SR 8806-X-S + 防火墙双主控板、一个业务板、一个板载防火墙进行升级步骤和可升级版本号
主控板和板载 防火墙登录后使用dis ver查看信息如下:
<E21E20-42U-BR.SR8806XS>dis ver
<E21E20-42U-BR.SR8806XS>dis version
H3C Comware Software, Version 7.1.075, Release 8261P29
Copyright (c) 2004-2022 New H3C Technologies Co., Ltd. All rights reserved.
H3C SR8806-X-S uptime is 0 weeks, 0 days, 4 hours, 4 minutes
Last reboot reason : Cold reboot
Boot image: flash:/SR8800FS-CMW710-BOOT-R8261P29.bin
Boot image version: 7.1.075, Release 8261P29
Compiled Jul 22 2022 11:00:00
System image: flash:/SR8800FS-CMW710-SYSTEM-R8261P29.bin
System image version: 7.1.075, Release 8261P29
Compiled Jul 22 2022 11:00:00
Feature image(s) list:
flash:/SR8800FS-CMW710-DEVKIT-R8261P29.bin, version: 7.1.075
Compiled Jul 22 2022 11:00:00
MPU(M) Chassis 2 Slot 0:
Uptime is 0 weeks,0 days,4 hours,4 minutes
BOARD TYPE: SR07SRPUA1
DRAM: 4096M bytes
FLASH: 500M bytes
NVRAM: 1M bytes
PCB 1 Version: VER.A
Bootware Version: 151
CPLD 1 Version: 001
CPLD 2 Version: 001
Reboot Cause : ColdReboot
Number of Exist Subcards: 0
MPU(S) Chassis 2 Slot 1:
Uptime is 0 weeks,0 days,4 hours,4 minutes
BOARD TYPE: SR07SRPUA1
DRAM: 4096M bytes
FLASH: 500M bytes
NVRAM: 1M bytes
PCB 1 Version: VER.A
Bootware Version: 151
CPLD 1 Version: 001
CPLD 2 Version: 001
Reboot Cause : ColdReboot
Number of Exist Subcards: 0
LPU Chassis 2 Slot 2:
Uptime is 0 weeks,0 days,1 hour,33 minutes
BOARD TYPE: SPC-XLP2XP4LC
DRAM: 4096M bytes
PCB 1 Version: VER.A
Bootware Version: 124
CPLD 1 Version: 002
Reboot Cause : WarmReboot
Number of Exist Subcards: 0
LPU Chassis 2 Slot 3:
Uptime is 0 weeks,0 days,3 hours,52 minutes
BOARD TYPE: SPC-XP12LC
DRAM: 4096M bytes
PCB 1 Version: VER.A
Bootware Version: 124
CPLD 1 Version: 001
Reboot Cause : ColdReboot
Number of Exist Subcards: 0
LPU Chassis 2 Slot 7:
Uptime is 0 weeks,0 days,3 hours,51 minutes
BOARD TYPE: LSU3FWCEA0
DRAM: 1024M bytes
FLASH: 0M bytes
NVRAM: 0K bytes
PCB 1 Version: VER.B
PCB 2 Version: VER.A
Bootware Version: 518
CPLD 1 Version: 002
Reboot Cause : ColdReboot
Number of Exist Subcards: 0
<E21E20-42U-BR.SR8806XS>
<E21E20-42U-SecBladeFW>dis ver
<E21E20-42U-SecBladeFW>dis version
H3C Comware Software, Version 7.1.064, Release 8241P2417
Copyright (c) 2004-2021 New H3C Technologies Co., Ltd. All rights reserved.
