Refer to knowledge base article, How to Upgrade On-Prem Network Security Manager firmware for detailed instructions on upgrading NSM firmware using SWI files.
Capacity Requirements: The capacity requirements for an NSM On-Premises deployment have changed:
| Number of Firewalls | CPU (Cores) | RAM (GB) |
|---|---|---|
| 100 | 4 | 16 |
| 150 | 4 | 16 |
| 250 | 8 | 16 |
| 500 | 8 | 16 |
| 750 | 8 | 16 |
| 1000 | 8 | 16 |
| 1000+ | 16 | 32 |
| Number of Firewalls | CPU (Cores) | RAM (GB) |
|---|---|---|
| 100 | 4 | 24 |
| 150 | 4 | 24 |
| 250 | 8 | 24 |
| 500 | 8 | 32 |
| 750 | 8 | 32 |
| 1000 | 8 | 32 |
| 1000+ | 16 | 64 |
| Number of Firewalls | Data Retention 7 days | Data Retention 365 days |
|---|---|---|
| 50 | 600 GB | 750 GB |
| 100 | 1.2 TB | 1.5 TB |
| 150 | 1.7 TB | 2.3 TB |
| 250 | 2.8 TB | 4 TB |
| Number of Firewalls | NSM Nodes |
|---|---|
| ≤ 250 | NSM Controller Node / Single Node Deployment |
| > 250 | Controller Node + 1 Reporting Agent per 250 firewall |
| Reporting Agent resource requirements (CPU and RAM ) is the same as the controller node. | |
Upgrade Instructions:
NSM 3.0.1 On-Premises is a maintenance release and does not support fresh installation. To upgrade to 3.0.1 On-Premises, follow the upgrade paths mentioned below.
| Current Build | Upgrade Path to 3.0.1 HF1 |
|---|---|
| NSM 2.6.0 | 2.6.0 > 2.6.0 HF1 > 3.0.0 > 3.0.1 |
| NSM 2.6.0 HF1 | 2.6.0 HF1 > 3.0.0 > 3.0.1 |
| NSM 3.0.0 | 3.0.0 > 3.0.1 |
This maintenance release provides fixes for previously reported issues.
| Issue ID | Description |
|---|---|
| NSM-30335 | Resolved the issue in showing the integrated analytics under External Reports. |
| NSM-30434 | Resolved the issue in Group firmware upgrade. |
| NSM-30568 |
Resolved the issue of stopping or starting the agent services for every eight minutes when deployed a distributed Controller or Agent for larger deployment with more than 200 firewalls. |
| NSM-30771 | Resolved the issue of configuring Time settings on a template. |
| Issue ID | Description |
|---|---|
| NSM-30748 | Manually acquired firewalls are unable to forward Heartbeats to custom IP/FQDN if reporting is not enabled. |
| NSM-30869 | Unit locally changed event with firewall device going to out of sync status is not occurring while GMS/NSM config on firewall is using NSM Private IP vs Public IP. |