Before you begin
Ensure that the ESA is upgraded prior to upgrading the protectors.
This is the multi-page printable view of this section. Click here to print.
Ensure that the ESA is upgraded prior to upgrading the protectors.
When ESA is upgraded from v9.1.0.x, then the process is completed over two phases.During Phase 1, the Kernel, OS, and other components are upgraded. After the Phase 1 is completed, the system restarts automatically.
After the system restarts, Phase 2 begins automatically and the critical components of ESA are upgraded.
It is recommended to wait for a few minutes before logging in to the ESA using SSH, to view the upgrade progress.
If logging into the system using SSH is attempted immediately after the system restarts, then an error with
Invalid Credentialsappears. This may occur while LDAP upgrade is in process.
After the upgrade is successful, the system restarts automatically. After the system restarts, log in to the ESA using the CLI Manager or Web UI. When using the SSH, it is recommended to wait for a few minutes before logging in to the ESA.
While upgrading the ESA from v9.1.0.x, the entire process takes approximately 45 minutes. A temporary downtime is expected, resulting in limited access or intermittent interruptions.Additionally, the time taken for creating the backup depends on the actual size of the data which is being backed up. The time taken for the backup is excluded from the upgrade process.
Perform the following steps to upload the patch from the CLI Manager:
The patch file is uploaded.
When upgrading nodes in an Audit Store cluster, if cluster-related checks pass on one node, you can safely ignore similar errors on the other nodes.
While upgrading multiple nodes in the Audit Store cluster, the post-upgrade steps are completed successfully only after all cluster nodes are upgraded. A success message is then logged and shown to the user as a notification message, both, in the ESA UI and the CLI. Investigate post-upgrade errors only after all nodes are upgraded.
Perform the following steps to install the patch from the CLI Manager:
Log in to the ESA CLI Manager with administrator credentials.
Navigate to Administration > Patch Management to install the patch.
Enter the root password and click OK.
Select Install a Patch.
Select the ESA_PAP-ALL-64_x86-64_10.2.0.UP.2631.pty patch file and select Install.
After Phase 1 is installed, following screen appears.

After the reboot is successful, Phase 2 begins automatically.
After Phase 2 is completed, a message for System going down for reboot now appears.After the reboot is successful, then the patch is installed successfully.
The patch is installed successfully and the ESA is upgraded to v10.2.0.
After upgrading the system successfully on v10.2.0, when using the SSH, it is recommended to wait for a few minutes before logging in to the ESA.
After succesfully upgrading the ESA to v10.2.0, apply the ESA 10.2.1 HF patch. This patch contains various vulnerability fixes, package updates, and bug fixes.
When ESA is upgraded from v9.2.0.x, then the upgrade process happens in a single phase.
During the upgrade, the system displays the upgrade progress which appears on the ESA CLI Manager. After the upgrade is successful, the system restarts automatically.After the system restarts, log in to the ESA using the CLI Manager or Web UI.
While upgrading the ESA from v9.2.0.x, the entire process takes approximately 30 minutes. A temporary downtime is expected, resulting in limited access or intermittent interruptions.Additionally, the time taken for creating the backup depends on the actual size of the data which is being backed up. The time taken for the backup is excluded from the upgrade process.
Perform the following steps to upload the patch from the CLI Manager:
The patch file is uploaded.
When upgrading nodes in an Audit Store cluster, if cluster-related checks pass on one node, you can safely ignore similar errors on the other nodes.
While upgrading multiple nodes in the Audit Store cluster, the post-upgrade steps are completed successfully only after all cluster nodes are upgraded. A success message is then logged and shown to the user as a notification message, both, in the ESA UI and the CLI. Investigate post-upgrade errors only after all nodes are upgraded.
Perform the following steps to install the patch from the CLI Manager:
Log in to the ESA CLI Manager with administrator credentials.
Navigate to Administration > Patch Management to install the patch.
Enter the root password and click OK.
Select Install a Patch.
Select the ESA_PAP-ALL-64_x86-64_10.2.0.UP.2631.pty patch file and select Install.
After the patch is installed, select Reboot Now.

