R9628P2414. Before you use this version on a live network, back up the configuration and test the version to avoid software upgrade affecting your live network. Use this document in conjunction with H3C SECPATH5080F-CMW710-R9628P2414Release Notes (Software Feature Changes) and the documents listed in "Related...
[CVE-2011-1473]: SSL does not properly restrict client-initiated renegotiation, and SSL clients can renegotiate successfully. Version information Version number H3C Comware software, Version 7.1.064, Release 9628P2414 Note: You can see the version number with the display version command in any view. Please see Note①. Version history IMPORTANT: The software feature changes listed in the version history table for each version are not complete.
Page 8
Version number Last version Release date Release type Remarks Released for resolved R9628P24 F9628P22 2021-02-25 Release version problems and for the use of technical support. Release for resolved problems. F9628P22 F9628P20 2021-01-12 Feature version Restricted to the use of technical support. Release for resolved problems.
Sample: To display the host software and BootWare version of F5030, perform the following: <H3C> display version H3C Comware Software, Version 7.1.064, Release 9628P2414 ----Note① Copyright (c) 2004-2021 New H3C Technologies Co., Ltd. All rights reserved. H3C SecPath F5080 uptime is 0 weeks, 0 days, 5 hours, 38 minutes...
SECPATH5080F-CMW710-E9628P07 Compatible SECPATH5080F-CMW710-E9628P05 Compatible SECPATH5080F-CMW710-E9628P03 Compatible Upgrade restrictions and guidelines To ensure hardware compatibility, do not downgrade the factory software version. For the signature databases for anti-virus and URL filtering, the official website provides two sizes for different device storage spaces. The letter H in the name indicates a large signature database.
Software feature and command updates This version added support for sending logs to log hosts in SGCC format. For more information about the software feature and command update history, see H3C SECPATH5080F-CMW710-R9628P2413Release Notes (Software Feature Changes). MIB updates...
Safari 5 or higher. Internet Explorer 9 or higher. When two power modules are installed, do not repeatedly re-install them within a short period. To avoid the CPU errors caused by frequent power module re-installation, install power modules correctly in one operation.
Resolved problems in R9628P2412 None. Resolved problems in R9628P2410 202102070830 Symptom: The CPU usage information of the 2.6GHz multi-core CPU is abnormal. Some cores' usage rates exceed 100%. Condition: This symptom occurs when you execute the display process cpu i drv command to view CPU usage information on the device running R9628P24 or a lower version.
Resolved problems in R9628P13 None. Resolved problems in F9628P12 202001070642 Symptom: The rate of file download through the Server Message Block protocol is very low. Condition: This symptom occurs if the device is configured with bandwidth management, audit management, or IPS settings.
H3C SecPath PSR650B-12A1 & PSR650B-12D1 Power Modules User Manual-6W102 H3C SecPath Firewall Command References(V7) H3C SecPath Firewall Configuration Guides(V7) Obtaining documentation To obtain the related documents from the H3C website at http://www.h3c.com/en: Click http://www.h3c.com/en/Support/Resource_Center/Technical_Documents. Choose the desired product category and model. Technical support service@h3c.com http://www.h3c.com/en...
Item Specifications Operating: Operating Without hard disks: 0°C to 45°C (32°F to 113°F) temperatu With hard disks: 5°C to 40°C (41°F to 104°F) Storage: –40°C to 70°C (–40°F to 158°F) Operating: Without hard disks: 5% RH to 95% RH, noncondensing ...
Page 20
Category Features Email sender/recipient-based filtering. Email subject/content/attachment filtering. Email filtering Uploaded/downloaded FTP file filtering. Support for matching Chinese character codes. Setting the maximum upstream bandwidth and the maximum downstream bandwidth. Setting the guaranteed upstream bandwidth and the guaranteed downstream bandwidth. Specifying traffic profiles based on parameters such as source security zone, Bandwidth destination security zone, source address, destination address, application,...
Category Features the Web interface. Support for SNMPv3 and compatibility with SNMPv2C and SNMPv1. Network management NTP time synchronization. Appendix B Upgrading software CAUTION: Do not power off or reboot the device during the upgrade process. The software upgrade procedure is the same for all security devices. This chapter describes how to upgrade software from the CLI, Web interface, and BootWare menus.
Configuration files You can save settings you made to a configuration file so they can survive a reboot. The device supports .cfg configuration files. The default .cfg configuration file is named startup.cfg. Upgrade methods To upgrade system software, use one of the following methods: ...
