Manual Chapter : Overview: Upgrading BIG-IQ from version 5.2 or 5.3 with a Data Collection Device Cluster

Applies To:

  • BIG-IQ Centralized Management

    7.0.0

Overview: Upgrading BIG-IQ from version 5.2 or 5.3 with a Data Collection Device Cluster

The following upgrade process to BIG-IQ Centralized Management version 7.0.0 is for system setups that currently have version 5.2 or 5.3 installed, and include a data collection device cluster. If your system is not currently running version 5.2 or 5.3 or does not include a data collection device cluster, refer to Supported Upgrade Processes to BIG-IQ Version 7.0.0 on support.f5.com.

This example represents a BIG-IQ a high-availability (HA) configuration with a data collection device (DCD) cluster. During the upgrade, all devices in the DCD cluster are deactivated until they are all upgraded. Data collected from the managed BIG-IP devices resume only after all devices in the DCD cluster are upgraded and restarted.

Before upgrading F5 BIG-IQ Centralized Management, complete these tasks.

Tasks

Additional information

Download the BIG-IQ software image and Pre-upgrade Check tool from the F5 Downloads site.

downloads.f5.com

Run the pre-upgrade check script on the primary BIG-IQ by typing the following command: preUpgradeCheck.

This script verifies the following for BIG-IQ:- Disk assessment and partition size.

  • Health checks

  • Licensing verification.

  • CPU and memory assessment.

Deploy any staged configuration changes to your managed BIG-IP devices.

When addressing configuration conflicts for each BIG-IP device, F5 recommends you use BIG-IP to override the configuration settings stored on BIG-IQ.

Decide which disk volume you want to install the BIG-IQ software on. You must have at least two volumes to upgrade BIG-IQ.

If you don’t have two volumes and are upgrading from versions 5.2 or 5.3, refer to: K17406: Using the tmsh utility to create a new software volume for installing a new image or hotfix on the BIG-IQ system at:https://support.f5.com/csp/article/K17406. If you are upgrading from version 5.4 or later, you can add the second volume as part of the upgrade.

If you are currently using a self-IP address for device discovery, make a note of that IP address.

You’ll need to enter that IP address when you perform setup after you upgrade and reboot the BIG-IQ system.

Upgrade all managed BIG-IP devices to version 12.1 or later.

For you to manage BIG-IP devices from BIG-IQ Centralized Management, the BIG-IP devices must be running version 12.1 or later.

Before you install or upgrade BIG-IQ Centralized Management, it’s important to take inventory of the status of the running daemons. Then after you upgrade, you can verify that they’re in the same state, and make any necessary modifications. To view the daemons, type the following command: admin@(ip-10-1-1-4)(cfg-sync Standalone)(Active)(/Common)(tmos)# show /sys service.

Daemon Example of status
admd down, Not provisioned
alertd run (pid 6579) 22 hours
apmd down, Not provisioned
asm down, Not provisioned
autodosd down, Not provisioned
avrd down, Not provisioned
bigd run (pid 5338) 22 hours
bigiqsnmpd run (pid 5035) 22 hours
captured down, Not provisioned
cbrd run (pid 6117) 22 hours
chmand run (pid 5678) 22 hours
clusterd down, Not required
cman cluster is running
corosync (pid 22585) is running 22 hours
csyncd run (pid 5038) 22 hours
datasyncd down, Not provisioned
dnscached down, Not provisioned
dosl7d down, Not provisioned
dosl7d_attack_monitor down, Not provisioned
dwbld down, Not provisioned
elasticsearch run (pid 5041) 22 hours
errdefsd run (pid 6112) 22 hours
eventd run (pid 5043) 22 hours
evrouted run (pid 6583) 22 hours
f5_update_checker down, No action required
fpuserd down, Not provisioned
fslogd down, Not provisioned
grafana run (pid 6107) 22 hours
gtmd down, Not provisioned
guiserver run (pid 6105) 22 hours
gunicorn run (pid 6587) 22 hours
hwpd down 22 hours, normally up
icontrolportald run (pid 5337) 22 hours
iprepd run (pid 6113) 22 hours
istatsd run (pid 6109) 22 hours
lacpd down, not required
lind run (pid 6116) 22 hours
mcpd run (pid 6110) 22 hours
merged run (pid 6938) 22 hours
mgmt_acld down, Not provisioned
monpd run (pid 6578) 22 hours
named run (pid 4855) 22 hours
nokiasnmpd down, Not enabled
ntlmconnpool run (pid 6111) 22 hours
pabnagd down, Not logging node
pacemakerd (pid 23004) is running 22 hours
pccd down, Not provisioned
pgadmind run (pid 7310) 22 hours
pkcs11d down, Not required
restjavad run (pid 4853) 22 hours
rethinkdb run (pid 15058) 21 hours, 1 start
scriptd run (pid 5344) 22 hours
sdmd down, sdmd is not provisioned
searchd run (pid 5343) 22 hours
sflow_agent run (pid 6937) 22 hours
shmmapd down, Not provisioned
snmpd run (pid 5674) 22 hours
sod run (pid 4810) 22 hours
statsd run (pid 5336) 22 hours
syscalld run (pid 6939) 22 hours
tamd run (pid 5679) 22 hours
tmipsecd run (pid 5341) 22 hours
tmm run (pid 6581) 22 hours
tmrouted run (pid 6581) 22 hours
tokumond run (pid 7311) 22 hours
tokumx run (pid 6580) 22 hours
webd run (pid 6941) 22 hours
wr_urldbd down, Not provisioned
zrd down, Not provisioned
zxfrd run (pid 5034) 22 hours

To ensure that your upgrade goes smoothly, F5 recommends that you perform a few system checks. Perform this test at least a day or so before you upgrade in case you discover any issues that take longer than expected to resolve. Going through this list ahead of time gives you a chance to resolve any issues before the clock is ticking on your upgrade window.

