Escolar Documentos
Profissional Documentos
Cultura Documentos
USG2100
V100R003C01SPC010
Issue
01
Date
2010-5-12
Huawei Symantec Technologies Co., Ltd. provides customers with comprehensive technical support and
service. Please feel free to contact our local office or company headquarters.
Building 1
The West Zone Science Park of UESTC, No. 88, Tianchen Road
Chengdu, 611731
P.R.China
Website:
http://www.huaweisymantec.com
Tel:
400-888-2333
Fax:
+86-028-87897555
Mailbox:
support@huaweisymantec.com
Note
The information in this document is subject to change without notice. Every effort has been made in the
preparation of this document to ensure accuracy of the contents, but all statements, information, and
recommendations in this document do not constitute the warranty of any kind, express or implied.
Issue 01 (2010-5-12)
Page 2 of 47
Contents
1 Upgrade Mode Overview................................................................7
1.1 Upgrade Mode...................................................................................................................................................7
1.1.1 Upgrade During Device Startup...............................................................................................................7
1.1.2 Upgrade When Device Is Running...........................................................................................................7
2 Upgrade Impacts........................................................................... 9
3 Upgrade Procedure.....................................................................10
3.1 Upgrade Procedure of Versions Earlier than V100R001C01SPC001.............................................................10
3.1.1 Upgrade Flow Chart...............................................................................................................................10
3.1.2 Upgrade Procedure.................................................................................................................................11
3.2 Upgrade Procedure of V100R001C01SPC001 and Later Versions.................................................................12
3.2.1 Upgrade Flow Chart...............................................................................................................................12
3.2.2 Upgrade Procedure.................................................................................................................................13
5 Upgrade Operations....................................................................21
5.1 Upgrade Operations of Versions Earlier than V100R001C01SPC001............................................................21
5.2 Upgrade Operations of V100R001C01SPC001 and Later Versions................................................................28
5.2.1 Upgrade Operations During Device Startup...........................................................................................28
5.2.2 Upgrade Operations When Device Is Running......................................................................................32
6 Upgrade Verification.................................................................... 34
6.1 Verification Checklist.......................................................................................................................................34
6.1.1 Querying the Host Software Version......................................................................................................34
7 Version Rollback.........................................................................37
7.1 Rollback Operations of Versions Earlier than V100R001C01SPC001...........................................................38
7.1.1 Rollback Flow Chart...............................................................................................................................38
USG2100 V100R003C01SPC010
Version Upgrade Instructions
7.1.2 Rollback Operations...............................................................................................................................39
7.2 Rollback Operations of V100R001C01SPC001 and Later Versions...............................................................45
7.2.1 Rollback Flow Chart...............................................................................................................................45
7.2.2 Rollback Operations...............................................................................................................................45
A Upgrade Record..........................................................................47
Issue 01 (2010-5-12)
Page 4 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Figures
Figure 3-1 Flow chart of upgrade during device startup.......................................................................................10
Figure 3-2 Flow chart of upgrade during device startup.......................................................................................12
Figure 3-3 Flow chart of upgrade when device is running...................................................................................12
Figure 4-1 Connection between the PC and the USG2100 through the serial port..............................................15
Figure 4-2 Connection between the PC and the USG2100 through the Ethernet interface..................................16
Figure 4-3 Creating a connection..........................................................................................................................16
Figure 4-4 Connect to dialog box.........................................................................................................................17
Figure 4-5 Setting port parameters........................................................................................................................17
Figure 7-1 Flow chart of the version Earlier than V100R001C01SPC001 rollback....................38
Figure 7-2 Flow chart of V100R001C01SPC001 and later versions rollback...............................45
Issue 01 (2010-5-12)
Page 5 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Tables
Table 3-1 Procedure for upgrade during device startup........................................................................................11
Table 3-2 Procedure for upgrade during device startup........................................................................................13
Table 3-3 Procedure for upgrade when device is running.....................................................................................13
Table 4-1 Checklist before upgrade.......................................................................................................................19
Table 5-1 Parameters of the FTP mode.................................................................................................................26
Table 5-2 Parameters of the FTP mode.................................................................................................................30
Table 6-1 Verification checklist.............................................................................................................................34
Table 7-1 Parameters of the FTP/TFTP mode.......................................................................................................42
Issue 01 (2010-5-12)
Page 6 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Issue 01 (2010-5-12)
Page 7 of 47
Upgrade Impacts
If the USG2100 is running on the current network, using the upgrade method described
in section 1.1.1Upgrade During Device Startup leads to service interruption during the
upgrade. Using the upgrade method described in section 1.1.2Upgrade When Device Is
Running requires the reboot of the firewall after the software package is loaded, which leads
to service interruption. You can determine when to perform the upgrade according to the
actual situation.
