Upgrading ESA with DSGs and 9.1.0.0/10.x Protectors
This section describes the steps to upgrade ESAs and DSGs with running v9.1.0.0 protectors in backward compatibility mode or v10.x protectors.
Upgrade Approaches for DSG
Two upgrade approaches are available for the DSG upgrade process:
- Canary Upgrade - Reimaging DSG instances to the newer version using ISO or cloud images.
- In-place Upgrade - Upgrading existing DSG instances using patches.
Select the most appropriate upgrade approach based on organizational requirements, infrastructure constraints, and operational considerations.
Important Notes
The steps in this section ensure zero downtime of v9.1.0.0 or v10.x Protectors during ESA upgrade.
Both upgrade approaches will incur DSG downtime during the upgrade process. Plan accordingly to minimize impact on production operations.
Canary Upgrade
The canary upgrade involves reimaging existing DSG instances to the newer version using ISO or cloud images. This can be performed by reusing the same instance or spawning a new instance for DSG and terminating the older version DSGs.
Important: DSG downtime will occur during upgrade. However, downtime can be minimized by spawning fresh DSGs v4.0.0 in parallel to upgrading ESAs.
Phase 1: DR Site Upgrade
For backing up ESAs, refer to Backup all ESAs.
Disable TAC replication job from Primary ESA P1.
For disabling TAC replication, refer to Disable TAC replication job from Primary ESA P1.
Ensure all the prerequisites are followed before proceeding with the upgrade of each ESA.
For more information about the prerequisites, refer to Prerequisites.
Upgrade ESAs S3, S4 and S5 at the Disaster Recovery (DR) site parallely.
For upgrading DR site ESAs, refer to Upgrade ESAs S3, S4 and S5 at the DR site.
Validate DR Site ESAs Post upgrade.
For validating DR site ESAs, refer to Validate DR Site ESAs Post Upgrade.
Stop Application Traffic to DSGs.
Ensure to stop the Application Traffic to any of the DSGs.
- Remove all existing DSGs from the TAC before proceeding with further upgrade steps.
- Stop all existing DSGs to minimize downtime impact.
Redirect Protector Traffic to DR Site.
Adjust configurations to redirect the GTM to point to LTM2. This ensures that protectors communicate with the upgraded ESAs at the DR site.
Important: At this stage, do not add any new protectors. The validations mentioned in the following steps must be performed using existing protectors.
For verifying protector status, refer to Verify Protector Status.
Validate v9.1.0.0 or v10.x Protector Operations.
For protector validation, refer to Validate Protector Operations.
Phase 2: Primary Site Upgrade
Upgrade ESAs P1, S1 and S2 at the Primary site parallely.
For upgrading primary site ESAs, refer to Upgrade ESAs P1, S1 and S2 at the Primary site.
Validate Primary Site ESAs post upgrade.
For validating primary site ESAs, refer to Validate Primary Site ESAs post upgrade.
Installing and configuring the DSGs.
For installing and configuring DSGs, refer to Install and Configure DSGs.
Install DSG Patch on All ESAs.
Install DSG v4.0.0 patch on all ESAs in both Primary and DR sites, that is, ESA P1, S1, S2, S3, S4, and S5.
Redirect Protector Traffic to Primary Site.
Adjust configurations to redirect the GTM to point to LTM1. This allows protectors to resume communication with the ESAs at the Primary site.
Reset Node Status for only the v9.1.0.0 Protectors.
For resetting node status at primary site ESA P1, refer to Reset Node Status for 9.1.0.0 Protectors Only.
For verifying protector status at primary site ESA P1, refer to Verify Protector Status.
Validate v9.1.0.0 or v10.x Protector Operations.
For protector validation, refer to Validate Protector Operations.
Perform ESA communication from all DSGs. For all options in ESA communication, provide GTM IP, hostname or FQDN as applicable. For more information, refer to Setting up ESA communication.
During the prompt for DSG details, provide the FQDN or hostname of any running DSG in the TAC. Ensure the same DSG FQDN/hostname is provided during DSG node registration in all ESAs, that is, P1, S1, S2, S3, S4, and S5.
Verify DSG Cluster Page in ESA.
Verify that all installed DSGs are listed under Cloud Gateway > Cluster page in ESA P1.
Click the Deploy button from the DSG Cluster page in ESA P1 to deploy rulesets to all DSGs present in the TAC. For more information, refer to Deploying configurations to the cluster.
Check Health Status of DSGs from Cluster Page.
After successful deployment of rulesets, verify the health status of DSGs in the TAC from the DSG Cluster page in ESA P1. All DSGs should show health status as green.
For validating DSG operations, refer to Validate DSG Operations.
Phase 3: Post-Upgrade Tasks
For enabling scheduler tasks, refer to Enable Scheduler tasks in Primary site ESAs.
With successful upgrade of DSGs and validation of operations, terminate all older version DSGs that were stopped in Pre-Upgrade Steps for DSG to free up resources.
