Performing a FIPS or CC Software Upgrade to FastIron 08.0.95

To upgrade the FastIron software image to FastIron 08.0.95 in support of a FIPS or CC environment, perform the following steps.
  1. Place the new flash signature file and the new flash image in an SCP client directory to which the FastIron device has access.
  2. Note: In FIPS mode, SSH and SCP use diffie-hellman-group-exchange-sha256 by default for Key Exchange. The SCP client used should be able to support this option. Any client with OpenSSH 7.2 or higher supports this option as does Putty 0.67 or higher.
    If the device is FIPS- or CC-enabled, enter the following command to copy the SHA-256/RSA-2048 signature file from the SCP client into flash memory:
    Syntax:scpsignaturefilenameusername@ipaddress:file:primary.sig secondary.sig
    $ scp SPR08095.sig test@10.20.66.70:file:primary.sig secondary.sig
    Note: If the device is not FIPS- or CC-enabled, refer to FIPS Configuration to enable FIPS or CC mode.
  3. To copy the flash code from an scp client into flash memory, enter the following command.
    Syntax:scpimage.binusername@ipaddress:flash:pri | sec:filename
    $ scp SPR08095.bin test@10.20.66.70:flash:sec:SPR08095.bin
  4. For all ICX models other than ICX 7550 and ICX 7850 devices, to copy the boot image and appropriate signature file for the boot image, enter the following command.
    $ scp swz10115.bin test@10.20.66.70:flash:bootrom
    Note: ICX 7550 and ICX 7850 devices do not support copying boot image separately. The application image and the boot image are both copied together using the ufi.bin file as shown in the following example. This is the only way to load a flash image on an ICX 7850 device.
    $ scp TNR08095ufi.bin test@10.20.66.70:flash:primary:TNR08095ufi.bin

    The ICX 7850 signature file is copied separately as shown in the following example.

    $ scp TNR08095ufi.sig test@10.20.66.70:file:primary.sig
    

  5. Verify that the flash code has been successfully copied by examining the console log or entering the show flash command at any level of the CLI.
    --FIPS: secondary image verification success
    Note: If image verification fails, the binary image is note saved.
  6. Save the running configuration by entering the write memory command.
  7. Reload the configuration to run the FIPS-enabled or CC-enabled image by entering the reload command.
    Note: The encrypted device will not pass traffic during a reboot.
  8. Repeat Step 3 with the SHA-256/RSA-2048 signature file and then repeat Step 4. This ensures digital signature verification of the flash code with the SHA-256/RSA-2048 signature file.