Deployment rollback
Deployment rollback is the process of reverting a device to a previously saved configuration state. This operation allows you to restore the device to its earlier state if a recent policy deployment results in unintended traffic behavior.
Note | Rollback is a disruptive operation. Executing a rollback terminates all existing connections and resets routing tables, which will cause a temporary interruption of traffic. |
Identifying the disruptive configuration
When a deployment has caused unintended traffic interruption, identify the specific change responsible for the condition. To compare current and previous deployments:
Before a rollback
-
Choose , expand the last deployed job that caused the traffic disruption, and click the Preview (
).The preview page lets you compare deployments to identify specific changes from previous configurations.
-
After identifying the change causing the problem, rectify the configuration and redeploy it on the device.
After a rollback
-
After a successful rollback, choose , and click the Preview icon next to the rolled back device.
-
View the changes between the rolled back configuration and the current changes in the Cloud-Delivered Firewall Management Center that are pending deployment.
-
After identifying the change causing the problem, rectify the configuration, and redeploy it on the device.
Rollback reverts most configurations, but some exceptions apply. Refer the table below for details.
Rollback guidelines
Follow these guidelines to ensure successful configuration rollbacks.
-
You have to perform a deployment before you can roll back again.
-
After you perform a rollback, the rolled back devices are marked as out-of-date on the Cloud-Delivered Firewall Management Center. The changes you made to the configuration are still pending for the next deployment. To see the pending changes, choose , and click the Preview icon next to the rolled back device.
-
For devices with very large access lists, if the Object Group Search setting is disabled, then the rollback operation may take a longer duration to complete. To verify the Object Group Search setting, choose , and then select the device and click Edit Advanced Settings.
-
For the Firepower 4100/9300, make sure your current Firewall Chassis Manager interface configuration is the same for any rollback versions. Otherwise, the rollback interface configuration may not match your actual interfaces.
-
Independent certificate enrollments are also listed as deployment jobs in the Deployment History page. However, you cannot roll back to these versions. A rollback from a deployment version created after certificate enrollments reverts the certificate associations as well. In the next deployment after a rollback, manually associate the certificates before proceeding with the deployment.
-
If a deployment for a device with a FlexConfig object configured with a deployment frequency set to Once is rolled back, then you will not be able to redeploy the object even though it is displayed as out-of-date on the Preview page. After a rollback, you will have to manually unassign and then reassign the FlexConfig object to the device before the next deployment.
Rollback limitations
Observe these limitations that restrict the use of rollback functionality.
-
You can roll back to any one of the last 10 versions before the currently deployed version. Rollback to versions prior to these are not supported. The rollback icon is greyed out for unsupported versions.
-
Rollback is not supported if the manager access interface (Manager or data interface) is different between the rollback version and the current version.
-
If you upgrade the Cloud-Delivered Firewall Management Center, all rollback versions from the previous software release will no longer be available for devices, even if you did not upgrade the devices.
-
If you upgrade the device, you can only roll back to versions on the current software release.
-
For High Availability, rollback is not supported in these scenarios:
-
When the version you want to roll back to contains the high-availability bootstrap configuration. In other words, the deployment when you first formed high availability for the standalone devices.
-
When a device that is currently in standalone mode was part of a high availability pair in the previous deployment version.
-
-
For clustering:
-
Rollback is not supported when a device that is currently in standalone mode was part of a cluster in the previous deployment version.
-
(Secure Firewall 3100/4200 and Firewall Threat Defense Virtual in a private cloud) If you change the clustering bootstrap configuration or add or delete nodes, you cannot roll back to a version prior to those changes.
-
|
Configurations that are reverted during a rollback |
Configurations that are not reverted during a rollback |
|---|---|
|
|