This screen has a timeout of 60 seconds. If Reboot Now is not selected manually, then the system automatically reboots after 60 seconds.
After the reboot is initiated, the message Patch has been installed successfully !! appears. Select Exit.
The patch is installed successfully and the ESA is upgraded to v10.2.0.
After upgrading the system successfully on v10.2.0, when using the SSH, it is recommended to wait for a few minutes before logging in to the ESA.
After succesfully upgrading the ESA to v10.2.0, apply the ESA 10.2.1 HF patch. This patch contains various vulnerability fixes, package updates, and bug fixes.
When ESA is upgraded from v10.0.1 or v10.1.0, ensure to apply the hotfix patch before applying the v10.2.0 upgrade patch.
| ESA Version | Hotfix to be applied |
|---|---|
| 10.0.1 | ESA_PAP-ALL-64_x86-64_10.0.2+HF.2451.pty |
| 10.1.0 | ESA_PAP-ALL-64_x86-64_10.1.1+HF.2473.pty |
If upgrading ESA from v10.0.1 or v10.1.0, then the upgrade process happens in a single phase.
During the upgrade, the system displays the upgrade progress which appears on the ESA CLI Manager. After the upgrade is successful, the system restarts automatically.After the system restarts, log in to the ESA using the CLI Manager or Web UI.
While upgrading the ESA from v10.0.1 or v10.1.0, the entire process takes approximately 30 minutes. A temporary downtime is expected, resulting in limited access or intermittent interruptions.Additionally, the time taken for creating the backup depends on the actual size of the data which is being backed up. The time taken for the backup is excluded from the upgrade process.
The ESA patch can be uploaded using the Web UI or the CLI Manager but the patch should only be installed using the CLI Manager.
Perform the following steps to upload the patch from the Web UI:
Log in to the ESA Web UI with administrator credentials.
Navigate to Settings > System > File Upload.The File Upload page appears.
In the File Selection section, click Choose File.The file upload dialog box appears.
Select the patch file and click Open.
Only a user with the administrative role can perform this action.
Click Upload.
After the file is uploaded successfully, then from the Uploaded Files area, choose the uploaded patch.The information for the selected patch appears.

Perform the following steps to upload the patch from the CLI Manager:
The patch file is uploaded.
When upgrading nodes in an Audit Store cluster, if cluster-related checks pass on one node, you can safely ignore similar errors on the other nodes.
While upgrading multiple nodes in the Audit Store cluster, the post-upgrade steps are completed successfully only after all cluster nodes are upgraded. A success message is then logged and shown to the user as a notification message, both, in the ESA UI and the CLI. Investigate post-upgrade errors only after all nodes are upgraded.
Perform the following steps to install the patch from the CLI Manager:
Log in to the ESA CLI Manager with administrator credentials.
Navigate to Administration > Patch Management to install the patch.
Enter the root password and click OK.
Select Install a Patch.
Select the ESA_PAP-ALL-64_x86-64_10.2.0.UP.2631.pty patch file and select Install.
After the patch is installed, select Reboot Now.

This screen has a timeout of 60 seconds. If Reboot Now is not selected manually, then the system automatically reboots after 60 seconds.
After the reboot is initiated, the message Patch has been installed successfully !! appears. Select Exit.
The patch is installed successfully and the ESA is upgraded to v10.2.0.
After upgrading the system successfully on v10.2.0, when using the SSH, it is recommended to wait for a few minutes before logging in to the ESA.
After succesfully upgrading the ESA to v10.2.0, apply the ESA 10.2.1 HF patch. This patch contains various vulnerability fixes, package updates, and bug fixes.
Perform the following steps to verify the patch installation:
The ESA is upgraded to v10.2.0.
During the upgrade process, logs describing upgrade process are generated. The logs describe the services that are initiated, restarted, or the errors generated.
To view the logs under the /var/log directory from the CLI Manager, navigate to CLI Manager > Administration > OS console.
| Log Type | Description |
|---|---|
| syslog | Provides collective information about the syslogs. |
| upgrade_10.2.0.log | Provides the information of real time logs, when upgrading the ESA from v9.1.0.x. |
| patch_ESA_10.2.0_UPGRADE_INSTALLER.log |
|
| patch_ESA_10.2.0_UPGRADE_PHASE_2.log |
|
After upgrading all the ESAs in the Trusted Appliance Cluster to v10.2.0, ensure that all the nodes in the cluster are healthy.
Perform the following steps to verify health of ESAs in the TAC.
These steps must be performed individually on each ESA node in the Trusted Appliance Cluster.