01-Fundamentals Configuration Guide

HomeSupportConfigure & DeployConfiguration GuidesH3C SecPath Firewall Series Configuration Guides(V7)-6W40201-Fundamentals Configuration Guide
07-Software upgrade configuration
Title Size Download
07-Software upgrade configuration 93.46 KB

Upgrading software

About software upgrade

Software upgrade enables you to upgrade a software version, add new features, and fix software bugs. This chapter describes software types and release forms, compares software upgrade methods, and provides the procedures for upgrading software from the CLI.

Software types

The following software types are available:

·     BootWare image—Also called the Boot ROM image. This image contains a basic segment and an extended segment.

¡     The basic segment is the minimum code that bootstraps the system.

¡     The extended segment enables hardware initialization and provides system management menus. When the device cannot start up correctly, you can use the menus to load software and the startup configuration file or manage files.

Typically, the BootWare image is integrated into the Boot image to avoid software compatibility errors.

·     Comware image—Includes the following image subcategories:

¡     Boot image—A .bin file that contains the Linux operating system kernel. It provides process management, memory management, and file system management.

¡     System image—A .bin file that contains the Comware kernel and standard features, including device management, interface management, configuration management, and routing.

¡     Feature image—A .bin file that contains advanced or customized software features. You can purchase feature images as needed.

¡     Patch image—A .bin file that is released for fixing bugs without rebooting the device. A patch image does not add or remove features.

Patch images have the following types:

-     Incremental patch images—A new incremental patch image can cover all, part, or none of the functions provided by an old incremental patch image. A new incremental patch image can coexist with an old incremental patch image on the device only when the former covers none of the functions provided by the latter.

-     Non-incremental patch images—A new non-incremental patch image covers all functions provided by an old non-incremental patch image. Each of the boot, system, and feature images can have one non-incremental patch image, and these patch images can coexist on the device. The device uninstalls the old non-incremental patch image before installing a new non-incremental patch image.

An incremental patch image and a non-incremental patch image can coexist on the device.

Comware images that have been loaded are called current software images. Comware images specified to load at the next startup are called startup software images.

BootWare image, boot image, and system image are required for the device to operate.

You can install up to 32 .bin files on the device, including one boot image file, one system image file, and up to 30 feature and patch image files.

Software release forms

Software images are released in one of the following forms:

·     Separate .bin files. You must verify compatibility between software images.

·     As a whole in one .ipe package file. The images in an .ipe package file are compatible. The system decompresses the file automatically, loads the .bin images and sets them as startup software images.

 

 

NOTE:

Software image file names use the model-comware version-image type-release format. This document uses boot.bin and system.bin as boot and system image file names.

 

Upgrade methods

Upgrade method

Software types

Remarks

Upgrading from the CLI by using the boot loader method

·     BootWare image

·     Comware images (excluding patches)

This method is disruptive. You must reboot the entire device to complete the upgrade.

Performing an ISSU from the CLI

Comware images

This method enables a software upgrade with a minimum amount of downtime. Use this method if possible.

For more information about ISSU, see "Performing an ISSU."

Upgrading from the BootWare menu

·     BootWare image

·     Comware images

Use this method when the device device, PEX, or security engine cannot start up correctly.

To use this method, first connect to the console port and power cycle the device, PEX, or security engine. Then, press Ctrl+B at prompt to access the BootWare menu.

For more information about upgrading software from the BootWare menu, see the release notes for the software version.

IMPORTANT IMPORTANT:

Use this method only when you do not have any other choice.

 

This chapter covers only upgrading software from the CLI by using the boot loader method.

Software image loading 

Startup software images

To upgrade software, you must specify the upgrade files as the startup software images for the device to load at next startup. You can specify two lists of software images: one main and one backup. The device first loads the main startup software images. If the main startup software images are not available, the devices loads the backup startup software images.

Image loading process at startup

At startup, the device performs the following operations after loading and initializing BootWare:

1.     Loads main images.

2.     If any main image does not exist or is invalid, loads the backup images.

3.     If any backup image does not exist or is invalid, checks the main or backup boot image.

4.     If both the main and backup boot images do not exist or are invalid, the device cannot start up.

Restrictions and guidelines: Software upgrade

As a best practice, store the startup images in a fixed storage medium. If you store the startup images in a hot swappable storage medium, do not remove the hot swappable storage medium during the startup process.

Software upgrade is supported only on the default context.

