Performing a FIPS or CC Software Upgrade to FastIron 10.0.10d

To upgrade the FastIron software image to FastIron 10.0.10d in support of a FIPS or CC environment, perform the following steps.
  1. Place the new flash signature file and the new flash image in an SCP client directory to which the FastIron device has access.
  2. If the ICX device is FIPS- or CC-enabled, copy the SHA-256/RSA-2048 signature file from the SCP client into flash memory as shown in the following example.
    Note: If the ICX device is not FIPS- or CC-enabled, refer to FIPS Configuration to enable FIPS or CC mode.
    Note: In FIPS mode, SSH and SCP use diffie-hellman-group14-sha256 by default for Key Exchange. The SCP client used should be able to support this option. Any client with OpenSSH 7.2 or higher supports this option as does Putty 0.67 or higher.
    ICX# copy scp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-primary-sig
    ICX# copy scp flash 1.1.1.1 SPR10010dufi.sig fips-ufi-secondary-sig
    
    Syntax: copy scp flash source-ip-address signaturefileufi.sig { fips-ufi-primary-sig | fips-ufi-secondary-sig }
  3. Copy the image file from an scp client into flash memory as shown in the following example.
    ICX# copy scp flash 1.1.1.1 SPR10010dufi.bin primary
    ICX# copy scp flash 1.1.1.1 SPR10010dufi.bin secondary
    
    Syntax: copy scp flash source-ip-address image-nameufi.bin { primary | secondary }
  4. Verify that the flash code has been successfully copied by examining the console log or entering the show flash command at any level of the CLI.
    --FIPS: secondary image verification success
    Note: If image verification fails, the binary image is not saved.
  5. Save the running configuration by entering the write memory command.
  6. Reload the configuration to run the FIPS-enabled or CC-enabled image by entering the reload command.
    Note: The encrypted device will not pass traffic during a reboot.