General Considerations for Upgrade to or Downgrade from FastIron 09.0.10a or Later

Because of the many software design and CLI changes implemented in FastIron 09.0.10a, downgrading to a previous release is complex and may produce unexpected results.

IMPORTANT REMINDER
Be sure you have backed up your previous startup configuration before you begin any upgrade or downgrade process.

Preparing for the Upgrade

Note: Before you begin an upgrade, read the release notes for the target release carefully to familiarize yourself with any behavior and CLI changes.
As part of resolving FI-273736, the AAA authentication-method list defect, this or a similar note is being added to the FI 09.0.10x, FI 10.0.00x, and FI 10.0.10x upgrade guides (latest versions).

RUCKUS ICX FastIron 09.0.10e Release Notes

Before upgrading to FastIron 09.0.10a or a later release, RUCKUS strongly recommends the following steps:

  • Make a backup copy of the ICX startup configuration (the startup-config file). This copy will be used if a downgrade to a previous release is necessary. If you have made changes to the running configuration, you may also want to save a copy of the running-config file.

    The following example saves a copy of a FastIron 08.0.95 startup configuration and a running configuration and stores them on the TFTP server, identified by its IP address.

    ICX# copy startup-config tftp 10.176.198.42 old-8095-cfg
    ICX# Upload startup-config to TFTP server done.
    ICX# copy running-config tftp 10.176.198.42 old-8095-run-cfg
    ICX# Upload running-config to TFTP server done.

Note: A FastIron 09.0.10a or later startup-config file does not parse properly for a pre-09.0.10 release due to design changes. When you downgrade, configuration changes, including the user account configuration and stack configuration, among others, will be lost.
  • Consult the FastIron release notes and user documentation for the current release about significant software design changes that may need to be taken into consideration.

Note: If you are upgrading an ICX switch for the first time from a version earlier than FastIron 08.0.95, RUCKUS recommends that you upgrade to FastIron 08.0.95d as the intermediate version and then upgrade to FastIron 09.0.10a or later. This step is required to ensure that the FPGA version is compatible with the target release.
Note: If you are installing an ICX 7150 or ICX 7450 device that contains MCU PD69220, you can prevent the POE capabilities of the device from being disabled by upgrading the stack to FastIron 09.0.10d or later firmware prior to installing the ICX 7150 or ICX 7450 device.
Note: If you are upgrading to FastIron 09.0.10a or later and the ICX device contains the service password-encryption sha1 configuration, any users who are configured with SHA1 encryption are removed during the upgrade.
Note: If you are upgrading to FastIron 09.0.10a or later, it is recommended to re-configure the DHCP server address pool, and to configure the lease count with the number of leases specific to the address pool. Refer to "Configuring the Number of Leases for the Address Pool" in the RUCKUS FastIron DHCP Configuration Guide for more information.

Transition to cli timeout Command

The cli timeout command is introduced in FastIron 09.0.10a and replaces the ip ssh idle-time, telnet timeout, and console timeout commands. The following rules apply when converting a timer configuration from earlier releases upon upgrade to FastIron 09.0.10a or later:

  • The default value for the cli timeout command is 2 minutes, which applies if none of the replaced commands has s prior configuration. After 2 minutes, by default, a console, Telnet, or SSH session times out.
  • Previously, the default for console timeout was 0, which meant the console session never timed out. Starting with FastIron 09.0.10a, if you do not want sessions to time out, you must set the cli timeout value to 0.
  • Upon upgrade to FastIron 09.0.10a or a later release, the cli timeout value is acquired from previous configurations in the following order of priority:
    • ip ssh idle-time configuration
    • telnet timeout configuration
    • console timeout configuration