Figure 1 Setting up the upgrade environment TFTP/FTP Client Ethernet Console cable cable TFTP/FTP Server Upgrading system software This configuration example upgrades system software from R8513 to R8514. The system software image file name is main.ipe. Upgrading system software from the CLI You can use TFTP or FTP on the device to access the TFTP or FTP server to back up or download software files.
Page 25
c. Specify boot_backup.bin and system_backup.bin as the backup startup image files. <Sysname> boot-loader file boot cfa0:/boot_backup.bin system cfa0:/system_backup.bin backup d. Execute the save command in any view to save the running configuration. <Sysname> save The current configuration will be written to the device. Are you sure? [Y/N]:y Please input the file name(*.cfg)[cfa0:/startup.cfg] (To leave the existing filename unchanged, press the enter key): cfa0:/startup.cfg exists, overwrite? [Y/N]:y...
Page 26
<Sysname> boot-loader file cfa0:/main.ipe all main Verifying the file cfa0:/main.ipe on slot 1..Done. H3C SecPath T5020 images in IPE: main-cmw710-boot-R8514.bin main-cmw710-system-R8514.bin This command will set the main startup software images. Please do not reboot any MPU during the upgrade.
Page 27
<Sysname> display version H3C Comware Software, Version 7.1.064, Release 8514 Copyright (c) 2004-2018 New H3C Technologies Co., Ltd. All rights reserved. H3C SecPath T5020 uptime is 0 weeks, 2 days, 5 hours, 53 minutes Last reboot reason: User reboot Boot image: cfa0:/main-cmw710-boot-R8514.bin Boot image version: 7.1.064, Release 8514...
Page 28
<Sysname> boot-loader file boot cfa0:/boot_backup.bin system cfa0:/system_backup.bin backup d. Execute the save command in any view to save the running configuration. <Sysname> save The current configuration will be written to the device. Are you sure? [Y/N]:y Please input the file name(*.cfg)[cfa0:/startup.cfg] (To leave the existing filename unchanged, press the enter key): cfa0:/startup.cfg exists, overwrite? [Y/N]:y Validating file.
Page 29
<Sysname> boot-loader file cfa0:/main.ipe all main Verifying the file cfa0:/main.ipe on slot 1..Done. H3C SecPath T5020 images in IPE: main-cmw710-boot-R8514.bin main-cmw710-system-R8514.bin This command will set the main startup software images. Please do not reboot any MPU during the upgrade.
Page 30
<Sysname> display version H3C Comware Software, Version 7.1.064, Release 8514 Copyright (c) 2004-2018 New H3C Technologies Co., Ltd. All rights reserved. H3C SecPath T5020 uptime is 0 weeks, 2 days, 5 hours, 53 minutes Last reboot reason: User reboot Boot image: cfa0:/main-cmw710-boot-R8514.bin Boot image version: 7.1.064, Release 8514...
Upgrading system software from the Web interface CAUTION: You can use the default account settings or create a new account to log in to the Web interface for the first time. This section uses the default account settings. For security purposes, if you use the default account settings, modify the default password or create a new account and delete the default account after the first login.
Figure 2 Upgrade Immediately page Upgrading system software from BootWare menus To upgrade Comware images from BootWare menus, use one of the following methods: Using TFTP to upgrade system software through the management Ethernet port Using FTP to upgrade system software through the management Ethernet port Preparing for the upgrade Connect the configuration terminal to the MPU's console port.
Page 33
============================================================================ Enter your choice(0-5): Enter 5 in the Ethernet submenu to configure the network settings. NOTE: To use the existing setting for a field, press Enter without modifying the setting. ======================<ETHERNET PARAMETER SET>============================== |Note: '.' = Clear field. '-' = Go to previous field. Ctrl+D = Quit.
Page 34
|<0> Exit To Main Menu |<Ensure The Parameter Be Modified Before Downloading!> ============================================================================ Enter your choice(0-5): Enter 2 or 3 in the Ethernet submenu to upgrade the main or backup software images. For example, enter 2 to upgrade the main software images. Loading..............
Page 35
|Note: '.' = Clear field. '-' = Go to previous field. Ctrl+D = Quit. ============================================================================ Protocol (FTP or TFTP):ftp Load File Name :main.ipe Target File Name :main.ipe Server IP Address :192.168.0.2 Local IP Address :192.168.0.1 Subnet Mask :255.255.255.0 Gateway IP Address :0.0.0.0 FTP User Name :admin...
