Updates, patches, and hotfixes are published in update archives. Depending on the deployment type, the update process differs. The firewall and/or Control Center must be able to access the following Barracuda services to access the downloads:
Updating a Stand-alone Firewall or Control Center
You can update a stand-alone F-Series Firewall or Control Center using NextGen Admin or on the command line. If the firewall or Control Center can access the Barracuda update servers, download and install the updates directly from the NextGen Admin UPDATES element on the dashboard. For units that do not have access to the download server, or if the update is not available in the dashboard element, you can also manually install the update. For flash-based models such as the F10, F100, or F101, it is recommended to update the firewall via command line.
- NextGen Admin DASHBOARD – Download and install the update via the UPDATE element. For more information, see How to Install Updates via NextGen Admin.
- NextGen Admin Manual Upload – Manually upload and install the update file via NextGen Admin. For more information, see How to Manually Install Updates via NextGen Admin.
- Command Line – Manually download the update files, copy them to the firewall or Control Center, and trigger the update on the command line. For more information, see How to Install Updates via SSH.
Updating a High Availability Cluster
To avoid downtime when updating a high availability cluster, you must update only the firewall that is in standby and then transfer the virtual server to the updated unit before the firmware is updated on the other firewall as well.
For more information, see How to Update High Availability Clusters or How to Update Managed High Availability Clusters with Automatic Failover.
Updating Managed Firewalls
The Control Center can distribute and install updates on all its managed F-Series Firewalls. If the Control Center has access to the Internet, all hotfixes, updates, and patches can be downloaded directly to the Control Center. If the Control Center has no Internet connection, you can also manually upload the update archives. The managed firewalls are placed in update groups. The admin can then decide to update a single firewall or an entire update group. When the update archive has been transferred to the firewall, the admin can trigger the update. Copying the update can be scheduled to be performed when it does not impact other traffic.
Since all F-Series Firewalls in a cluster must have the same firmware version, all the firewalls in a cluster must be updated at the same time. Migrate the cluster configuration after updating the units.