When USG2100 V100R001C01B01c or USG2100V100R001C01B01f is upgraded to
USG2100 V100R003C01SPC010, the Flash needs to be formatted, which results in the loss
of important files such as the configuration files. Therefore, before the version upgrade,
configuration files, host software, and license files should be backed up. For details, see
section 4.1.3.
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Upgrade Procedure
Issue 01 (2010-5-12)
Page 10 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Issue 01 (2010-5-12)
Page 11 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Operation
Impact
Duration
Mandatory
or Optional
None
About 1
min
Mandatory
Load the
software upgrade
package through
the BootROM
during the
startup.
About 3 min
Mandatory
None
Null
configuration
file: About 2
min
Mandatory
None
About 1 min.
Mandatory
None
About 0.5
min.
Mandatory
None
Null
configuration
file: About 2
min.
Mandatory
Issue 01 (2010-5-12)
Page 12 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Issue 01 (2010-5-12)
Page 13 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Operation
Load the
software
upgrade
package
through the
BootROM
during the
startup.
Impact
Duration
Mandatory
or Optional
About 3
min
Mandatory
None
Null
configuratio
n file:
About 3
min
Mandatory
None
About 1
min
Mandatory
None
Null
configuratio
n file:
About 3
min
Mandatory
Impact
Duration
Mandatory
or Optional
None
About 3
min
Mandatory
Operation
Load the
software
upgrade
package when
device is
running by
running
commands.
Issue 01 (2010-5-12)
Page 14 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Issue 01 (2010-5-12)
Null
configuratio
n file:
About 2
min
Mandatory
Page 15 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Configuration Notes
The FTP or TFTP software must be installed on the PC. The FTP and TFTP software is not
described here because it is a third-party software.
The Ethernet cable for upgrade must be inserted to the WAN interface other than the LAN
interface. Otherwise, the upgrade fails.
Operation Procedure
Step 1 Connect a serial port of the PC and the Console port on the MPU of the USG2100 through a
serial port cable, as shown in Figure 1.1.
Issue 01 (2010-5-12)
Page 16 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Figure 1.1 Connection between the PC and the USG2100 through the serial port
Console cable
PC
Console interface
USG2100
Step 2 Connect the Ethernet interface of the PC and the WAN interface on the MPU of the USG2100
through a network cable, as shown in Figure 1.1.
Figure 1.1 Connection between the PC and the USG2100 through the Ethernet interface
Step 3 Start the FTP server or TFTP server software on the PC.
Step 4 Save the software package for upgrade to the FTP or TFTP root directory.
For how to obtain the software package, see section 4.1.2.
Step 5 Set serial port parameters.
1.
Run the terminal emulation program such as the HyperTerminal on the PC. Choose Start
> All Programs > Accessories > Communications > Hyper Terminal. The
Connection Description dialog box is displayed.
2.
Input the name of the connection, such as COMM1 in the field Name, between the PC
and the USG2100. Select one of the icons, as shown in Figure 2.1.
Issue 01 (2010-5-12)
Page 17 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
3.
4.
Select the serial port such as COM1 used for the connection from the Connect using
drop down list, as shown in Figure 4.1.
5.
6.
Issue 01 (2010-5-12)
Page 18 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
7.
Click OK.
Other terminal software can be used instead of HyperTerminal.