Upgrading the BootWare from the CLI Whether a .btw file is compressed together with an .ipe file depends on the device model and software release. Please check it with H3C technical support. This section describes only how to upgrade the BootWare from the CLI.
Update extended bootrom success! Update bootrom success! <System> Execute the reboot command to reboot the device. Upgrading BootWare from BootWare menus To upgrade the BootWare image from BootWare menus, use one of the following methods: Using TFTP to upgrade BootWare through the management Ethernet port ...
Page 38
Enter 4 in the Ethernet submenu to configure the network settings. NOTE: To use the existing setting for a field, press Enter without modifying the setting. ==========================<ETHERNET PARAMETER SET>========================== |Note: '.' = Clear field. '-' = Go to previous field. Ctrl+D = Quit.
Page 39
Enter 0 to return to the BootWare Operation menu. Enter 0 in the BootWare Operation menu to return to the EXTEND-BOOTWARE menu. Enter 0 in the EXTEND-BOOTWARE menu to reboot the system. Using FTP to upgrade BootWare through the management Ethernet port Enter 7 in the BootWare menu to access the BootWare Operation submenu.
|<1> Update Full BootWare |<2> Update Extended BootWare |<3> Update Basic BootWare |<4> Modify Ethernet Parameter |<0> Exit To Main Menu ============================================================================ Enter your choice(0-4): Choose an option from options 1 to 3. For example, enter 1 to upgrade the entire BootWare image.
Appendix C Using BootWare menus Overview BootWare provides a menu method to perform basic file operations, software upgrade, and system management when the Comware CLI is inaccessible because of image corruption. BootWare is stored in each MPU's built-in the SD card. It has one basic segment and one extended segment.
Shortcut Prompt message Function keys Press Ctrl+D to access Accesses the BASIC-BOOTWARE menu BASIC-BOOTWARE MENU while the device is starting up. Ctrl+D Ctrl+D = Quit Exits the parameter settings menu. Memory Test(press Ctrl+C to skip it,press Ctrl+E Prints information during the memory test. Ctrl+E to ECHO INFO) Ctrl+F Ctrl+F: Format File System...
Option Task Reference Upgrade the entire BootWare, <3> Update Full including the basic segment and Upgrading the entire BootWare BootWare the extended segment. <4> Boot Extended Run the primary extended Running the primary extended BootWare BootWare segment. BootWare segment <5> Boot Backup Extend Run the backup extended Running the backup extended BootWare...
Enter your choice(0-5): 4 Booting Normal Extended BootWare. The Extended BootWare is self-decompressing..Done. **************************************************************************** H3C SecPath BootWare, Version 1.05 **************************************************************************** Copyright (c) 2004-2017 New H3C Technologies Co., Ltd. Compiled Date : Aug 31 2017 Memory Type : DDR3 SDRAM Memory Size...
Return to the BASIC-BOOTWARE menu. Testing the memory IMPORTANT: To avoid unexpected exceptions, perform this task under the guidance of H3C Support. To test the memory, use one of the following methods: In the BASIC-BOOTWARE menu, press Ctrl+T within 4 seconds after the "Press Ctrl+T to start memory test"...
Page 46
Memory Type : DDR3 SDRAM Memory Size : 16384MB Sda0 Size : 8MB sda0 Size : 3728MB CPLD Version : 1.0 PCB Version : Ver.B BootWare Validating... Press Ctrl+B to access EXTENDED-BOOTWARE MENU... Password recovery capability is enabled. Note: The current operating device is sda0 Enter <...
Option Tasks Reference Display files on the current storage medium. Set a Comware image file as the main or backup <4> File Control Managing files startup software image file. Delete files to release storage space. Restore the factory-default configuration.
If a user role password is lost, the user can skip the configuration file, and then access the CLI to configure a new password. If password recovery capability is disabled, console users must restore the factory-default configuration before they can configure new passwords. To enhance system security, disable password recovery capability.
Table 16 Serial submenu options Option Tasks Load and run Comware images in SDRAM. <1> Download Image Program To This option is available only if password recovery capability is SDRAM And Run enabled. Download Comware images to the current storage medium as the main images (the file attribute is set to M).
Page 50
Table 17 Ethernet submenu options Option Description Load and run software images in SDRAM. <1> Download Image Program To SDRAM If password recovery capability is enabled, this option And Run is not available. Download software images to the current storage medium as main images (the file attribute is set to M).