Migrate Audit Logs from DR Site ESAs to Primary Site ESAs.
When the traffic from protectors is redirected to the DR site ESAs, audit logs are generated in these ESAs. These audit logs need to be migrated to Primary site ESAs. For migrating audit logs, refer to Migrate Audit logs from DR site ESAs to Primary site ESAs.
In-place Upgrade
The in-place upgrade involves upgrading existing DSG instances to the newer version sequentially using patches.
Phase 1: DR Site Upgrade
For backing up ESAs, refer to Backup all ESAs.
Disable TAC replication job from Primary ESA P1.
For disabling TAC replication, refer to Disable TAC replication job from Primary ESA P1.
Ensure all the prerequisites are followed before proceeding with the upgrade of each ESA.
For more information about the prerequisites, refer to Prerequisites.
Upgrade ESAs S3, S4 and S5 at the DR site in parallel.
For upgrading DR site ESAs, refer to Upgrade ESAs S3, S4 and S5 at the DR site.
Validate DR Site ESAs Post Upgrade.
For validating DR site ESAs, refer to Validate DR Site ESAs Post Upgrade.
Stop Application Traffic to DSGs.
Ensure to stop the Application Traffic to any of the DSGs.
Redirect Protector Traffic to the DR Site.
Adjust configurations to redirect the GTM to point to LTM2. This ensures that protectors communicate with the upgraded ESAs at the DR site.
Important: At this stage, do not add any new protectors. The validations mentioned in the following steps must be performed using existing protectors.
For verifying protector status, refer to Verify Protector Status.
Validate Protector Operations.
For validating protector operations, refer to Validate Protector Operations.
For installing DSG patch on DR site ESAs, refer to Install DSG Patch on DR Site ESAs.
For upgrading DSG nodes, refer to Upgrade DSG Nodes.
Restore DSG TAC from the first DSG.
For restore DSG TAC, refer to Restore DSG TAC.
For configuring ESA communication, refer to Configure ESA Communication.
For registering DSG nodes with DR ESAs, refer to Register DSG Node with ESA.
For verifying DSG cluster at ESA S3, refer to Verify DSG Cluster.
For deploying rulesets from ESA S3, refer to Deploy Rulesets.
For verifying DSG health status at ESA S3, refer to Verify DSG Health Status.
For validating DSG operations, refer to Validate DSG Operations.
Phase 2: Primary Site Upgrade
Upgrade ESAs P1, S1 and S2 at the Primary site in parallel.
For upgrading primary site ESAs, refer to Upgrade ESAs P1, S1 and S2 at the Primary site.
Validate Primary Site ESAs post upgrade.
For validating primary site ESAs, refer to Validate Primary Site ESAs post upgrade.
For installing DSG patch on primary site ESAs, refer to Install DSG Patch on Primary Site ESAs.
For registering DSG nodes with primary ESAs, refer to Register DSG Node with ESA.
Redirect Protector Traffic to Primary Site.
Adjust configurations to redirect the GTM to point to LTM1. This allows protectors to resume communication with the ESAs at the Primary site.
Reset Node Status only on the v9.1.0.0 Protectors.
For resetting node status at primary site ESA P1, refer to Reset Node Status (9.1.0.0 Protectors Only).
For verifying protector status at primary site ESA P1, refer to Verify Protector Status.
Validate v9.1.0.0 or v10.x Protector Operations.
For protector validation, refer to Validate Protector Operations.
Verify DSG Cluster Page in ESA.
Verify that all installed DSGs are listed under Cloud Gateway > Cluster page in ESA P1.
Click the Deploy button from the DSG Cluster page in ESA P1 to deploy rulesets to all DSGs present in the TAC. For more information, refer to Deploying configurations to the cluster.
Check Health Status of DSGs from Cluster Page.
After successful deployment of rulesets, verify the health status of DSGs in the TAC from the DSG Cluster page in ESA P1. All DSGs should show health status as green.
For validating DSG operations, refer to Validate DSG Operations.
Phase 3: Post-Upgrade Tasks
Enable Scheduler tasks in Primary site ESAs..
For enabling scheduler tasks, refer to Enable Scheduler tasks in Primary site ESAs.
Migrate Audit logs from DR site ESAs to Primary site ESAs.
When the traffic from protectors was redirected to the DR site ESAs, audit logs will be generated in those ESAs. Those audit logs need to be migrated to Primary site ESAs. For migrating audit logs, refer to Migrate Audit logs from DR site ESAs to Primary site ESAs.
Additional Considerations
Documentation: Maintain detailed records of the upgrade procedure for future reference.
Troubleshooting: Have contingency plans in place to address potential issues during the upgrade. For more information on troubleshooting, refer to Troubleshooting.
Support: Utilize Protegrity support services for guidance or troubleshooting assistance as needed. For assistance, contact Protegrity Support at
support@protegrity.com.
Feedback
Was this page helpful?