Upgrading ESA with DSG

This section describes the steps to upgrade ESAs with DSG (Data Security Gateway) installed. To ensure compatibility and leverage new features, security fixes, and enhancements, both ESAs and DSGs must be upgraded to the latest version.

Prerequisites

Before proceeding with the upgrade, ensure the following requirements are met:

  • All ESAs must be on v9.1.0.0 or above.
  • All DSGs must be on v3.1.0.0 or above.
  • Ensure network connectivity between the DSG installation machine and all ESAs.
  • Ensure ESAs in both Primary site (ESA P1, S1, S2) and Disaster Recovery (DR) site (ESA S3, S4, S5) are operational.
  • Ensure all ESAs and DSGs in the cluster are reachable using hostname or FQDN.
  • Ensure all ESAs and DSGs are using common CA.
  • Review the before you begin section.

If DSGs are installed along with other v9.1.0.0 protectors, refer to Upgrading ESA with DSGs and Protectors.


Upgrade Approaches

There are two upgrade approaches available for DSG, a canary upgrade and an in-place upgrade.

  • The canary upgrade reimages DSG instances to the newer version using ISO or cloud images. Refer to Canary Upgrade for instructions.

  • The in-place upgrade is for upgrading existing instances using patches. Refer to In-place Upgrade for instructions.

Select the appropriate upgrade approach based on organizational requirements, infrastructure constraints, and operational considerations.

Important: Both upgrade approaches will incur DSG downtime during the upgrade process. Plan accordingly to minimize impact on production operations.


Canary Upgrade

The canary upgrade involves reimaging existing DSG instances to the newer version using ISO or cloud images. This can be performed by reusing the same instance or spawning a new instance for DSG and terminating the older version DSGs.

Important: DSG downtime will occur during upgrade. However, downtime can be minimized by spawning fresh DSGs v4.0.0 in parallel to upgrading ESAs.

Phase 1: DR Site Upgrade

  1. Backup all ESAs.

    For backing up ESAs, refer to Backup all ESAs.

  2. Disable TAC replication job from Primary ESA P1.

    For disabling TAC replication, refer to Disable TAC replication job from Primary ESA P1.

  3. Ensure all the prerequisites are followed before proceeding with the upgrade of each ESA.

    For more information about the prerequisites, refer to Prerequisites.

  4. Upgrade ESAs S3, S4 and S5 at the DR site parallely.

    For upgrading DR site ESAs, refer to Upgrade ESAs S3, S4 and S5 at the DR site.

  5. Validate DR site ESAs post upgrade.

    For validating DR site ESAs, refer to Validate DR Site ESAs Post Upgrade.

  6. Stop Application Traffic to DSGs.

    Ensure to stop the Application Traffic to any of the DSGs.

  7. Pre-Upgrade Steps for DSG.

    1. Remove all existing DSGs from the TAC before proceeding with further upgrade steps.
    2. Stop all existing DSGs to minimize the downtime impact.

Phase 2: Primary Site Upgrade

  1. Upgrade ESAs in Primary Site.

    Upgrade ESAs P1, S1 and S2 at the Primary site parallely.

    For upgrading primary site ESAs, refer to Upgrade ESAs P1, S1 and S2 at the Primary site.

  2. Validate Primary Site ESAs post upgrade.

    For validating primary site ESAs, refer to Validate Primary Site ESAs post upgrade.

  3. Install and configure DSGs.

    1. Create fresh DSGs v4.0.0. Perform this step in parallel to upgrading ESAs in Primary Site to minimize DSG downtime. Create DSGs v4.0.0 using ISO or cloud image as applicable.

      For more information, refer to Installing the DSG.

    2. Create a new TAC with reimaged DSGs. Starting with DSG v3.3.0.0, ESAs and DSGs should be in separate TACs. Create a new TAC with DSGs reimaged in the preceding step.

    3. Upload and install DSG Management Server certificates in each DSG individually. Ensure the SAN field in each certificate contains the hostname and FQDN of the DSG node where it will be installed.

  4. Install DSG patch on all ESAs.

    Install DSG v4.0.0 patch on all ESAs in both Primary and DR sites, that is, ESA P1, S1, S2, S3, S4, and S5.