Field Description Set a file name for saving the file in the current storage medium on the device. Target File Name By default, the target file name is the same as the source file name. Server IP Address Set the IP address of the FTP or TFTP server. Local IP Address Set the IP address of the device.
Page 52
Display all file(s) in cfa0: 'M' = MAIN 'B' = BACKUP 'N/A' = NOT ASSIGNED ============================================================================ |NO. Size(B) Time Type Name Jan/21/2019 17:59:34 N/A cfa0:/ifindex.dat 24671 Mar/28/2018 09:08:56 N/A cfa0:/wdydiudie.cfg Mar/28/2018 09:18:22 N/A cfa0:/hostkey 116549 Oct/09/2017 13:51:02 N/A cfa0:/lwb-t5k.cfg Mar/27/2018 15:24:12 N/A cfa0:/license/history/deviceid_2| |0180327152412.did Mar/27/2018 15:24:12 N/A...
Page 56
|130 110592 Jan/31/2018 14:31:18 N/A cfa0:/core/node16_dpid_202565_11| |_20180131-143118_1517409078.core |131 118784 Jul/24/2018 11:51:10 N/A cfa0:/core/node16_ntopd_820_11_2| |0180724-115110_1532433070.core |132 118784 Dec/17/2018 08:32:20 N/A cfa0:/core/node16_ntopd_803_11_2| |0181217-083220_1545035540.core |133 3249 Apr/16/2018 16:40:28 N/A cfa0:/ngips2018041616523608292.a| ============================================================================ Setting the attribute for software images Enter 2 in the File Control submenu. ===============================<File CONTROL>=============================== |Note:the operating device is cfa0 |<1>...
Page 57
Saving file cfa0:/main-cmw710-system-E8524P15.bin ...................................................Done. Set the file attribute success! Setting the attribute for .bin files Enter 3 in the File Control submenu. Enter your choice(0-5): 3 'M' = MAIN 'B' = BACKUP 'N/A' = NOT ASSIGNED ============================================================================ |NO.
Page 58
Deleting the file in cfa0: 'M' = MAIN 'B' = BACKUP 'N/A' = NOT ASSIGNED ============================================================================ |NO. Size(B) Time Type Name Jan/21/2019 17:59:34 N/A cfa0:/ifindex.dat 24671 Mar/28/2018 09:08:56 N/A cfa0:/wdydiudie.cfg Mar/28/2018 09:18:22 N/A cfa0:/hostkey 116549 Oct/09/2017 13:51:02 N/A cfa0:/lwb-t5k.cfg Mar/27/2018 15:24:12 N/A cfa0:/license/history/deviceid_2| |0180327152412.did Mar/27/2018 15:24:12 N/A...
|129 231817 Jan/31/2018 10:53:26 N/A cfa0:/dpi1.mdb |130 110592 Jan/31/2018 14:31:18 N/A cfa0:/core/node16_dpid_202565_11| |_20180131-143118_1517409078.core |131 118784 Jul/24/2018 11:51:10 N/A cfa0:/core/node16_ntopd_820_11_2| |0180724-115110_1532433070.core |132 118784 Dec/17/2018 08:32:20 N/A cfa0:/core/node16_ntopd_803_11_2| |0181217-083220_1545035540.core |133 3249 Apr/16/2018 16:40:28 N/A cfa0:/ngips2018041616523608292.a| Exit ============================================================================ Enter file No.: Enter the number of the file to delete. For example, enter 13 to delete the sda0:/test.cfg file. When the following message appears, enter Y.
To start the device with the factory-default configuration: Enter 6 in the EXTEND-BOOTWARE menu and press Enter. Enter your choice(0-9): 6 Flag Set Success. Follow the system instruction to complete the task. If password recovery capability is enabled, the device uses the factory-default configuration ...
Clear Image Password Success! If password recovery capability is disabled, first enable the capability from the CLI, and then reboot the device to access the EXTENDED-BOOTWARE menu. Password recovery capability is disabled. To perform this operation, first enable the password recovery capability using the password-recovery enable command in CLI. Managing storage media Enter 9 in the EXTEND-BOOTWARE menu and press Enter.
Formatting the file system CAUTION: Formatting the file system clears all files and directories in a storage medium permanently. The cleared files and directories cannot be recovered. Press Ctrl+F in the EXTEND-BOOTWARE menu. Warning:All files on sda0 will be lost! Are you sure to format? [Y/N]...
Need help?
Do you have a question about the SECPATH 5080F-CMW710-R9628P2414 and is the answer not in the manual?
Questions and answers