Loading the Flash Code Using TFTP
- Place the new FastIron flash signature file and the new flash image in a TFTP server directory to which the RUCKUS ICX device has access.
- Enter the global configuration
mode and enable TFTP access using the
fips policy allow tftp-accesscommand. - Copy the SHA-256/RSA-2048
signature file from the TFTP server into flash memory as shown in the following
example.
device# copy tftp flash 10.246.201.17 TNR10010g_cd1devufi.sig fips-ufi-primary-sig Parameter Validation Successful Signature Download Started SYSLOG: <14>1 2025-04-07T04:21:26Z ICX7550 ICX7550 - - [meta sequenceId=43] BOM Download: SIGNATURE DOWNLOAD STARTED by super Signature Download Done Signature Write Done SYSLOG: <14>1 2025-04-07T04:21:30Z ICX7550 ICX7550 - - [meta sequenceId=44] BOM Download: SIGNATURE COPY COMPLETED by super Signature Download Complete
- Copy the UFI image file from the
TFTP server into flash memory as shown in the following example.
device# copy tftp flash 10.246.201.17 TNR10010g_cd1devufi.bin primary Parameter Validation Successful Image Download Started SYSLOG: <14>1 2025-04-07T04:21:36Z ICX7550 ICX7550 - - [meta sequenceId=45] BOM Download: COPY IMAGE TO FLASH START by super Image Download Done Image Validation Started FIPS: Image verification passed and stored in flash SYSLOG: <14>1 2025-04-07T04:21:53Z ICX7550 ICX7550 - - [meta sequenceId=46] BOM Download: FIPS IMAGE VERIFICATION PASSED AND STORED IN FLASH by super Image Validated SYSLOG: <14>1 2025-04-07T04:21:53Z ICX7550 ICX7550 - - [meta sequenceId=47] BOM Download: COPY APPLICATION IMAGE FROM BUNDLE START by super SYSLOG: <14>1 2025-04-07T04:21:53Z ICX7550 ICX7550 - - [meta sequenceId=48] BOM Download: COPY BOOTROM IMAGE FROM BUNDLE START by super Image Write Done SYSLOG: <14>1 2025-04-07T04:22:30Z ICX7550 ICX7550 - - [meta sequenceId=49] BOM Download: COPY BUNDLE IMAGE COMPLETED by super Image Download Complete
- Verify that the flash code has
been successfully copied by examining the console log or entering the
show flashcommand at any level of the CLI.If image verification fails, the binary image is not saved. - Save the running configuration
to the startup configuration using the
write memorycommand. - Reload the configuration to run
the Korean CC-enabled image by entering the
reloadcommand.Note: The encrypted device will not pass traffic during a reboot.