  5. Configure ESA Communication.

    Perform ESA communication from all DSGs. For all options in ESA communication, provide GTM IP, hostname, or FQDN as applicable. For more information, refer to Setting up ESA communication.

  6. Register DSG Node with ESA.

    During the prompt for DSG details, provide the FQDN or hostname of any running DSG in the TAC. Ensure the same DSG FQDN or hostname is provided during DSG node registration in all ESAs, that is, P1, S1, S2, S3, S4, and S5.

  7. Verify DSG Cluster.

    Verify that all installed DSGs are listed under Cloud Gateway > Cluster page in ESA P1.

  8. Deploy Rulesets.

    Click the Deploy button from the DSG Cluster page in ESA P1 to deploy rulesets to all DSGs present in the TAC. For more information, refer to Deploying configurations to the cluster.

  9. Verify DSG Health Status.

    After successful deployment of rulesets, verify the health status of DSGs in the TAC from the DSG Cluster page in ESA P1. All DSGs should show health status as green.

  10. Validate DSG operations.

    1. Confirm that DSGs can perform data security operations post-upgrade.
    2. Verify that audit events are being forwarded successfully to the ESAs.

Phase 3: Post-Upgrade Tasks

  1. Enable Scheduler tasks in Primary site ESAs.

    For enabling scheduler tasks, refer to Enable Scheduler tasks in Primary site ESAs.

  2. Migrate Audit logs from DR site ESAs to Primary site ESAs.

    When the traffic from protectors was redirected to the DR site ESAs, audit logs will be generated in those ESAs. Those audit logs need to be migrated to Primary site ESAs. For migrating audit logs, refer to Migrate Audit logs from DR site ESAs to Primary site ESAs.

  3. Terminate older version DSGs.

    With successful upgrade of DSGs and validation of operations, terminate all older version DSGs that were stopped in Pre-Upgrade Steps for DSG to free up resources.


In-place Upgrade

The in-place upgrade involves upgrading existing DSG instances to the newer version sequentially using patches.

Phase 1: DR Site Upgrade

  1. Backup all ESAs.

    For backing up ESAs, refer to Backup all ESAs.

  2. Disable TAC replication job from Primary ESA P1.

    For disabling TAC replication, refer to Disable TAC replication job from Primary ESA P1.

  3. Ensure all the pre-requisites are followed before proceeding with the upgrade of each ESA.

    For more information about the prerequisites, refer to Prerequisites.

  4. Upgrade ESAs S3, S4 and S5 at the DR site parallely.

    For upgrading DR site ESAs, refer to Upgrade ESAs S3, S4 and S5 at the DR site.

  5. Validate DR Site ESAs post upgrade.

    For validating DR site ESAs, refer to Validate DR Site ESAs Post Upgrade.

  6. Stop Application Traffic to DSGs.

    Ensure to stop the Application Traffic to any of the DSGs.

  7. Redirect GTM to LTM2.

    Adjust configurations to redirect the GTM to point to LTM2. This ensures that DSG nodes, after upgrade, communicate with the upgraded ESAs at the DR site.

    Important: At this stage, do not add any new DSG nodes. Also, do not make any changes to ESA or DSG configurations or rulesets. The validations mentioned in the following steps must be performed using existing DSG nodes.

  8. Install DSG Patch on DR Site ESAs.

    Install DSG v4.0.0 patch on all ESAs in the DR site, that is, ESA S3, S4, and S5.

  9. Upgrade DSG nodes.

    1. Upgrade the DSGs by applying the patch. For more information, refer to Upgrading to DSG 4.0.0.

      • For DSG v3.3.0.1 or later, DSGs can be upgraded in parallel.
      • For DSG versions prior to v3.3.0.1, upgrade DSGs one at a time.
    2. Perform post upgrade steps in DSG. For more information, refer to Post Upgrade Steps.

    3. Upload and install DSG Management Server certificates in each DSG individually. Ensure the SAN field in each certificate contains the hostname and FQDN of the DSG node where it will be installed.

