Loading the Flash Code Using SCP

  1. Place the new FastIron flash signature file and the new flash image in an SCP client directory to which the RUCKUS ICX device has access.
  2. Copy the SHA-256/RSA-2048 signature file from the SCP client into primary or secondary flash memory as shown in the following example.
    device# copy scp flash 1.1.1.1 TNR10010g_cd1_kccufi.sig fips-ufi-primary-sig
    device# copy scp flash 1.1.1.1 TNR10010g_cd1_kccufi.sig fips-ufi-secondary-sig
    Syntax:
    In the CR guide, it says that this command is deprecated in 09.0.00 release. (Aarthi: This command is still available for ufi signature file)
    copy scp flash source-ip-address signaturefile { fips-ufi-primary-sig | fips-ufi-secondary-sig }
  3. Copy the UFI image file from an SCP client into primary or secondary flash memory as shown in the following example.
    device# copy scp flash 1.1.1.1 TNR10010g_cd1_kccufi.bin primary
    device# copy scp flash 1.1.1.1 TNR10010g_cd1_kccufi.bin secondary
    
    Syntax: copy scp flash source-ip-address image-name { primary | secondary }
  4. (Optional) Use the windows-openssh-server command if you encounter a failure while using the Windows OpenSSH server for SCP image copying.
    device# copy scp flash 1.1.1.1 TNR10010g_cd1_kccufi.bin primary windows-openssh-server
    
    Login:test
     
    Password:
    Parameter Validation Successful
    Image Download Started
    .................................................................
    Image Download Done
    Image Validation Started
    FIPS: Image verification passed and stored in flash
    Image Write Done
    Image Download Complete
    Note: The windows-openssh-server command should not be used with Linux or other Windows-based SCP servers, as it may cause image download failures.
  5. Verify that the flash code has been successfully copied by examining the console log or entering the show flash command at any level of the CLI.
    If image verification fails, the binary image is not saved.
  6. Save the running configuration to the startup configuration using the write memory command.
    device# write memory
  7. Reload the configuration to run the Korean CC-enabled image by entering the reload command.
    Note: The encrypted device will not pass traffic during a reboot.