  • Verify that you have completed the pre-upgrade tasks. These are detailed in the article Tasks to complete before you start the upgrade process on support.f5.com.)

  • Verify that the software version of the BIG-IP devices managed by the BIG-IQ you are updating are at or beyond the minimum supported version. (For details on how to do this, refer to the AskF5 article K34133507 on support.f5.com.)

  • If you plan to gather performance Analytics data for the BIG-IP devices managed by the BIG-IQ you are updating confirm that the managed devices are at or beyond version 13.1.1, and provisioned with the AVR service.

  • If you have custom settings for the DCD statistics data collection retention or aggregation, these custom settings are not automatically retained over the upgrade process. Save your data retention and aggregation settings before you begin the upgrade, so you can manually enter your custom settings, once your upgrade is complete. See System > BIG-IQ DATA COLLECTION > BIG-IQ Data Collection Cluster > CONFIGURATION > Statistics Data Collection.

  • Check that you have sufficient disk space for the upgrade. To calculate the disk space you need, make sure you include the space your current installation consumes and the extra amount needed for the upgrade.

    Note: If the var partition for any of the devices in your cluster was extended before you upgraded, you must extend the var partition for that device before the upgrade can succeed.

    (For details on how to do this check, refer to Check the volume sizes on your current BIG-IQ installation and Check the volume sizes required by the software you want to install in F5 BIG-IQ Centralized Management Disk Space Management on support.f5.com. For details on how to extend a disk volume, refer to Resizing VE Disk Volume Workflows in F5 BIG-IQ Centralized Management Disk Space Management on support.f5.com).

  • Verify that your BIG-IQ VE has sufficient memory and CPUs for the configuration that you plan to deploy. (For details on how to do this, refer to Determine the resources required for deployment in Planning and Implementing a BIG-IQ Centralized Management Deployment on support.f5.com).

  • Examine the health of the devices you plan to upgrade. Make sure to inspect the BIG-IQ primary and secondary devices as well as each DCD in the cluster. (For details on how to do this, refer to Check the health of devices in a DCD cluster in Planning and Implementing a BIG-IQ Centralized Management Deployment on support.f5.com).

  • Re-activate the licenses on the devices you plan to upgrade to make sure that the service contract date is up to date. Make sure to do this for the BIG-IQ primary and secondary devices, as well as each DCD in the cluster. (For details on how to do this, refer to the F5 Knowledge Center article K15365 on support.f5.com).

  • Confirm the zone configuration of the DCDs that you plan to upgrade and for the devices managed by the BIG-IQ systems you plan to upgrade. If a device is configured to be in a zone that does not have DCDs in it, statistics for that device will not be collected after the upgrade.

    Note: If the BIG-IQ system you are upgrading includes multiple zones, then in addition to the three DCD minimum, there must also be at least two DCDs in each zone before you can perform a rolling upgrade procedure.

    • To view the zone configuration for a DCD, navigate to System > BIG-IQ DATA COLLECTION > BIG-IQ Data Collection Devices and note the zone.
    • To view the zone configuration for a device, navigate to Devices, click the name of the device, then click STATISTICS COLLECTION and note the zone.

The upgrade process consists of the following phases, where each phase includes a series of tasks.

Important: F5 recommends that you upgrade the BIG-IQ system and the DCD cluster through the user interface. Attempting to use a sequence of tmsh commands will likely result in loss of data.

Important: The upgrade process illustrated here is specific to version 5.2 or 5.3, and requires taking the DCD cluster offline. To prevent losing data, perform this process during a maintenance window. To upgrade from a different version, refer to Choosing the appropriate upgrade process on support.f5.com for guidance.

Preparing for an upgrade

  • Download the BIG-IQ software image from the F5 Downloads site.
  • Upload the latest version of the BIG-IQ software image to the primary BIG-IQ.

Upgrade your DCD cluster.

  • Check the health of the devices in the DCD cluster.
  • Determine available disk space for the devices in the DCD cluster.
  • Prepare the upgrade for your DCD cluster.
  • For each device in the DCD cluster, upload the BIG-IQ software and upgrade the device.

Upgrade the BIG-IQ systems in the HA pair.

  • Remove the secondary BIG-IQ system from the primary BIG-IQ system.
  • Upgrade the primary BIG-IQ system.
  • Upload the latest version of the BIG-IQ software image to the secondary BIG-IQ.
  • Upgrade the secondary BIG-IQ to the latest version.

Complete post-upgrade processes.

  • Add the secondary BIG-IQ system back to the primary BIG-IQ system.
  • Run the post upgrade process.
  • Upgrade the statistics agent.
  • Re-discover devices and re-import services (you can do this either manually or using a script).
  • If you manage devices that use APM services, remove and recreate access groups. There are 3 ways to do this, depending on whether your devices use Secure Web Gateway data and whether you want to do this manually or in bulk.
  • If you plan to deploy applications to a VMware cloud environment, install the vCenter host root certificate on BIG-IQ.