Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Firmware Upgrades

Upgrade firmware at specific sites or across your entire organization.

Upgrade Options

You can manage and monitor upgrades on the Organization > Admin > Firmware Upgrades page.

  • To upgrade automatically as new firmware is available—Click Auto Upgrade Settings at the top-right corner of the page. For help with this feature, see Enable Automatic Upgrades.

  • To do a one-time upgrade—Click Schedule Upgrade at the top-right corner of the page. For help with this feature, see Set Up an Ad Hoc Upgrade.

  • To view upcoming and completed upgrades—Click a device tab at the top of the page. For help with this feature, see View the Status or Modify a Scheduled Upgrade.

Enable Automatic Upgrades

Enable Mist to automatically upgrade devices based on certain parameters. You specify the device types, the sites, and the firmware that you want. You can even set it up to select a different firmware version for different device models.

If you enable automatic upgrade for switches or WAN Edges, the upgrade is triggered only when the devices connect to the Mist cloud for the first time.

Note: If you want to perform a one-time upgrade instead, see Set Up an Ad Hoc Upgrade.
To enable automatic upgrades:
  1. From the left menu, select Organization > Firmware Upgrades.
  2. Click Auto Upgrade Settings near the top-right corner of the page.
  3. Select the device type, and then select the options for the upgrade.

    Depending on the device type, follow these tips:

    • WAN Edges

      WAN Edges Upgrade Options in the Configure Auto Upgrade Window
      • Drag the slider bar to enable Enable auto upgrade.

      • Select the same firmware version for All SRXs and for All SSRs, or select Show All Models and specify different versions for different models. To omit a model from the upgrade, select None from the drop-down list.

      • Create a recovery snapshot—This option is selected by default and is recommended so that you can restore from the backup if needed. You can clear this check box if you don't want to create a snapshot.

      • End User License Agreement—Use the link to read the information, and then select the check box to accept the agreement.

    • Switches

      Switches Upgrade Options in the Configure Auto Upgrade Window
      • Drag the slider bar to enable Enable auto upgrade.

      • Select the firmware version for each model. To omit a model from the upgrade, select None from the drop-down list. If no upgrade is available, you'll see an indicator such as n/a for this model.

      • Create a recovery snapshot—This option is selected by default and is recommended so that you can restore from the backup if needed. You can clear this check box if you don't want to create a snapshot.

      • End User License Agreement—Use the link to read the information, and then select the check box to accept the agreement.

  4. Click Save.

Notifications of upcoming upgrades will appear on device list views and site configuration pages.

If needed, repeat this procedure to enable automatic upgrades for other device types.

Review, Disable, or Modify an Automatic Upgrade

From the left menu, select Organization > Firmware Upgrades. Then click Auto Upgrade Settings.

  • To review the settings—Click the device type for the automation that you want to review. View the on-screen information. When finished, click Cancel.

  • To disable an automation—Click the device type for the automation that you want to disable. Turn off Enable auto upgrade. Click Save.

  • To modify the settings—See Enable Automatic Upgrades.

Set Up an Ad Hoc Upgrade

With this approach, you can run an upgrade whenever you need to. Maybe you have a few new devices that you want to upgrade right away. Maybe you want to install a specific firmware version on a few devices for testing purposes. You can set up this upgrade to run immediately or in a specified maintenance window.

Note:

Keep in mind, although the scheduling option is a form of automation, this approach is not the same as "auto upgrades." The auto upgrade process runs repeatedly to regularly check for new firmware. A scheduled upgrade runs once. To set up recurring upgrades, see Enable Automatic Upgrades.

To set up an ad hoc upgrade:
  1. From the left menu, select Organization > Firmware Upgrades.
  2. Click Schedule Upgrade near the top-right corner of the page.
  3. At the top of the pop-up window, click a Device Type.
  4. Set the Scope:
    • To include your entire organization—Turn on Entire Org.

    • To specify sites—Turn off Entire Org. Then use the Add Site option to add one or more sites.

    The screen displays the models present in the selected organization or sites.
  5. Under Device Type, click the tab for the device that you want to upgrade.
  6. Depending on the selected device type, enter the upgrade options that appear.
    • Version (switches and WAN edges)—Select the firmware version for each model that you want to upgrade. Or select None to omit a model from the upgrade.

