Download Print this page

Nortel 6000 Series Manual page 9

Switched firewall

Advertisement

Pre-Upgrade Preparation
Backup configuration: You are strongly advised to backup the NSF configuration before doing the
upgrade. Please use "/cfg/ptcfg" command to export the configuration. This should be done only in
one SFD.
Downloading the upgrade Package
The upgrade package can be downloaded in different ways. In the first method, the image can be
downloaded via FTP using "/boot/software/download" CLI command. The CLI will prompt all the
detailed information, such as IP address of the server and the filename on the server, etc.
Since the NSF installation CD contains the upgrade files (i.e. pkg files), it can be used to import the pkg
file to the SFD. User can also burn his/her own CD containing the pkg file. Note that upgrade process
requires the file extension to be .pkg. The CD-ROM gets automatically ejected at the end of the
operation. This step should be done only in one SFD.
Activating the new software
Once the upgrade package is downloaded, "/boot/software/cur" can be used to display all the software
versions in the SFD. The version that was just imported will have the status "unpacked." The new
version (4.2.2) can now be activated using "/boot/software/activate". This should be done only in one
SFD.
The activation process will upgrade both the Nortel software and the Check Point software to the same
version as a clean install from the CD. Each SFD will reboot twice (if it is a HA setup) during the
upgrade process: once after the upgrade of Nortel software and again for sync to start. The whole
process could take somewhere between 15-20 minutes.
After the successful software upgrade, the following steps must be done:
Re-establish the trust for each director by,
a. Reset sic on the firewall director (/cfg/fw/sic).
b. Unload the default policy on the firewall director (/maint/diag/uldplcy).
c. On the CP management server, Reset and re-initialize sic on the firewall director object.
Push the Check Point Firewall policy from the CP management server.
Post-Upgrade Verification
The following steps should be done to verify that the upgrade process was completed successfully.
These steps are not required for a successful upgrade. However, it is recommended only for the purpose
of verification.
• Login as root and run "os-version" command. You will get the output "1.5.1.3_tng 4.2.2_R60" or
"1.5.1.3_tng.4.2.2_R65"
• Login as admin and check "/info/cluster" CLI to make sure that all the directors in the cluster are
working fine.
©2007-2008 Nortel Networks Limited
9

Advertisement

loading