Upgrading ESA with 9.1.0.0/10.x Protectors

This section describes the steps to upgrade ESAs with 9.1.0.0/10.x protectors already installed (excluding DSGs). To ensure compatibility and leverage new features, security fixes, and enhancements, it is necessary to upgrade the ESA to the latest version. This section outlines the required steps for upgrading from a previous version, applicable to both on-premise and cloud platforms.

Prerequisites

Before proceeding with the upgrade, refer to Before you begin to ensure all prerequisites are met.

Important: The steps in this section ensure zero downtime of protectors during ESA upgrade.

Upgrade Steps

Phase 1: Disaster Recovery (DR) Site Upgrade

  1. Backup all ESAs

For backing up ESAs, refer to Backup all ESAs.

  1. Disable TAC replication job from Primary ESA P1

For disabling TAC replication, refer to Disable TAC replication job from Primary ESA P1.

  1. Ensure all the prerequisites are followed before proceeding with the upgrade of each ESA

For more information about the prerequisites, refer to Prerequisites.

  1. Upgrade ESAs S3, S4 and S5 at the DR site parallely

For upgrading DR site ESAs, refer to Upgrade ESAs S3, S4 and S5 at the DR site.

  1. Validate DR Site ESAs Post Upgrade

For validating DR site ESAs, refer to Validate DR Site ESAs Post Upgrade.

  1. Redirect GTM to LTM2

Adjust configurations to redirect the GTM so that it points to LTM2. This ensures that protectors communicate with the upgraded ESAs at the DR site.

Important: At this stage, do not add any new protectors. The validations mentioned in the steps below must be performed using existing protectors.

  1. Verify Protector Status

    For v9.1.0.0 Protectors:

    1. Log in to ESA S3 Web UI.
    2. Navigate to Policy Management and verify:
      • All protector registrations in Data Stores show as GREEN or Ok.
      • Policy Deploy Status shows as GREEN or Ok.

    For v10.x Protectors:

    1. Log in to ESA S3 Web UI.
    2. Navigate to Audit Store > Dashboard. Verify the protector status in Protector Status Dashboard is shown as GREEN or OK.

  1. Validate Protector Operations

    1. Confirm that protectors can perform data security operations after upgrading the ESAs.
    2. Verify that audit events are being forwarded successfully to the ESAs.

Phase 2: Primary Site Upgrade

  1. Upgrade ESAs P1, S1 and S2 at the Primary site parallely

For upgrading primary site ESAs, refer to Upgrade ESAs P1, S1 and S2 at the Primary site.

  1. Validate Primary Site ESAs post upgrade

For validating primary site ESAs, refer to Validate Primary Site ESAs post upgrade.

  1. Redirect GTM to LTM1

Reconfigure the GTM to point back to LTM1, allowing protectors to resume communication with the ESAs at the primary site.

  1. Reset Node Status for only the v9.1.0.0 Protectors

At this point, Nodes Connectivity Status of some or all nodes may show as red (Error) or yellow (Warning) under Policy Management > Data Stores in ESA P1 Web UI.

To reset node status to green (OK), follow these steps:

  1. Log in to ESA P1 Web UI.
  2. Navigate to Policy Management > Data Stores.
  3. Select nodes showing red (Error) or yellow (Warning) status and click the delete button to remove the entry.

Important: If there are many pepserver nodes registered, delete the nodes in batches of 200.

After deleting the registered nodes, pepserver nodes will re-register with ESA and the status will become green (OK).

  1. Verify Protector Status

    For 9.1.0.0 Protectors: - Follow the same verification steps as in Phase 1, Step 3. Refer step 1 for steps.

    For 10.x Protectors: - Follow the same verification steps as in Phase 1, Step 3. Refer step 1 for steps.

  2. Validate Protector Operations

    1. Confirm that protectors can perform data security operations post-upgrade.
    2. Verify that audit events are being forwarded successfully to the ESAs.

Phase 3: Post-Upgrade Tasks

  1. Enable Scheduler tasks in Primary site ESAs

For enabling scheduler tasks, refer to Enable Scheduler tasks in Primary site ESAs.

  1. Migrate Audit logs from DR site ESAs to Primary site ESAs

When the traffic from protectors was redirected to the DR site ESAs, audit logs will be generated in those ESAs. Those audit logs need to be migrated to Primary site ESAs. For migrating audit logs, refer to Migrate Audit logs from DR site ESAs to Primary site ESAs.

Additional Considerations

  • Documentation: Maintain detailed records of the upgrade procedure for future reference.

  • Troubleshooting: Have contingency plans in place to address potential issues arising during the upgrade. For more information on troubleshooting, refer to Troubleshooting.

  • Support: Utilize Protegrity support services for guidance or troubleshooting assistance as needed. For assistance, contact Protegrity Support at support@protegrity.com.


Last modified : February 23, 2026