      Note: To see a list of the devices for each model, hover your mouse over the devices link.
    • Reboot without upgrade (switches only)—Turn on this feature to reboot, not upgrade, switches.

      Reboot without upgrade
    • Match Criteria (switches and WAN edges)—Turn on this feature to identify specific devices. Then enter a name to use to find the devices. Also specify an offset number, which indicates where to look for these characters in the specified name. For example, let's say your device names follow the pattern site-usage-device, such as SiteA-IOT-device1. You want to find all your IOT devices. You enter the characters IOT as the match criteria and 7 as the offset. (Look for matching characters in the device name, starting with the 7th character.) To save these options, click Apply.

      Match Criteria
      Note: When using this feature for WAN edges, you also can search for role. For switches, you can only search for the device name.
    • SRX or SSR (WAN edges)—If you have both SRX and SSR devices, complete the firmware version sections for all devices by using the SRX and SSR tabs.

    • OS and Service Upgrade or Service Upgrade (Mist Edges only)—Choose whether to do a complete upgrade or to update the tunnel service only.

  7. At the bottom of the pop-up window, select the Scheduling options:
    • Reboot Now (if you selected the Reboot option)—Reboot the switches immediately after you complete the steps in this pop-up window.

    • Reboot Later (if you selected the Reboot option)—Specify a date and time to reboot the switches.

    • Upgrade Now—Run the upgrade immediately after you complete the steps in this pop-up window.

    • Schedule upgrade—Run the upgrade at a date and time that you specify.

      • If your scope includes the entire organization or multiple sites, the upgrade will run at the specified time in each site's own time zone.

      • If you want to reboot at a specific time, rather than immediately after the firmware is installed, click Set a different reboot time, and then select the date and time.

  8. (Optional) Click Advanced Settings to consider these device-specific options:

    AP Advanced Settings

    • Specify how devices download firmware:

      • Direct—All devices download and install images at the same time. This is the fastest and most common approach.

      • Peer-to-peer—Devices can download firmware images directly from peer devices instead of downloading from the cloud. This approach uses less bandwidth.

    • Specify how devices reboot after upgrading:

      • Simultaneous—Devices reboot all at once. This is the fastest and most common approach.

      • RRM Based—The reboot sequence is determined by considering client count and neighboring devices. This is a balanced approach.

      • Serial—Devices reboot one at a time. This is a low-impact approach.

    Switches and WAN Edges Advanced Settings

    • Specify how devices download firmware and how the devices reboot:

      • Simultaneous—All devices upgrade at once. It's the fastest and most common approach.

      • Phased—Upgrades proceed in phases, based on the percentages that you enter in the Download Canary Phases box. For example, if you enter 5, 25, 50, 100, 5 percent of the devices will be upgraded in the first phase, 25 percent in the second phase, 50 percent in the third, and 100 in the fourth. This is a balanced approach.

      • Serial—The devices upgrade and reboot one at a time. This is a low-impact approach.

    Mist Edges Advanced Settings

    Specify how devices upgrade and reboot:

    • Simultaneous—All devices upgrade and reboot at once. It's the fastest and most common approach.

    • Optimized—The devices are grouped by cluster or site and are prioritized based on the tunnel count. This is a low-impact approach.

    • Serial—The devices upgrade and reboot one at a time. This is a low-impact approach.

  9. Select or clear Recovery Snapshot.

    When this option is selected, you'll have a snapshot that you can restore from if issues occur.

  10. Click the link to read the End User License Agreement, and then select the check box to accept it.
  11. At the bottom of the pop-up window, click Schedule.

The selected actions are performed according to the schedule that you set.

Notifications of upcoming upgrades will appear on device list views and site configuration pages, alerting administrators.

If needed, repeat this procedure to schedule other upgrades.

View the Status or Modify a Scheduled Upgrade

From the left menu, select Organization > Admin > Firmware Upgrades. Then click a device tab at the top of the page.

In the main area of the page, click the tab for Scheduled (upcoming upgrades) or Past(completed upgrades). You'll see high-level information for each upgrade.

  • To see more details—At the left side of the row, click the arrow button to see more details.

  • To change the settings—(not available for past upgrades) At the left side of the row, click the arrow button. On the right side of the screen, click Edit. Make your changes, and then click Save.

  • To cancel—(not available for past upgrades) At the left side of the row, click the arrow button. On the right side of the screen, click Cancel Upgrade. When the confirmation message appears, click Cancel Upgrade.