----End
Result Verification
Start the USG2100. Check whether the startup information collected through the serial port is
displayed on the HyperTerminal of the PC. If the information is collected through the serial
port, it indicates that the connection between the PC and the USG2100 is established and the
serial port cable is properly connected.
Issue 01 (2010-5-12)
Page 19 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
USG2100_V1R3C01SPC010.bin
big.bin
Operation Procedure
Obtain the reference and version from the customer service center. The phone number of the
customer service center is 400-888-2333.
Configuration Notes
The FTP or TFTP software must be installed on the PC. The FTP and TFTP software is not
described here because it is a third-party software.
Operation Procedure
Step 1 Start the FTP or TFTP server on the PC.
Step 2 Configure the IP addresses of the USG2100 and PC so that the USG2100 and PC can
communicate with each other.
Step 3 Upload the host software, current configuration files, and license files on the USG2100 to the
FTP server for backup.Log in to the FTP server through the FTP client.In the user view, enter
ftp <the IP address of the FTP server>. You can log in to the FTP server and then upload the
configuration files and license files to the FTP server.
<USG2100>ftp 10.2.1.2
Trying 10.2.1.2 ...
Press CTRL+K to abort
Connected to 10.2.1.2.
220 WFTPD 2.0 service (by Texas Imperial Software) ready for new user
User(10.2.1.2:(none)):123
331 Give me your password, please
Password:
230 Logged in successfully
[ftp]put vrpcfg.zip (Note: vrpcfg.zip is the current configuration file.)
200 PORT command okay
150 "D:\vrpcfg.zip" file ready to receive in ASCII mode
226 Transfer finished successfully.
FTP: 891 byte(s) sent in 0.117 second(s) 7.61Kbyte(s)/sec.
[ftp]put license.dat Note: license.dat is the currently used license file.
200 PORT command okay
Issue 01 (2010-5-12)
Page 20 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
150 "D:\license.dat" file ready to receive in ASCII mode
226 Transfer finished successfully.
FTP: 2093 byte(s) sent in 0.117 second(s) 17.88Kbyte(s)/sec.
[ftp]
[ftp]put usg2100v1r1c01b01f.bin Note: usg2100v1r1c01b01f.bin is the currently
used system software
200 PORT command okay
150 "D:\ usg2100v1r1c01b01f.bin " file ready to receive in ASCII mode
226 Transfer finished successfully.
FTP: 5763764 byte(s) sent in 11.200 second(s) 502.56Kbyte(s)/sec.
----End
Item
Check Points
Task Description
1.
2.
In the case of the startup with null configurations, the default user name is admin and
the password is Admin@123.
Issue 01 (2010-5-12)
Page 21 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Upgrade Operations
Step 3 Switch on the power and power on the device or restart the device.
Step 4 Upload the host software, current configuration files, and license files on the USG2100 to the
FTP server for backup. Log in to the FTP server through the FTP client. In the user view, enter
ftp <the IP address of the FTP server>. You can log in to the FTP server and then upload
the configuration files and license files to the FTP server.
<USG2100>ftp 10.2.1.2
Trying 10.2.1.2 ...
Press CTRL+K to abort
Connected to 10.2.1.2.
220 WFTPD 2.0 service (by Texas Imperial Software) ready for new user
User(10.2.1.2:(none)):123
331 Give me your password, please
Password:
230 Logged in successfully
[ftp]put vrpcfg.zip (Note: vrpcfg.zip is the current configuration file)
200 PORT command okay
150 "D:\vrpcfg.zip" file ready to receive in ASCII mode
226 Transfer finished successfully.
FTP: 891 byte(s) sent in 0.117 second(s) 7.61Kbyte(s)/sec.
[ftp]put license.dat Notelicense.dat is the currently used license file
200 PORT command okay
Issue 01 (2010-5-12)
Page 22 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
150 "D:\license.dat" file ready to receive in ASCII mode
226 Transfer finished successfully.
FTP: 2093 byte(s) sent in 0.117 second(s) 17.88Kbyte(s)/sec.
