Upgrading ESA with 9.1.0.0/10.x Protectors
This section describes the steps to upgrade ESAs with 9.1.0.0/10.x protectors already installed (excluding DSGs). To ensure compatibility and leverage new features, security fixes, and enhancements, it is necessary to upgrade the ESA to the latest version. This section outlines the required steps for upgrading from a previous version, applicable to both on-premise and cloud platforms.
Prerequisites
Before proceeding with the upgrade, refer to Before you begin to ensure all prerequisites are met.
Related Documentation
- If DSGs are installed with other protectors, refer to Upgrading ESA with DSGs and Protectors
- If only DSGs are installed, refer to Upgrading ESA with DSG
Important: The steps in this section ensure zero downtime of protectors during ESA upgrade.
Upgrade Steps
Phase 1: Disaster Recovery (DR) Site Upgrade
For backing up ESAs, refer to Backup all ESAs.
For disabling TAC replication, refer to Disable TAC replication job from Primary ESA P1.
For more information about the prerequisites, refer to Prerequisites.
For upgrading DR site ESAs, refer to Upgrade ESAs S3, S4 and S5 at the DR site.
For validating DR site ESAs, refer to Validate DR Site ESAs Post Upgrade.
Adjust configurations to redirect the GTM so that it points to LTM2. This ensures that protectors communicate with the upgraded ESAs at the DR site.
Important: At this stage, do not add any new protectors. The validations mentioned in the steps below must be performed using existing protectors.
For v9.1.0.0 Protectors:
- Log in to ESA S3 Web UI.
- Navigate to Policy Management and verify:
- All protector registrations in Data Stores show as GREEN or Ok.
- Policy Deploy Status shows as GREEN or Ok.
For v10.x Protectors:
- Log in to ESA S3 Web UI.
- Navigate to Audit Store > Dashboard. Verify the protector status in Protector Status Dashboard is shown as GREEN or OK.
- Confirm that protectors can perform data security operations after upgrading the ESAs.
- Verify that audit events are being forwarded successfully to the ESAs.
Phase 2: Primary Site Upgrade
For upgrading primary site ESAs, refer to Upgrade ESAs P1, S1 and S2 at the Primary site.
For validating primary site ESAs, refer to Validate Primary Site ESAs post upgrade.
Reconfigure the GTM to point back to LTM1, allowing protectors to resume communication with the ESAs at the primary site.
At this point, Nodes Connectivity Status of some or all nodes may show as red (Error) or yellow (Warning) under Policy Management > Data Stores in ESA P1 Web UI.
To reset node status to green (OK), follow these steps:
- Log in to ESA P1 Web UI.
- Navigate to Policy Management > Data Stores.
- Select nodes showing red (Error) or yellow (Warning) status and click the delete button to remove the entry.
Important: If there are many pepserver nodes registered, delete the nodes in batches of 200.
After deleting the registered nodes, pepserver nodes will re-register with ESA and the status will become green (OK).
For 9.1.0.0 Protectors: - Follow the same verification steps as in Phase 1, Step 3. Refer step 1 for steps.
For 10.x Protectors: - Follow the same verification steps as in Phase 1, Step 3. Refer step 1 for steps.
- Confirm that protectors can perform data security operations post-upgrade.
- Verify that audit events are being forwarded successfully to the ESAs.
Phase 3: Post-Upgrade Tasks
For enabling scheduler tasks, refer to Enable Scheduler tasks in Primary site ESAs.
When the traffic from protectors was redirected to the DR site ESAs, audit logs will be generated in those ESAs. Those audit logs need to be migrated to Primary site ESAs. For migrating audit logs, refer to Migrate Audit logs from DR site ESAs to Primary site ESAs.
Additional Considerations
Documentation: Maintain detailed records of the upgrade procedure for future reference.
Troubleshooting: Have contingency plans in place to address potential issues arising during the upgrade. For more information on troubleshooting, refer to Troubleshooting.
Support: Utilize Protegrity support services for guidance or troubleshooting assistance as needed. For assistance, contact Protegrity Support at
support@protegrity.com.
Feedback
Was this page helpful?