Migration Guide: Legacy SSL Visibility (v4.5.15.1) to SSP Series SSL Visibility (v6.2.1.1) virtual application.
search cancel

Migration Guide: Legacy SSL Visibility (v4.5.15.1) to SSP Series SSL Visibility (v6.2.1.1) virtual application.

book

Article ID: 448701

calendar_today

Updated On:

Products

ISG SSLV SSL Visibility Appliance Software

Issue/Introduction

This guide provides the technical framework for migrating from the legacy SV3800B-20 hardware (SSL Visibility version 4.5.15.1) to the modern Symantec Security Platform (SSP) architecture. In the target 6.2.1.1 environment, SSL Visibility (SSLV) operates as a high-performance virtual application hosted on the Integrated Secure Gateway (ISG) software.

Environment

Legacy Appliances (SV800, SV1800/B, SV2800/B, SV3800/B, SV3800B-20)

The legacy appliances are no longer supported in the 6.x software branch. These models cannot run the virtualized SSLV architecture. Customers are requested to work with the Sales team to deploy SSLV virtualized applications on SSP appliances. 

For SSP Appliance sizing for the SSL Visibility virtual appliance utilize the following sizing guide: SSL Visibility Appliance Data Sheet

For additional information regarding SSLV 6.2.1.1 version, see the SSL Visibility 6.2.1.1 Release notes.

Cause

Hardware Refresh/Upgrade

  • To run SSL Visibility as a virtual application on an SSP based appliance you must have an Enterprise license. A new license must be obtained from Broadcom Support Portal prior to migration.
  • PKI & Policy from SSLV 4.5.15.1 software can be restored on 6.2.1.1 See Configuration Compatibility Matrix below.

Configuration Compatibility Matrix 

4.x Backup Component

Supported for Restore to v6.2.1.1

PKI Only

Supported

Policy Only

Supported

Platform Only

NOT supported

Full Backup

NOT supported

 

Critical Warnings and Compatibility Matrix

CAUTION: CRITICAL DATA PLANE FAILURE 

Attempting to restore a version 4.x Full Backup or Platform Backup onto a version 6.2.1.1 will cause a system crash and prevent the data plane from initializing. To avoid an unrecoverable state, strictly adhere to the supported backup components listed above.

Target Platform Version Compatibility (ISG & BCSI)

The SSLV 6.2.1.1 virtual application requires specific ISG host versions and hardware resources.

Compatibility with ISG Host Versions

  • SSP-S620-10: ISG 2.5.5.1 or later.
  • S210-10, S410-20B, S410-40B: ISG 2.5.4.1 or later.

Minimum Resource Requirements per Instance

SSP Appliance (Model)

Cores

RAM (GB)

Disk (GB)

SSP-S210-10 (C12S-1)

12

48

800

SSP-S410-20B (C32XS-3)

32

80

800

SSP-S410-40B (C64L-3)

64

320

1600

SSP-S620-10 (C112L-4)

112

960

3200

Hardware Accelerators and NICs:

  • Crypto Acceleration: S410-20B and S410-40B models require the ISG-QAT-S410 accelerator card installed in Slot 4.

IMPORTANT: Performance Advisory: SSP-S210-10 systems may encounter degraded performance on version 6.2.1.1. As a best practice, it is recommended maintaining these specific units on version 6.1.1.1.  SSL Visibility 6.3.1.1, when released,  includes fixes for the performance issues mentioned above.

Resolution

Phase 1: Getting Ready

Before decommissioning the SV3800B-20, engineers must perform granular data extraction:

  1. Manual Platform Documentation: Because Platform backups are incompatible, you must manually document all configurable settings on the Platform Management menu, such as management network, SNMP, remote logging, date/time, authentication, alerts, and login banner.
  2. Generate Supported Files: Navigate to Platform Management > Backup/Restore in the 4.x WebUI.
  3. Export PKI: Generate and download a "PKI only" backup. This is critical for maintaining CA trust without re-deploying certificates to endpoints.
  4. Export Policy: Generate and download a "Policy only" backup.

Phase 2: Setting up the ISG

Obtaining the 6.x License

  1. Log in to the Broadcom Support Portal (My Entitlements).
  2. Locate the target SSP appliance via Serial Number or Site ID.
  3. Download the software license.

Configure the ISG for a virtual SSL Visibility application

  1. Load Enterprise Serial Number for SSLV application on ISG.
  2. Download the SSLv software application to the ISG.
  3. Create a network-definition for the SSLV.
  4. Create an application for SSL Visibility.
  5. Bind the application to the SSLV network-definition.
  6. Connect to the SSLV application console and complete the network set-up of SSLv.
  7. Log into the GUI of the SSLV via a browser.
  8. Ensure you have the license for the SSLV installed.

For detailed explanations of the steps above and configuration commands refer to the following KB article:

Creating a SSL Visibility application on an ISG

Information is also available via Broadcom Tech Docs

Phase 3: Migration & Restore

Platform Configuration

Platform configuration must be manually reconstructed based on the documentation gathered in Phase 1.

Restoration of Policy and PKI on v6.2.1.1

  1. PKI Restore: Finalize the "Import PKI" process. Ensure all re-signing CAs (outbound) and server key/cert pairs (inbound) are verified. The system now mandates RSA 2048-bit keys for management; a self-signed certificate is automatically generated if a legacy 1024-bit key was present.
  2. Policy Restore: Upload the 4.x Policy backups via the SSLV WebUI (Platform Management > Backup/Restore).  You must check the “Allow policies from other appliances” check box to restore from the older model of hardware. 

Phase 4: Post-Migration

Logging and Security

  • Session Logs: Legacy session logs are not retained. Verify that the new 6.2.1.1 logging is active and configure a Session Log Retention Policy (Logging > Session Log Retention Policy).
  • Management Trust: If using Chrome, you may encounter an ERR_CERT_AUTHORITY_INVALID warning due to the new 2048-bit self-signed certificate. Configure the browser to trust the new certificate or import a CA-signed management certificate.
  • Password History: Note that the Password History policy now applies to Enable mode and Setup Console passwords, ensuring uniform security across all access methods.

 

For additional information regarding SSLV 6.2.1.1 version, see the SSL Visibility 6.2.1.1 Release notes.