[ftp]
[ftp]put usg2100v1r1c01b01f.bin Noteusg2100v1r1c01b01f.bin is the currently
used system software
200 PORT command okay
150 "D:\ usg2100v1r1c01b01f.bin " file ready to receive in ASCII mode
226 Transfer finished successfully.
FTP: 5763764 byte(s) sent in 11.200 second(s) 502.56Kbyte(s)/sec.
Step 5 When starting the device, you can view the startup process of the main control board on the
serial port tool. If the following information is displayed, press and hold Ctrl+A to enter the
SMALL-BOOTROM menu.
NOW GO TO C CODE...
Go on Checking the Sdram? Yes or No(Y/N):
Press CTRL+A to Stop AutoBoot!
Starting...
===============<SMALL-BOOTROM MENU(Ver 1.07)>===============
|
Creation date: Jan 4 2009, 11:22:55
|
| <1> Change BaudRate
|
| <2> Update LargeBootrom
|
| <3> Boot Main System
|
| <0> Reboot
|
=============================================================
Enter your choice(0-3): 2
Step 6 In the SMALL-BOOTROM menu, enter 2. Choose Transfer > Send File on the serial port
tool.
The following interface is displayed. (Select the directory where big.bin is saved as the
viewing part, and select Xmodem in the protocol drop-down list.) The selection must be
Issue 01 (2010-5-12)
Page 23 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
quick, or if the time for upgrading exceeds the timeout time, you need to select both big.bin
and Xmodem once again.
Step 7 Enter 0. The device restarts. When starting the device, you can view the startup
process of the main control board on the serial port tool. When the following
information is displayed, press and hold Ctrl+B to enter the BootROM main menu
*************************************************************
*
Bootrom, Ver1.31
*************************************************************
Issue 01 (2010-5-12)
Page 24 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
CPU type
CPU L1 Cache
CPU Clock Speed
Memory Size
: MPC8321E
: 32KB
: 333MHz
: 256M
Press Ctrl+B within four seconds and enter the password when Password: is displayed to access the
BootROM main menu. The default password for accessing the BootROM main menu is Secospace.
Step 8 In the BootROM main menu, enter Ctrl+Z to enter the Hidden submenu, format the Flash, and
then return to the main menu.
Hidden Menu...
======================<HIDDEN SUB-MENU>======================
| <1> Delete file from Flash
|
| <2> Init Flash File System Space.
|
| <3> Display Flash Files
|
| <4> Enter Flash-Aging Test
|
| <5> Flash Test
|
| <6> E2PRom Test
|
| <7> CPLD Test
|
| <8> DDR memory Test
|
| <9> System Clock Test
|
| <a> System Led Test
|
| <b> Show System-Aging Result
|
| <c> VRPSoftware Backup
|
| <d> Recover console0 password
|
| <e> Big Bootrom Backup
|
| <f> Small Bootrom Upgrade
|
| <g> VRPSoftware Backup Test
|
| <0> Exit To Main Menu
|
=============================================================
Enter your choice(0-g): 2
Init Flash File System Space...
Formatting Flash, Please Waiting ...Done.
======================<HIDDEN SUB-MENU>======================
| <1> Delete file from Flash
|
Issue 01 (2010-5-12)
Page 25 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
| <2> Init Flash File System Space.
|
| <3> Display Flash Files
|
| <4> Enter Flash-Aging Test
|
| <5> Flash Test
|
| <6> E2PRom Test
|
| <7> CPLD Test
|
| <8> DDR memory Test
|
| <9> System Clock Test
|
| <a> System Led Test
|
| <b> Show System-Aging Result
|
| <c> Recover console0 password
|
| <d> Big Bootrom Backup
|
| <e> Small Bootrom Upgrade
|
| <0> Exit To Main Menu
|
=============================================================
Enter your choice(0-f):0
=====================<MAIN-BOOTROM MENU>=====================
| <1> Boot With Default Mode
|
| <2> Boot From Flash
|
| <3> Enter Serial SubMenu
|
| <4> Enter Ethernet SubMenu
|
| <5> Change Flash Boot File
|
| <6> Modify Bootrom Password
|
| <7> Restore Factory Setting
|
| <8> Restore Default Config
|
| <0> Reboot
|
=============================================================
Enter your choice(0-8):
Step 9 In the BootROM main menu, enter 4 to enter the Ethernet submenu.
