ is not exactly a good choice for my method. I prefer having more control over the whole process than letting some external platform do all the steps. My method also allows you to do the time-consuming step of preparing boot volumes beforehand.
/Mike/
- DeepsriAug 25, 2022Altocumulus
Thanks Mike for the very detailed response. The steps that you shared for the upgrade are exactly what we do to upgrade our device pairs. With the frequency of vulnerability's increasing and our frequency of upgrade cycles increasing, we thought of exploring a zero touch OS upgrade approach. But unfortunately that does seem to be the case. Appreciate you for your response sir
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com