KB Article | Forcepoint Support

Notes & Warnings

See Using the X-Series Command Line Interface (CLI) for information about new and updated CLI commands in v7.8.4.

Problem Description

My X-Series appliance is at version 7.8.2 or 7.8.3, and I want to upgrade to 7.8.4. How do I upgrade?

Resolution

IMPORTANT:
After upgrade, if you want to enable VLAN support, you must update the configuration of switches A1 and A2 on your X10G chassis. Please refer to the Switch Configuration Guide for details before you begin the upgrade process.

BEFORE YOU BEGIN:
If you are currently using link aggregation, and plan to enable VLAN support after upgrade, you must disable link aggregation before enabling VLAN support on the blade or chassis.

Note that the upgrade process has small but important differences depending on whether you are upgrading from v7.8.2 or v7.8.3. Follow the appropriate procedure below.

Upgrade instructions from v7.8.3

NOTE:
This procedure describes downloading patches directly to each security blade. As an alternative, you can download the patch files from mywebsense.com to a remote filestore, then upload the files from the filestore to each blade. The patch file names are the same regardless of whether you download them directly to the appliance or from mywebsense.com to a filestore.
  1. Log on to the appliance CLI via the security blade iDRAC controller.
  2. Enter config mode.
  3. Use the load patch command with no additional parameters to see a list of upgrade patches available for the appliance.
  4. Select the appliance patch from the list. The patch name is Websense-Patch-APP-7.8.4.rpm.
  5. Repeat steps 3 and 4, selecting the Web Security patch (Websense-Patch-WSE-7.8.4.tgz) and the Content Gateway patch (Websense-Patch-WCG-7.8.4.tgz).
  6. Because the patch download process is asynchronous, use the show patch list command to verify that all three patches are ready to install before you continue. (You can also use the show patch load --status command to track the progress of the patch download.)
  7. Upgrade the policy source machine before upgrading your security blades. See Upgrade Instructions: Web Security Gateway or Upgrade Instructions: Web Security Gateway Anywhere for information about getting the installers used to upgrade off-appliance components.
    Note that in all instances, you must upgrade in the following order:
    1. Full policy source
    2. User directory and filtering (policy lite) security blades, and non-appliance servers that host Policy Server
    3. Filtering only security blades
  8. Use the install patch command with no parameters to see a list of upgrade patches available on the appliance.
  9. Select the appliance patch from the list.
  10. Repeat steps 8 and 9 to install first the Web Security patch, then the Content Gateway patch.
  11. See "Verify the upgrade" at the end of this article for information about verifying the new appliance version.


Upgrade instructions from v7.8.2

  1. Log on to mywebsense.com and select the Downloads tab.
  2. Select Websense X10G Base Configuration from the Product drop-down box, then select version 7.8.4.
  3. Locate the X10G Security Blade Upgrade Patch and download the appliance rpm patch file (Websense-Patch-APP-7.8.4.rpm) to a remote filestore. There are 2 additional patch files that you will download later.
  4. Upgrade the policy source machine before upgrading your security blades. See Upgrade Instructions: Web Security Gateway or Upgrade Instructions: Web Security Gateway Anywhere for information about getting the installers used to upgrade off-appliance components.
    Note that in all instances, you must upgrade in the following order:
    1. Full policy source
    2. User directory and filtering (policy lite) security blades, and non-appliance servers that host Policy Server
    3. Filtering only security blades
  5. Log on to the appliance CLI via the security blade iDRAC controller.
  6. Enter config mode and use the load patch --location <filestore_alias> command to see a list of patches available on the filestore, then select the appliance patch file.
  7. When the patch has been uploaded, use the following command to upgrade the appliance, including the CLI:
    apply patch --file Websense-Patch-APP-7.8.4.rpm
    The upgrade process takes about 15 minutes. Do not restart or turn off the appliance while the upgrade is underway. The patch will automatically restart the appliance to complete the patching process.
  8. After the appliance patch is installed successfully, reconnect to the appliance CLI, either via the iDRAC or via SSH.
  9. Use the load patch command with no additional parameters to see a list of upgrade patches available for the appliance on Websense servers.

    If you download the patches from mywebsense.com to a remote filestore, you can alternatively use the load patch --location <filestore_alias> command to see a list of downloaded patches available in the remote filestore.
     
  10. Select the Web Security patch (Websense-Patch-WSE-7.8.4.tgz) from the list.
  11. Repeat steps 9 and 10 to download the Content Gateway patch (Websense-Patch-WCG-7.8.4.tgz).
  12. Enter the install patch command and select the Web Security patch to begin the Web Security upgrade.
  13. When the Web Security upgrade is complete, enter the install patch command and select the Content Gateway patch to begin the Content Gateway upgrade.

Verify the upgrade

After the upgrade is complete, you can verify the product version from the appliance CLI as follows:

  1. To verify the appliance version, use the command show appliance
  2. To verify the Web Security version, use the command show wse --version
  3. To verify the Content Gateway version, use the command show wcg --version

Article Feedback



Thank you for the feedback and comments.