Upgrading device software by using the boot loader method

Software upgrade tasks at a glance

To upgrade software, perform one of the following tasks:

·     Upgrade the IRF fabirc:

a.     (Optional.) Preloading the BootWare image to BootWare

If a BootWare upgrade is required, you can perform this task to shorten the subsequent upgrade time. This task helps reduce upgrade problems caused by unexpected power failure. If you skip this task, the device upgrades the BootWare automatically when it upgrades the startup software images.

b.     Specifying startup images and completing the upgrade

·     (Optional.) Synchronizing startup images from the master device to subordinate devices

Perform this task when the startup images on subordinate devices are not the same version as those on the master device.

Prerequisites

1.     Use the display version command to verify the current BootWare image version and startup software version.

2.     Use the release notes for the upgrade software version to evaluate the upgrade impact on your network and verify the following items:

¡     Software and hardware compatibility.

¡     Version and size of the upgrade software.

¡     Compatibility of the upgrade software with the current BootWare image and startup software image.

3.     Use the release notes to verify whether the software images require a license. If licenses are required, register and activate licenses for each license-based software image. For more information about licensing, see "Managing licenses."

4.     Use the dir command to verify that all IRF member devices have sufficient storage space for the upgrade images. If the storage space is not sufficient, delete unused files by using the delete command. For more information, see "Managing file systems."

5.     Use FTP or TFTP to transfer the upgrade image file to the root directory of a file system. For more information about FTP and TFTP, see "Configuring FTP" or "Configuring TFTP." For more information about file systems, see "Managing file systems."

Preloading the BootWare image to BootWare

Hardware and feature compatibility

Hardware

Feature compatibility

F5010, F5020, F5020-GM, F5030, F5030-6GW, F5040, F5060, F5080, F5000-AI-20, F5000-AI-40, F5000-V30, F5000-C, F5000-S, F5000-M, F5000-A

Yes

F1000-AI-20, F1000-AI-30, F1000-AI-50, F1000-AI-60, F1000-AI-70, F1000-AI-80, F1000-AI-90

Yes

F1003-L, F1005-L, F1010-L

Yes

F1005, F1010

Yes

F1020, F1020-GM, F1030, F1030-GM, F1050, F1060, F1070, F1070-GM, F1070-GM-L, F1080, F1090, F1000-V70

Yes

F1000-AK1110, F1000-AK1120, F1000-AK1130, F1000-AK1140

Yes

F1000-AK1212, F1000-AK1222, F1000-AK1232, F1000-AK1312, F1000-AK1322, F1000-AK1332

Yes

F1000-AK1414, F1000-AK1424, F1000-AK1434, F1000-AK1514, F1000-AK1524, F1000-AK1534, F1000-AK1614

Yes

F1000-AK108, F1000-AK109, F1000-AK110, F1000-AK115, F1000-AK120, F1000-AK125, F1000-AK710

Yes

F1000-AK130, F1000-AK135, F1000-AK140, F1000-AK145, F1000-AK150, F1000-AK155, F1000-AK160, F1000-AK165, F1000-AK170, F1000-AK175, F1000-AK180, F1000-AK185, F1000-GM-AK370, F1000-GM-AK380, F1000-AK711

Yes

LSU3FWCEA0, LSUM1FWCEAB0, LSX1FWCEA1

Yes

LSXM1FWDF1, LSUM1FWDEC0, IM-NGFWX-IV, LSQM1FWDSC0, LSWM1FWD0, LSPM6FWD, LSQM2FWDSC0

Yes

vFW1000, vFW2000

No

 

Procedure

1.     Enter system view.

system-view

2.     (Optional.) Enable BootWare image validity check.

bootrom-update security-check enable

By default, this feature is enabled.

This feature examines BootWare images for file type errors, file corruption, and hardware incompatibility. As a best practice, enable it to ensure a successful upgrade.

3.     Return to user view.

quit

4.     (Optional.) Back up the current BootWare image in the Normal area of BootWare.

¡     Back up the image to the Backup area of BootWare:

bootrom backup slot slot-number-list [ all | part ]

¡     Back up the image to the default file system:

bootrom read slot slot-number-list [ all | part ]

The bootrom read command creates two BootWare image files on the default file system: basicbtm.bin for the basic segment and extendbtm.bin for the extended section.

Use either command to back up the BootWare image for a future version rollback or image restoration.