Enter your choice(0-8):4
Boot From Net Port.
=====================<NETWORK SUB-MENU>======================
| <1> Download Program To SDRAM And Run
|
| <2> Download Program To Flash
|
| <3> Change Boot Parameter...
|
| <0> Exit To Main Menu
|
| <Be Sure To Modify Parameter Before Downloading! >
|
=============================================================
Enter your choice(0-3):
Step 10 After entering 3 in the Ethernet submenu, you can change the parameters of the Ethernet
interface. The parameters are displayed as follows:
Change boot parameter through net port
Note: Available Boot Device: [qefcc1]
'.' = clear field; '-' = go to previous field; ^D = quit
boot device
: qefcc1
(You do not need to change the
parameter value.)
processor number
: 0
(You do not need to change the
parameter value.)
host name
:
(Host name)
Issue 01 (2010-5-12)
Page 26 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
file name
: USG2100_V1R3C01SPC010.bin
(File to be downloaded on
the server)
inet on ethernet (e) : 192.168.23.143
(IP address of the board)
inet on backplane (b) :
(NONE)
host inet (h)
: 192.168.23.142
(IP address of the server)
gateway inet (g)
:
(NONE)
user (u)
: 123
(User name of the server)
ftp password (pw) (blank = use rsh): 123
(Password corresponding to the
server)
flags (f)
: 0x0
(Download mode: 0x0 FTP)
target name (tn)
: USG2100_V1R3C01SPC010.bin
(Name of the file saved on the
board)
startup script (s)
:
(NONE)
other (o)
:
(NONE)
FTP Mode
Filename
Inet on Ethernet
user (u)
flags (f)
Step 11 If you enter 2 in the Ethernet submenu, the host software package is downloaded to the Flash
memory.
If you enter 2, the screen display is as follows:
Check whether the parameters are correct. If the parameters are correct, enter Y. Then, press
Enter.
Load......Done!
12590404 Bytes Downloaded.
Step 12 Enter 5 in the BootROM main menu. The following information is displayed:
Change Flash Descriptor.
FlashFileName=flash:/usg2100.bin, Modify the File Name if Needed.
<File Name Should meet All Criterions!>
Please Input Correctly, e.g.: Secospace.bin USG2100_V1R3C01SPC010.bin
Enter the Flash boot file name. Press Enter, and the USG system writes the data into the Flash
description area. The following information is displayed:
Issue 01 (2010-5-12)
Page 27 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
The file name you input is USG2100_V1R3C01SPC010.bin,
are you sure? Yes or No(Y/N) Y
After the host software is started, you can further check whether the version is properly
loaded and check the version of the new software that is running on the device.
Step 14 Load the configuration file and Paf-license file and new license file, and activate the license
file. Load them from the server to the Flash through FTP.
<USG2100>ftp 10.2.1.2
Trying 10.2.1.2 ...
Press CTRL+K to abort
Connected to 10.2.1.2.
220 WFTPD 2.0 service (by Texas Imperial Software) ready for new user
User(10.2.1.2:(none)):123
331 Give me your password, please
Password:
230 Logged in successfully
[ftp]get vrpcfg.zip
200 PORT command okay
150 "D:\vrpcfg.zip" file ready to send (891 bytes) in ASCII mode
226 Transfer finished successfully.
FTP: 891 byte(s) received in 4.467 second(s) 199.46byte(s)/sec.
[ftp]get license.txt
200 PORT command okay
150 "D:\license.txt" file ready to send (788 bytes) in ASCII mode
226 Transfer finished successfully.
FTP: 788 byte(s) received in 9.466 second(s) 85.65byte(s)/sec.
[ftp]get license.dat
200 PORT command okay
150 "D:\license.dat" file ready to send (2093 bytes) in ASCII mode
226 Transfer finished successfully.
FTP: 2093 byte(s) received in 4.466 second(s) 468.65byte(s)/sec.
----End
Issue 01 (2010-5-12)
Page 28 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Step 3 Switch on the power and power on the device or restart the device.
