Secure the update process
When applying appliance upgrades and patches, review and follow the guidance in the Forcepoint Network Security Platform Product Guide to ensure that the update is secure.
For more information, see the SMC Appliance maintenance chapter and the Upgrading Security Engines chapter in the Forcepoint Network Security Platform Product Guide.
You can download all the installation files that you need to manually upgrade the SMC Appliance or Security Engine from https://support.forcepoint.com/s/download.
SMC Appliance and Security Engine updates are verified using ECDSA P-521 with SHA-512 digital signatures and a pre-installed public key.
The commands used to update the SMC Appliance verify the digital signature and reject any update that is not valid.
For Security Engine updates, the SMC verifies the Security Engine update signature when the update is imported to the SMC. Only valid updates can be imported and installed on the Security Engine.
Update Failures
The update process can fail for the following reasons:
- The digital signature verification fails for the update. When the signature verification fails the update is not imported. Therefore there is no need to remove the invalid update. Verify that the update is intended for the particular product component and version before importing it.
- The storage space is exceeded while importing the update. Take the following steps to remove any earlier updates that are no longer needed:
- Select .
- Remove the unnecessary imported Engine Upgrades. To remove the upgrade, right-click the upgrade and select the Delete option.
- Select .
- Remove the unnecessary imported SMC Appliance Patches. To remove the patch, right-click the patch and select the Unload option.
- Try to import the update again.
When upgrading the Security Engine system to a newer major release, it is necessary to update the virtual SMC Appliance before the Security Engines. The order is not significant when applying maintenance release updates.
If an incorrect Security Engine version update was applied, you can revert to the previous installed Security Engine version. Restart the appliance and select the previous version from the boot menu on the appliance console.
Follow these steps to patch the SMC Appliance:
Steps
- Download the SMC Appliance patch file (7.3.2U001.sap, for example) from https://support.forcepoint.com/s/download.
- To patch or upgrade the SMC Appliance, see the Patch or upgrade the SMC Appliance on the command line topic in the Forcepoint Network Security Platform Installation Guide.