---
title: "8.4.x, 8.5.x, and 8.6.x to 9.0.3 Upgrade Prerequisites and Affected Features"
canonical: "https://docs.infoblox.com/space/niosupgrade/1320354322/8.4.x%2C%208.5.x%2C%20and%208.6.x%20to%209.0.3%20Upgrade%20Prerequisites%20and%20Affected%20Features"
format: markdown
---
This section details general and specific upgrade prerequisites that you **must** follow before upgrading NIOS versions. It also details features that are impacted by a NIOS upgrade and guidelines that you **must **follow before the upgrade.

> Macro (toc)

> ℹ️ **Caution: **Powering off or resetting the appliance during an upgrade may cause the upgrade to fail and leave the system in an unusable state. Wait until the upgrade process is complete and till all associated scripts have been fully executed before initiating any power actions.

# NIOS 8.4.x, 8.5.x, and 8.6.x to NIOS 9.0.3 Upgrade Prerequisites

|  |  |
| --- | --- |
| **Target Version** | **9.0.3** |
| **Current Version** | **8.4.*****x***** or 8.5.*****x***** or 8.6.*****x *****(except 8.6.5)** |

| **Category** | **Upgrade Guidelines** |
| --- | --- |
| Critical algorithms | - Using an unsupported algorithm such as RSAMD5(1), DSA (3), DSA-NSEC3-SHA1(6) may cause the upgrade to fail.
- Using invalid key size for RSASHA1(5), RSA-NSEC3-SHA1(7), RSASHA256(8) (should be within range [1024 to 4096]) may cause the upgrade to fail.
- Manually creating (through the import keyset) a DS record with an unsupported algorithm or digest type SHA-1 may cause the upgrade to fail. |
| BIND | - In NIOS 8.6 and earlier versions, BIND allowed the configuration of the listen-on, notify-source, and query-source options on port 53 for both IPv4 and IPv6 addresses. However, starting from NIOS 9.0.*x* onwards, this configuration is not recommended as BIND does not support the listen-on, notify-source, and query-source options to use the same port for both IPv4 and IPv6. Having this configuration can cause BIND to fail during start-up.
- BIND performance may be poor if the DNS load originates from a small number of source IP addresses or ports. |
| Unbound | - If an Unbound license is present in the Grid, then upgrading to 9.0.x will fail. You must manually remove the Unbound license and then proceed with the upgrade.
- If you have offline Grid members and are not able to delete the Unbound license, then you must bring the Grid members online, remove the license, and then proceed with the upgrade. You can also contact Infoblox Support about creating a hotfix to clean up the Unbound licenses for the offline members.
- If you had a temporary Unbound license that you deleted from Grid Manager, the license will still be present in the database and the upgrade will fail. Please contact Infoblox Support to completely remove the temporary license.
- If Unbound is configured, the upgrade test fails to indicate that references to Unbound are being completely destroyed during the upgrade process. |
| Threat Insight and Threat Analytics | - If you set up your Grid to use Infoblox Threat Insight but have not enabled automatic updates for Threat Analytics module sets, you must manually upload the latest module set to your Grid or enable automatic updates before upgrading. Otherwise, your upgrade will fail.
- If you set up your Grid to use Infoblox Threat Insight but have not enabled automatic updates for Threat Analytics module sets, you must manually upload the latest module set to your Grid or enable automatic updates before upgrading. Otherwise, your upgrade will fail.
- If you are using threat analytics, you must have installed the minimum module set version (20210620) before upgrading to NIOS 8.6.1 or to NIOS 8.5.3 or later versions. |
| IPv4 and IPv6 networks | - Upgrade from 8.6.x to 9.0.x fails if you add invalid networks for any of the ACLs.
- Infoblox recommends that you do not enter invalid prefix lengths (for IPv6 and IPv4 networks) for any of the ACLs that are used by the DNS service.
- The IPv4 address or the IPv6 address specified for the query-source option must be available on one of the network interfaces. If the IP address is not available, the DNS services fails to start. |
| RADIUS authentication | The shared secret that you enter when adding a RADIUS authentication server in the *Add RADIUS Authentication Service *wizard > **RADIUS Servers** > **Shared Secret** field must be between 4 and 64 characters (inclusive) in length. Otherwise, the upgrade will fail. |

