Management Access Considerations when Upgrading from FastIron 08.0.95 to 09.0.10d or a Later Release

The following considerations apply when upgrading to FastIron 09.0.10d or later.

  • If the ICX switch configuration contains a management access command statement that allows only an IPv4 address, only IPv4 addresses will be permitted. IPv6 traffic will be blocked following upgrade.
  • If the ICX switch configuration contains a management access command statement that allows only an IPv6 address, only IPv6 addresses will be permitted on upgrade. IPv4 traffic will be blocked.
  • If the management access command allows a specific protocol, then only traffic for that protocol will be allowed. To add another protocol, an additional management access command entry must be configured.

    For example, if the system contains the configuration "management access mac 00:4e:24:45:04:00 src-ip 10.176.6.62 255.255.255.255 allow ssh log" then only SSH packets received with the source IP address 00:4e:24:45:04:00 + 10.176.6.62 will be allowed. All other traffic is dropped.

  • If you are upgrading from FastIron 09.0.00 or later to FastIron 09.0.10d and the management access command configuration contains a filter statement with more than one IP or MAC address, the configuration is removed on upgrade.

When an ICX device is updated from FastIron 08.0.95x to FastIron 09.0.10d or later, the migration adjustments described in the following scenarios are applied to preserve the configuration.

Scenario 1

The FastIron 08.0.95 configuration contains IPv6 configuration with an allow action for a particular protocol but does not contain IPv4 configuration with an allow statement for the same protocol.

Upgrade Transformation: Internally, IPv4 configuration is added to allow the protocol.

Example

FastIron 08.0.95 Configuration:

ssh access-group ipv6 ssh_acl
ipv6 access-list ssh_acl
sequence 10 permit ipv6 5::1/64 any

FastIron 09.0.10d or Later Migrated Configuration:

management access src-ipv6 5::1/64 allow ssh
management access src-ip 0.0.0.0 0.0.0.0 allow ssh

Scenario 2

The FastIron 08.0.95 configuration contains only IPv4 configuration with an allow action for a particular protocol but does not contain IPv6 configuration with an allow action for the same protocol.

Upgrade Transformation: Internally, IPv6 configuration is added to allow the protocol.

Example

FastIron 08.0.95 Configuration:

snmp-client 10.0.0.1

FastIron 09.0.10d or Later Migrated Configuration:

management access src-ip 10.0.0.1 255.255.255.255 allow snmp
management access src-ipv6 0::0/0 allow snmp

Scenario 3

The FastIron 08.0.95 configuration contains both IPv4 and IPv6 configuration with an allow action for a particular protocol.

Upgrade Transformation: No configuration is added. Configured commands are converted to equivalent management access filter statements.

Example

FastIron 08.0.95 configuration:

web client ipv6 2::1
web client 20.0.0.1

FastIron 09.0.10x migrated configuration:

management access src-ip 20.0.0.1 255.255.255.255 allow web
management access src-ipv6 2::1/128 allow web