H3C SecBlade III FW Enhanced Module uptime is 0 weeks, 0 days, 3 hours, 48 minutes
Last reboot reason: IRF Merge reboot
Boot image: cfa0:/blade3fw-cmw710-boot-R8241P2417.bin
Boot image version: 7.1.064, Release 8241P2417
Compiled Oct 14 2021 14:00:00
System image: cfa0:/blade3fw-cmw710-system-R8241P2417.bin
System image version: 7.1.064, Release 8241P2417
Compiled Oct 14 2021 14:00:00
SLOT 2
Uptime is 0 weeks, 0 days, 3 hours, 48 minutes
CPU type: Multi-core CPU
DDR3 SDRAM Memory 16382M bytes
CF0 Card 4002M bytes
Board PCB Version:Ver.A
CF SubCard PCB Version:Ver.C
CPLD_A Version: 2.0
CPLD_B Version: 4.0
CPLD_C Version: 1.0
Release Version:SecBlade III FW Enhanced Module-8241P2417
Basic BootWare Version: 2.06
Extend BootWare Version: 2.06
[SubSlot 0]2GE+4XGE (Hardware)Ver.A, (Driver)1.0, (Cpld)4.0
Error reading data on serial port:
Access is denied.
根据你提供的信息,这台SR8806-X-S的升级需要主控板(SR8800FS)和防火墙业务板(LSU3FWCEA0)分别独立进行。防火墙业务板(LSU3FWCEA0)作为OAP(Open Application Platform,开放应用平台)模块,其软件版本与主控板系统相互独立,不能随主控板一同升级。
在进行任何升级操作前,请务必完成以下准备,这是保障升级成功和业务安全的关键。
明确升级目标:确定本次升级的目标版本。主控板和防火墙业务板的目标版本需要分别确认。
记录设备状态:通过display interface brief、display ip routing-table等命令,记录下升级前的关键业务状态。
根据你提供的display version信息,主控板当前运行的是SR8800FS-CMW710-R8261P29。
确认目标版本与升级路径
上传并指定启动文件
将目标版本的IPE文件(例如SR8800FS-CMW710-RXXXXPXX.ipe)上传到主控板的Flash中。
在用户视图下执行以下命令,为所有主控板指定下次启动的IPE文件:
执行display boot-loader命令,确认启动文件已正确设置。
保存配置并重启
执行save命令保存配置。
执行reboot命令重启设备。对于双主控板设备,可以执行reboot chassis 2 slot 0和reboot chassis 2 slot 1分别重启主用和备用主控板,以实现平滑升级。
防火墙业务板(LSU3FWCEA0)是一个独立的OAP模块,需要单独升级。你提供的信息显示它当前运行的是blade3fw-cmw710-R8241P2417。
登录防火墙业务板
在主控板上,通过以下命令登录到防火墙业务板的操作系统:
成功后会进入防火墙业务板的命令行界面(提示符会变为类似<E21E20-42U-SecBladeFW>)。
上传目标版本软件
在防火墙业务板的命令行界面,将目标版本的Boot和System镜像文件(例如blade3fw-cmw710-boot-RXXXXPXX.bin和blade3fw-cmw710-system-RXXXXPXX.bin)上传到其存储介质(通常是cfa0:/)中。
指定下次启动文件
在防火墙业务板的系统视图下,执行以下命令指定Boot和System镜像:
注意:这里的slot 2是防火墙业务板在OAP系统中的槽位号,根据你display version的输出,它可能显示为SLOT 2。
重启防火墙业务板
执行reboot命令重启防火墙业务板。此操作只影响该业务板,不会导致主控板重启。
重启完成后,再次登录并执行display version确认版本已更新。
暂无评论
当前版本信息
重点约束:
SR8806‑X‑S 整机版本系列:R8261 分支、R8263 分支
版本包结构(SR8800FS 完整版本包)
SR8800FS‑CMW710‑BOOT‑R8261P42.bin 主控Boot
SR8800FS‑CMW710‑SYSTEM‑R8261P42.bin 主控System
SR8800FS‑CMW710‑DEVKIT‑R8261P42.bin Devkit特性包