Step 4 When the USG2100 is being powered on, you can view the MPU startup process on
HyperTerminal of the PC. When the following output is displayed, press Ctrl+B to enter the
BootROM main menu.
*************************************************************
*
Unified Security Gateway 2100 Bootrom, Ver1.16
*
*************************************************************
Copyright(C) 2008-2010 by Huawei Symantec Technologies Co.,Ltd.
CPU type
: MPC8321E
CPU L1 Cache
: 32KB
CPU Clock Speed
: 333MHz
Memory Size
: 256M
Press Ctrl+B to Enter Boot Menu... 4
Password:
=====================<MAIN-BOOTROM MENU>=====================
| <1> Boot With Default Mode
|
| <2> Boot From Flash
|
| <3> Enter Serial SubMenu
|
| <4> Enter Ethernet SubMenu
|
| <5> Change Flash Boot File
|
| <6> Modify Bootrom Password
|
| <7> Restore Factory Setting
|
| <8> Restore Default Config
|
| <0> Reboot
|
=============================================================
Enter your choice(0-8):
Press Ctrl+B within four seconds and enter the password when Password: is displayed to access the
BootROM main menu. The default password for accessing the BootROM main menu is Secospace.
Step 5 In the BootROM main menu, enter Ctrl+Z to enter the Hidden submenu, then delete the last
host software (for example: USG2100_V1R1C01SPC001.bin) and back to BootROM main
menu.
Issue 01 (2010-5-12)
Page 29 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Hidden Menu...
======================<HIDDEN SUB-MENU>======================
| <1> Delete file from Flash
|
| <2> Init Flash File System Space.
|
| <3> Display Flash Files
|
| <4> Enter Flash-Aging Test
|
| <5> Flash Test
|
| <6> E2PRom Test
|
| <7> CPLD Test
|
| <8> DDR memory Test
|
| <9> System Clock Test
|
| <a> System Led Test
|
| <b> Show System-Aging Result
|
| <c> VRPSoftware Backup
|
| <d> Recover console0 password
|
| <e> Big Bootrom Backup
|
| <f> Small Bootrom Upgrade
|
| <g> VRPSoftware Backup Test
|
| <0> Exit To Main Menu
|
=============================================================
Enter your choice(0-g): 1
BE CAREFUL!
This may cause your system fail to start!
Please input the file name you want to delete,
(e.g. Secospace.bin)-->USG2100_V1R1C01SPC001.bin
This Would Take Long Time,Wait Please...
Delete it? Yes or No(Y/N)y
Deleting File...Done.
======================<HIDDEN SUB-MENU>======================
| <1> Delete file from Flash
|
| <2> Init Flash File System Space.
|
| <3> Display Flash Files
|
| <4> Enter Flash-Aging Test
|
| <5> Flash Test
|
| <6> E2PRom Test
|
| <7> CPLD Test
|
| <8> DDR memory Test
|
| <9> System Clock Test
|
| <a> System Led Test
|
| <b> Show System-Aging Result
|
| <c> VRPSoftware Backup
|
| <d> Recover console0 password
|
| <e> Big Bootrom Backup
|
| <f> Small Bootrom Upgrade
|
| <g> VRPSoftware Backup Test
|
| <0> Exit To Main Menu
|
=============================================================
Enter your choice(0-g): 0
=====================<MAIN-BOOTROM MENU>=====================
Issue 01 (2010-5-12)
Page 30 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
| <1> Boot With Default Mode
|
| <2> Boot From Flash
|
| <3> Enter Serial SubMenu
|
| <4> Enter Ethernet SubMenu
|
| <5> Change Flash Boot File
|
| <6> Modify Bootrom Password
|
| <7> Restore Factory Setting
|
| <8> Restore Default Config
|
| <0> Reboot
|
=============================================================
Enter your choice(0-8):
Step 6 In the BootROM main menu, enter 4 to enter the Ethernet submenu.
Enter your choice(0-8):4
Boot From Net Port.