# NIOS 8.4.x, 8.5.x, and 8.6.x to NIOS 9.0.3 Upgrade Affected Features

|  |  |
| --- | --- |
| **Target Version** | **9.0.3** |
| **Current Version** | **8.4.x, 8.5.x, 8.6.x (except 8.6.5)** |

| **Affected Feature** | **Descriptions** |
| --- | --- |
| Downgrades | A downgrade from NIOS 9.0.x to NIOS 8.4.x is not supported. Auto-synchronization from NIOS 9.0.x to NIOS 8.4.x is not supported. |
| Bandwidth | Make sure that the bandwidth between the nodes in a Grid is at least 100 Mbps or higher to ensure timely completion of distribution. In slower environments, distribution may take longer and may result in delays. |
| Certificates | Before you upgrade to NIOS 9.0.x, check the validity of the CA certificates uploaded. If the certificate is invalid, install a new certificate that is in compliance with RFCs (for example RFC 5280). Failure to do so may result in the Grid Manager UI/WAPI not being accessible after the upgrade. However, NIOS will continue to be functional. To check the validity of the certificate, contact Infoblox Support. |
| Threat Protection and Threat Insight | - If there are Threat Protection members in your Grid for the 8.3 and later features (Grid Master Candidate test promotion, forwarding recursive queries to Infoblox Threat Defense Cloud, and CAA records), ensure that you upload the latest Threat Protection ruleset for these features to function properly.
- If you are upgrading from a version earlier than NIOS 8.6.1 to a later release and the Threat Insight service is enabled on a Reporting member, Infoblox recommends that you to stop the Threat Insight service on the Reporting member using the Grid Manager before starting the upgrade. This step helps prevent the "Threat Insight Service is failed" message from being displayed post-upgrade. |
| DNS Fault Tolerant Caching | Infoblox recommends that you enable DNS Fault Tolerant Caching right after you upgrade to NIOS 8.2.x and later and keep this feature enabled to handle unreachable authoritative servers. Note that enabling this feature requires a DNS service restart, which will clear the current cache. Therefore, if you enable this when you are trying to mitigate an ongoing attack on an authoritative server that is outside of your control, it will clear the DNS cache, which will magnify the issues that your system is experiencing. |
| NXDOMAIN redirection | During a scheduled full upgrade to NIOS 8.*x* and later versions, you can use only IPv4 addresses for NXDOMAIN redirection. You cannot use IPv6 addresses for NXDOMAIN redirection while the upgrade is in progress. |
| AWS Route 53 | - After a scheduled upgrade to NIOS 8.6.3 and later is complete, you must run the `update_rabbitmq_password` command on the Grid Master to get the Cloud DNS Sync service to be functional. Until that time, Route 53 synchronization does not start because the service has not been started.
- After an upgrade to NIOS 8.6.3 and later, the Cloud DNS Sync service starts automatically on the Grid member that is assigned to the Route 53 synchronization groups. |
| Active Directory authentication | After an upgrade to NIOS 8.6.3 and later, the **Disable Default Search Path** and the **Additional Search Paths** fields will no longer be displayed in the *Add Active Directory Authentication Service > Step 1 of 1 *wizard. |
| IB-FLEX | If you upgrade to NIOS 8.6.3 or later, all IB-FLEX appliances or Grids that have the FLEX Grid Activation license or the MSP license will have the ReportingSPLA external attribute assigned automatically for supported Grid members. |
| Virtual DNS Cache Acceleration (vDCA) | After an upgrade to NIOS 8.6.3 and later, only 5% of allowed blocklist subscribers is supported for virtual DNS Cache Acceleration. |