5.     Load the upgrade BootWare image to the Normal area of BootWare.

bootrom update file file slot slot-number-list [ all | part ]

Specify the downloaded software image file for the file argument.

The new BootWare image takes effect at a reboot.

Specifying startup images and completing the upgrade

Perform the following steps in user view:

1.     Specify main or backup startup images for all member devices.

¡     Use an .ipe file:

boot-loader file ipe-filename { all | slot slot-number } { backup | main }

¡     Use .bin files:

boot-loader file boot filename system filename [ feature filename&<1-30> ] { all | slot slot-number } { backup | main }

As a best practice in a multichassis IRF fabric, specify the all keyword for the command. If you use the slot slot-number option to upgrade member devices one by one, version inconsistencies occur among the member devices during the upgrade.

2.     Save the running configuration.

save

This step ensures that any configuration you have made can survive a reboot.

3.     Reboot the IRF fabric.

reboot

4.     (Optional.) Verify the software image settings.

display boot-loader [ slot slot-number ]

Verify that the current software images are the same as the startup software images.

Synchronizing startup images from the master device to subordinate devices

About this task

Perform this task when the startup images on subordinate devices are not the same version as those on the master device.

This task synchronizes startup images that are running on the master device to subordinate devices. If any of the startup images does not exist or is invalid, the synchronization fails.

The startup images synchronized to subordinate devices are set as main startup images, regardless of whether the source startup images are main or backup.

Restrictions and guidelines

If an ISSU or patch installation has been performed on the master device, use the install commit command to update the set of main startup images on the master device before software synchronization. This command ensures startup image consistency between the master and subordinate devices.

Procedure

Perform the following steps in user view:

1.     Synchronize startup images from the master to subordinate devices.

boot-loader update { all | slot slot-number }

2.     Reboot the subordinate devices.

reboot slot slot-number [ force ]

Restoring the BootWare image

About this task

Use this task to restore the BootWare image when the BootWare image in the Normal area is corrupted or a version rollback is required.

Hardware and feature compatibility

Hardware

Feature compatibility

F5010, F5020, F5020-GM, F5030, F5030-6GW, F5040, F5060, F5080, F5000-AI-20, F5000-AI-40, F5000-V30, F5000-C, F5000-S, F5000-M, F5000-A

Yes

F1000-AI-20, F1000-AI-30, F1000-AI-50, F1000-AI-60, F1000-AI-70, F1000-AI-80, F1000-AI-90

Yes

F1003-L, F1005-L, F1010-L

Yes

F1005, F1010

Yes

F1020, F1020-GM, F1030, F1030-GM, F1050, F1060, F1070, F1070-GM, F1070-GM-L, F1080, F1090, F1000-V70

Yes

F1000-AK1110, F1000-AK1120, F1000-AK1130, F1000-AK1140

Yes

F1000-AK1212, F1000-AK1222, F1000-AK1232, F1000-AK1312, F1000-AK1322, F1000-AK1332

Yes

F1000-AK1414, F1000-AK1424, F1000-AK1434, F1000-AK1514, F1000-AK1524, F1000-AK1534, F1000-AK1614

Yes

F1000-AK108, F1000-AK109, F1000-AK110, F1000-AK115, F1000-AK120, F1000-AK125, F1000-AK710

Yes

F1000-AK130, F1000-AK135, F1000-AK140, F1000-AK145, F1000-AK150, F1000-AK155, F1000-AK160, F1000-AK165, F1000-AK170, F1000-AK175, F1000-AK180, F1000-AK185, F1000-GM-AK370, F1000-GM-AK380, F1000-AK711

Yes

LSU3FWCEA0, LSUM1FWCEAB0, LSX1FWCEA1

Yes

LSXM1FWDF1, LSUM1FWDEC0, IM-NGFWX-IV, LSQM1FWDSC0, LSWM1FWD0, LSPM6FWD, LSQM2FWDSC0

Yes

vFW1000, vFW2000

No

Restrictions and guidelines

Make sure you have used the bootrom backup command to back up the image to the BootWare Backup area.

Procedure

Perform the following steps in user view:

1.     Restore the BootWare image in the Normal area of BootWare.

bootrom restore slot slot-number-list[ all | part ]

2.     Reboot the device.

reboot

At startup, the system runs the new BootWare image to complete the restoration.

Display and maintenance commands for software images

Execute display commands in any view and execute reset commands in user view.

 

Task

Command

Display current software images and startup software images.

display boot-loader [ slot slot-number ]

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网