Management Access Considerations when Upgrading from FastIron 08.0.95 to 09.0.10d or a Later Release
The following considerations apply when upgrading to FastIron 09.0.10d or later.
- If the ICX switch configuration contains a
management accesscommand statement that allows only an IPv4 address, only IPv4 addresses will be permitted. IPv6 traffic will be blocked following upgrade. - If the ICX switch configuration contains a
management accesscommand statement that allows only an IPv6 address, only IPv6 addresses will be permitted on upgrade. IPv4 traffic will be blocked. - If the
management accesscommand allows a specific protocol, then only traffic for that protocol will be allowed. To add another protocol, an additionalmanagement accesscommand entry must be configured.For example, if the system contains the configuration "management access mac 00:4e:24:45:04:00 src-ip 10.176.6.62 255.255.255.255 allow ssh log" then only SSH packets received with the source IP address 00:4e:24:45:04:00 + 10.176.6.62 will be allowed. All other traffic is dropped.
- If you are upgrading from FastIron
09.0.00 or later to FastIron 09.0.10d and the
management accesscommand configuration contains a filter statement with more than one IP or MAC address, the configuration is removed on upgrade.
When an ICX device is updated from FastIron 08.0.95x to FastIron 09.0.10d or later, the migration adjustments described in the following scenarios are applied to preserve the configuration.
Scenario 1
The FastIron 08.0.95 configuration contains IPv6 configuration with an allow action for a particular protocol but does not contain IPv4 configuration with an allow statement for the same protocol.
Upgrade Transformation: Internally, IPv4 configuration is added to allow the protocol.
FastIron 08.0.95 Configuration:
ssh access-group ipv6 ssh_acl ipv6 access-list ssh_acl sequence 10 permit ipv6 5::1/64 any
FastIron 09.0.10d or Later Migrated Configuration:
management access src-ipv6 5::1/64 allow ssh management access src-ip 0.0.0.0 0.0.0.0 allow ssh
Scenario 2
The FastIron 08.0.95 configuration contains only IPv4 configuration with an allow action for a particular protocol but does not contain IPv6 configuration with an allow action for the same protocol.
Upgrade Transformation: Internally, IPv6 configuration is added to allow the protocol.
FastIron 08.0.95 Configuration:
snmp-client 10.0.0.1
FastIron 09.0.10d or Later Migrated Configuration:
management access src-ip 10.0.0.1 255.255.255.255 allow snmp management access src-ipv6 0::0/0 allow snmp
Scenario 3
The FastIron 08.0.95 configuration contains both IPv4 and IPv6 configuration with an allow action for a particular protocol.
Upgrade Transformation: No configuration is added. Configured commands are converted to equivalent management access filter statements.
FastIron 08.0.95 configuration:
web client ipv6 2::1 web client 20.0.0.1
FastIron 09.0.10x migrated configuration:
management access src-ip 20.0.0.1 255.255.255.255 allow web management access src-ipv6 2::1/128 allow web