  10. Restore the DSG TAC.

    1. Choose one of the upgraded DSGs as a primary DSG.
    2. Restore DSG TACs from the designated primary DSG that were earlier a part of TAC.
    3. On the CLI Manager, navigate to Tools > Restore DSG-DSG TAC.
    4. Enter the appropriate user credentials and select OK.
    5. All the DSGs that were a part of a TAC and upgraded, are now restored.

  1. Configure ESA Communication.

    Perform ESA communication from all DSGs. For all options in ESA communication, provide GTM IP, hostname or FQDN as applicable. For more information, refer to Setting up ESA communication.

  2. Register DSG Node with ESA.

    During the prompt for DSG details, provide the FQDN or hostname of any running DSG in the TAC. Ensure the same DSG FQDN or hostname is provided during DSG node registration in all ESAs, that is, S3, S4, and S5.

  3. Verify DSG Cluster.

    Verify that all installed DSGs are listed under Cloud Gateway > Cluster page in ESA S3.

  4. Deploy Rulesets.

    Click the Deploy button from the DSG Cluster page in ESA S3 to deploy rulesets to all DSGs present in the TAC. For more information, refer to Deploying configurations to the cluster.

  5. Verify DSG Health Status.

    After successful deployment of rulesets, verify the health status of DSGs in the TAC from the DSG Cluster page in ESA S3. All DSGs should show health status as green.

  6. Validate DSG Operations.

    1. Confirm that DSGs can perform data security operations post upgrade.
    2. Verify that audit events are being forwarded successfully to the DR site ESAs.

Phase 2: Primary Site Upgrade

  1. Upgrade ESAs in Primary Site.

    Upgrade ESAs P1, S1 and S2 at the Primary site parallely.

    For upgrading primary site ESAs, refer to Upgrade ESAs P1, S1 and S2 at the Primary site.

  2. Validate Primary Site ESAs post upgrade.

    For validating primary site ESAs, refer to Validate Primary Site ESAs post upgrade.

  3. Install DSG Patch on Primary Site ESAs.

    Install DSG v4.0.0 patch on all ESAs in the Primary site, that is, ESA P1, S1, and S2.

  4. Register DSG Node with ESA.

    During the prompt for DSG details, provide the FQDN or hostname of any running DSG in the TAC. Ensure the same DSG FQDN or hostname is provided during DSG node registration in all ESAs, that is P1, S1, and S2.

  5. Redirect GTM to LTM1.

    Adjust the configurations to redirect the GTM to point to LTM1. This ensures that DSG nodes communicate with the upgraded ESAs at the Primary site.

  6. Verify DSG Cluster.

    Verify that all installed DSGs are listed under Cloud Gateway > Cluster page in ESA P1.

  7. Deploy Rulesets.

    Click the Deploy button from the DSG Cluster page in ESA P1 to deploy rulesets to all DSGs present in the TAC. For more information, refer to Deploying configurations to the cluster.

  8. Verify DSG Health Status.

    After successful deployment of rulesets, verify the health status of DSGs in the TAC from the DSG Cluster page in ESA P1. All DSGs should show health status as green.

  9. Validate DSG Operations.

    1. Confirm that DSGs can perform data security operations.
    2. Verify that audit events are being forwarded successfully to the ESAs in the Primary site.

Phase 3: Post Upgrade Tasks

  1. Enable Scheduler tasks in Primary site ESAs.

    For enabling scheduler tasks, refer to Enable Scheduler tasks in Primary site ESAs.

  2. Migrate Audit logs from DR site ESAs to Primary site ESAs.

    When the traffic from protectors is redirected to the DR site ESAs, audit logs are generated in these ESAs. These audit logs must be migrated to Primary site ESAs.

    For migrating audit logs, refer to Migrate Audit logs from DR site ESAs to Primary site ESAs.


Additional Considerations

  • Documentation: Maintain detailed records of the upgrade procedure for future reference.

  • Troubleshooting: Have contingency plans in place to address potential issues during the upgrade. For more information on troubleshooting, refer to Troubleshooting.

  • Support: Utilize Protegrity support services for guidance or troubleshooting assistance as needed. For assistance, contact Protegrity Support at support@protegrity.com.


Last modified : February 23, 2026