Performing a FIPS or CC Software Upgrade to FastIron 08.0.95
To upgrade the FastIron software image to
FastIron 08.0.95 in support of a FIPS or CC environment, perform the following steps.
- Place the new flash signature file and the new flash image in an SCP client directory to which the FastIron device has access.
-
Note: In FIPS mode, SSH and SCP use diffie-hellman-group-exchange-sha256 by default for Key Exchange. The SCP client used should be able to support this option. Any client with OpenSSH 7.2 or higher supports this option as does Putty 0.67 or higher.If the device is FIPS- or CC-enabled, enter the following command to copy the SHA-256/RSA-2048 signature file from the SCP client into flash memory:
$ scp SPR08095.sig test@10.20.66.70:file:primary.sig secondary.sig
Note: If the device is not FIPS- or CC-enabled, refer to FIPS Configuration to enable FIPS or CC mode. - To copy the flash code from an scp client into flash memory, enter the following command.
- For all ICX models other than
ICX 7550 and ICX 7850 devices, to copy the boot image and appropriate signature
file for the boot image, enter the following command. Note: ICX 7550 and ICX 7850 devices do not support copying boot image separately. The application image and the boot image are both copied together using the ufi.bin file as shown in the following example. This is the only way to load a flash image on an ICX 7850 device.
$ scp TNR08095ufi.bin test@10.20.66.70:flash:primary:TNR08095ufi.bin
The ICX 7850 signature file is copied separately as shown in the following example.
$ scp TNR08095ufi.sig test@10.20.66.70:file:primary.sig
- Verify that the flash code has been successfully copied by examining the console log
or entering the
show flashcommand at any level of the CLI.Note: If image verification fails, the binary image is note saved. - Save the running configuration by entering the
write memorycommand. - Reload the configuration to run the FIPS-enabled or CC-enabled image by entering the
reloadcommand.Note: The encrypted device will not pass traffic during a reboot. - Repeat Step 3 with the SHA-256/RSA-2048 signature file and then repeat Step 4. This ensures digital signature verification of the flash code with the SHA-256/RSA-2048 signature file.