blade3fw‑cmw710‑boot‑R8261P42.bin 板载防火墙Boot镜像
blade3fw‑cmw710‑system‑R8261P42.bin 板载防火墙System镜像
⚠️板载防火墙镜像在 SR8800FS 整机包内,不要用独立 F1000 防火墙 IPE 包,会板卡启动失败。
#1、保存配置,备份配置到TFTP
save
tftp x.x.x.x put startup.cfg
#2、双主控Flash空间检查,主备主控flash都要有足够剩余空间
display filesystem
#3、确认板卡状态全部正常,无告警
display device
display device manuf‑info
display alarm urgent
#4、查看当前板载防火墙版本
display version slot 7
slot7 为 LSU3FWCEA0 防火墙板位。
说明:SR8800FS 支持ISSU 不中断升级,也可以整机重启升级;存在防火墙业务板,ISSU 对防火墙业务有约束;防火墙业务板不支持 ISSU 平滑升级,升级过程防火墙业务会中断,建议维护窗口整机重启升级。
通过 TFTP/FTP 上传下面 5 个文件到主主控 flash:
#上传示例tftp
tftp x.x.x.x get SR8800FS‑CMW710‑BOOT‑R8261P42.bin
tftp x.x.x.x get SR8800FS‑CMW710‑SYSTEM‑R8261P42.bin
tftp x.x.x.x get SR8800FS‑CMW710‑DEVKIT‑R8261P42.bin
tftp x.x.x.x get blade3fw‑cmw710‑boot‑R8261P42.bin
tftp x.x.x.x get blade3fw‑cmw710‑system‑R8261P42.bin
boot boot‑loader flash:/SR8800FS‑CMW710‑BOOT‑R8261P42.bin
boot system flash:/SR8800FS‑CMW710‑SYSTEM‑R8261P42.bin
boot feature flash:/SR8800FS‑CMW710‑DEVKIT‑R8261P42.bin
#设置板载防火墙板位7的启动镜像(重点!)
boot subslot 7 boot‑loader flash:/blade3fw‑cmw710‑boot‑R8261P42.bin
boot subslot 7 system flash:/blade3fw‑cmw710‑system‑R8261P42.bin
#校验启动文件
display boot‑loader
display boot system
display boot subslot 7
copy flash:/SR8800FS‑CMW710‑BOOT‑R8261P42.bin slot1#flash:/
copy flash:/SR8800FS‑CMW710‑SYSTEM‑R8261P42.bin slot1#flash:/
copy flash:/SR8800FS‑CMW710‑DEVKIT‑R8261P42.bin slot1#flash:/
#备主控设置启动文件
boot boot‑loader slot1#flash:/SR8800FS‑CMW710‑BOOT‑R8261P42.bin
boot system slot1#flash:/SR8800FS‑CMW710‑SYSTEM‑R8261P42.bin
boot feature slot1#flash:/SR8800FS‑CMW710‑DEVKIT‑R8261P42.bin
防火墙 blade 镜像不需要拷贝到备主控;防火墙板卡是业务板,启动文件由主主控下发给 slot7。
⚠️防火墙业务板不支持 ISSU,整机重启,业务全部中断。
reboot
确认 Y 整机重启。
整机重启完成后执行校验:
#主机版本
display version
#业务板、防火墙板卡版本
display device
display version slot 7
#登录进入板载防火墙内部查看版本
oap connect slot 7
dis version
防火墙内部版本应当和主机版本 Release 号一致,从 R8241P2417 升级到 R8261P42。
升级异常,修改 boot 启动文件指向旧版本 R8261P29 镜像,整机 reboot 回退。
boot boot‑loader flash:/SR8800FS‑CMW710‑BOOT‑R8261P29.bin
boot system flash:/SR8800FS‑CMW710‑SYSTEM‑R8261P29.bin
boot subslot 7 boot‑loader flash:/blade3fw‑cmw710‑boot‑R8261P29.bin
boot subslot 7 system flash:/blade3fw‑cmw710‑system‑R8261P29.bin
reboot暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论