This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Upgrading ESA with 9.1.0.0/10.x Protectors

    This section describes the steps to upgrade ESAs with 9.1.0.0/10.x protectors already installed (excluding DSGs). To ensure compatibility and leverage new features, security fixes, and enhancements, it is necessary to upgrade the ESA to the latest version. This section outlines the required steps for upgrading from a previous version, applicable to both on-premise and cloud platforms.

    Prerequisites

    Before proceeding with the upgrade, refer to Before you begin to ensure all prerequisites are met.

    Important: The steps in this section ensure zero downtime of protectors during ESA upgrade.

    Upgrade Steps

    Phase 1: Disaster Recovery (DR) Site Upgrade

    1. Backup all ESAs

    For backing up ESAs, refer to Backup all ESAs.

    1. Disable TAC replication job from Primary ESA P1

    For disabling TAC replication, refer to Disable TAC replication job from Primary ESA P1.

    1. Ensure all the prerequisites are followed before proceeding with the upgrade of each ESA

    For more information about the prerequisites, refer to Prerequisites.

    1. Upgrade ESAs S3, S4 and S5 at the DR site parallely

    For upgrading DR site ESAs, refer to Upgrade ESAs S3, S4 and S5 at the DR site.

    1. Validate DR Site ESAs Post Upgrade

    For validating DR site ESAs, refer to Validate DR Site ESAs Post Upgrade.

    1. Redirect GTM to LTM2

    Adjust configurations to redirect the GTM so that it points to LTM2. This ensures that protectors communicate with the upgraded ESAs at the DR site.

    Important: At this stage, do not add any new protectors. The validations mentioned in the steps below must be performed using existing protectors.

    1. Verify Protector Status

      For v9.1.0.0 Protectors:

      1. Log in to ESA S3 Web UI.
      2. Navigate to Policy Management and verify:
        • All protector registrations in Data Stores show as GREEN or Ok.
        • Policy Deploy Status shows as GREEN or Ok.

      For v10.x Protectors:

      1. Log in to ESA S3 Web UI.
      2. Navigate to Audit Store > Dashboard. Verify the protector status in Protector Status Dashboard is shown as GREEN or OK.

    1. Validate Protector Operations

      1. Confirm that protectors can perform data security operations after upgrading the ESAs.
      2. Verify that audit events are being forwarded successfully to the ESAs.

    Phase 2: Primary Site Upgrade

    1. Upgrade ESAs P1, S1 and S2 at the Primary site parallely

    For upgrading primary site ESAs, refer to Upgrade ESAs P1, S1 and S2 at the Primary site.

    1. Validate Primary Site ESAs post upgrade

    For validating primary site ESAs, refer to Validate Primary Site ESAs post upgrade.

    1. Redirect GTM to LTM1

    Reconfigure the GTM to point back to LTM1, allowing protectors to resume communication with the ESAs at the primary site.

    1. Reset Node Status for only the v9.1.0.0 Protectors

    At this point, Nodes Connectivity Status of some or all nodes may show as red (Error) or yellow (Warning) under Policy Management > Data Stores in ESA P1 Web UI.

    To reset node status to green (OK), follow these steps:

    1. Log in to ESA P1 Web UI.
    2. Navigate to Policy Management > Data Stores.
    3. Select nodes showing red (Error) or yellow (Warning) status and click the delete button to remove the entry.

    Important: If there are many pepserver nodes registered, delete the nodes in batches of 200.

    After deleting the registered nodes, pepserver nodes will re-register with ESA and the status will become green (OK).

    1. Verify Protector Status

      For 9.1.0.0 Protectors: - Follow the same verification steps as in Phase 1, Step 3. Refer step 1 for steps.

      For 10.x Protectors: - Follow the same verification steps as in Phase 1, Step 3. Refer step 1 for steps.

    2. Validate Protector Operations

      1. Confirm that protectors can perform data security operations post-upgrade.
      2. Verify that audit events are being forwarded successfully to the ESAs.

    Phase 3: Post-Upgrade Tasks

    1. Enable Scheduler tasks in Primary site ESAs

    For enabling scheduler tasks, refer to Enable Scheduler tasks in Primary site ESAs.

    1. Migrate Audit logs from DR site ESAs to Primary site ESAs

    When the traffic from protectors was redirected to the DR site ESAs, audit logs will be generated in those ESAs. Those audit logs need to be migrated to Primary site ESAs. For migrating audit logs, refer to Migrate Audit logs from DR site ESAs to Primary site ESAs.

    Additional Considerations

    • Documentation: Maintain detailed records of the upgrade procedure for future reference.

    • Troubleshooting: Have contingency plans in place to address potential issues arising during the upgrade. For more information on troubleshooting, refer to Troubleshooting.

    • Support: Utilize Protegrity support services for guidance or troubleshooting assistance as needed. For assistance, contact Protegrity Support at support@protegrity.com.