It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda CloudGen Firewall

This Firmware Version Is End-Of-Support

Documentation for this product is no longer updated. Please see End-of-Support for CloudGen Firewall Firmware for further information on our EoS policy.

How to Update Control Center Managed F-Series Firewalls

  • Last updated on

The NextGen Control Center can manage multiple clusters each using different firmware versions from 4.2.X to 6.2.X. The Control Center can only manage F-Series Firewalls up the feature level of matching the Control Center firmware. This means it is not possible to configure 6.2. features using a Control Center running an older firmware. You cannot mix different firmware versions in a cluster. When upgrading your firmware, update the Control Center first, then all managed Firewalls, virtual servers and services in the cluster. After all managed Firewalls in a cluster have been updated, you must also migrate the cluster to the new release version.

In this article:

Before you Begin

If you are using SSL Interception on your border firewall, you must add to the SSL Interception Domain Exceptions on the your F-Series Firewall > Virtual Servers > Assigned Services > Firewall > Security Policy page.  


Step 1: Verify the Compatibility of the Control Center Firmware with the Managed Firewalls

The following table shows compatibility between the major versions of the Control Center and various systems. Upgrade the Control Center to the same, or newer, firmware version before updating the managed Firewalls.

For more information, see Updating F-Series Firewalls and Control Centers

Step 2. Download the Update Package from the Download Portal

Download the update package from the Control Center to your desktop client. Only update packages relevant for your cluster versions are displayed. To download files not listed here, go to

Do not use SSL Interception for the connection to the Barracuda Download Portal.

  1. Log into the Control Center.
  2. Go to CONTROL > Firmware Update.
  3. In the lower half of the screen, click on the Download Portal tab.
  4. Move the mouse over the desired update package, click the download icon, and select Download with your Default Browser. Your browser opens to download the desired update file.

Step 2: Import the Update Package into the Control Center

Import the update file to the Control Center.

  1. Log into the Control Center.
  2. Go to CONTROL > Firmware Update.
  3. In the lower half of the screen, click on the Files on NG Control Center tab.
  4. Click Import Update File and select the update package you downloaded in Step 1.

The file is copied to the Control Center and displayed in the Files on NG Control Center tab

Step 3: Send the Update Package to the Systems

  1. On the Firmware Update page, select the Ranges, Clusters, or Boxes to be updated.
  2. In the Files on NG Control Center tab, select the update package.
  3. Click Create Update Task. The New Update Task window opens.
  4. (optional) Select the Scheduling Mode.
  5. Click OK.

The update packages are now copied to the selected remote systems. Go to CONTROL > Update Tasks for more information.

Step 4. Execute the Update Package

  1. Go to CONTROL > Update Tasks.
  2. In the  column, a green icon is displayed, verifying that the update package was sent successfully.
  3. Select the systems which have received the entire update package and right-click the system select Perform Update.
  4. In the Schedule Task window, select Immediate Execution from the Scheduling Mode list and click OK.

Wait for the update to finish. Depending on the system hardware, the process can last anywhere from 15 minutes (for a fast system) to 60 minutes (for flash appliances).

Unless otherwise noted, NextGen F-Series Firewalls will reboot after the update has been applied.

Step 5. Migrate the Configuration Version of the Cluster

If you are updating to a new major version (5.4. to 6.0, 6.0 to 6.1, or 6.1 to 6.2), you must migrate the cluster version after the update has completed.

Update the Clusters Individually
  1. Open the cluster you just updated (CONFIGURATION > Configuration Tree > Multi-Range> your range > your cluster).
  2. Right-click on the cluster and select Lock.
  3. Right-click on the cluster and select Migrate Cluster.
  4. Select the new Release version.
  5. Click OK.
  6. Click Activate
Update all the Clusters in a Range

If all clusters in the range are on the same firmware version, you can migrate all clusters simultaneously. 

  1. Open the range containing the clusters you just updated (CONFIGURATION > Configuration Tree > Multi-Range> your range).
  2. Right-click on the range and select Lock.
  3. Right-click on the range and select Migrate Range.
  4. Select the new Release version.
  5. Click OK.
  6. Click Activate.

Troubleshooting / Logs

After the update process, review the Box\Release\update or Box\Release\update_hotfix log for each system to verify that it was successfully updated. To view a system log, you must connect directly to the system and open the Logs page.

Last updated on