=====================<NETWORK SUB-MENU>======================
| <1> Download Program To SDRAM And Run
|
| <2> Download Program To Flash
|
| <3> Change Boot Parameter...
|
| <0> Exit To Main Menu
|
| <Be Sure To Modify Parameter Before Downloading! >
|
=============================================================
Enter your choice(0-3):
Step 7 After entering 3 in the Ethernet submenu, you can change the parameters of the Ethernet
interface. The parameters are displayed as follows:
Change boot parameter through net port
Note: Available Boot Device: [qefcc1]
'.' = clear field; '-' = go to previous field; ^D = quit
boot device
: qefcc1
(You do not need to change the
parameter value.)
processor number
: 0
(You do not need to change the
parameter value.)
host name
:
(Host name)
file name
: USG2100_V1R3C01SPC010.bin
(File to be downloaded on
the server)
inet on ethernet (e) : 192.168.23.143
(IP address of the board)
inet on backplane (b) :
(NONE)
host inet (h)
: 192.168.23.142
(IP address of the server)
gateway inet (g)
:
(NONE)
user (u)
: 123
(User name of the server)
ftp password (pw) (blank = use rsh): 123
(Password corresponding to the
server)
flags (f)
: 0x0
(Download mode: 0x0 FTP)
target name (tn)
: USG2100_V1R3C01SPC010.bin
(Name of the file saved on the
board)
startup script (s)
:
(NONE)
other (o)
:
(NONE)
Issue 01 (2010-5-12)
Item
FTP Mode
Filename
Page 31 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Item
FTP Mode
Inet on Ethernet
user (u)
flags (f)
Step 8 If you enter 2 in the Ethernet submenu, the host software package is downloaded to the Flash
memory.
If you enter 2, the screen display is as follows:
Check whether the parameters are correct. If the parameters are correct, enter Y. Then, press
Enter.
Load......Done!
12590404 Bytes Downloaded.
Step 9 Enter 5 in the BootROM main menu. The following information is displayed:
Change Flash Descriptor.
FlashFileName=flash:/usg2100.bin, Modify the File Name if Needed.
<File Name Should meet All Criterions!>
Please Input Correctly, e.g.: Secospace.bin USG2100_V1R3C01SPC010.bin
Enter the Flash boot file name. Press Enter, and the USG system writes the data into the Flash
description area. The following information is displayed:
The file name you input is USG2100_V1R3C01SPC010.bin,
are you sure? Yes or No(Y/N) Y
After the host software is started, you can further check whether the version is properly
loaded and check the version of the new software that is running on the device.
Step 11 Log in to the FTP server through the FTP client. In user mode, you can log in to the FTP
server by entering ftp <IP address of the FTP server>.
Issue 01 (2010-5-12)
Page 32 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
<USG2100>ftp 10.2.1.2
Trying 10.2.1.2 ...
Press CTRL+K to abort
Connected to 10.2.1.2.
220 WFTPD 2.0 service (by Texas Imperial Software) ready for new user
User(10.2.1.2:(none)):123
331 Give me your password, please
Password:
230 Logged in successfully
Step 12 Obtain the Paf-license file( license.txt )You can obtain this file by entering get license.txt on
the FTP client.
[ftp]get license.txt
200 PORT command okay
150 "D:\ license.txt" file ready to send (808 bytes) in ASCII mode
226 Transfer finished successfully.
----End
Step 3 Log in to the FTP server through the FTP client. In user mode, you can log in to the FTP
server by entering ftp <IP address of the FTP server>.
<USG2100>ftp 10.2.1.2
Trying 10.2.1.2 ...
Press CTRL+K to abort
Connected to 10.2.1.2.
220 WFTPD 2.0 service (by Texas Imperial Software) ready for new user
Issue 01 (2010-5-12)
Page 33 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
User(10.2.1.2:(none)):123
331 Give me your password, please
Password:
230 Logged in successfully
Step 4 Obtain the USG2100_V1R3C01SPC010.bin file and Paf-license (license.txt)files. You can
obtain this file by entering get USG2100_V1R3C01SPC010.bin on the FTP client.
[ftp]get USG2100_V1R3C01SPC010.bin
200 PORT command okay
150 "D:\ USG2100_V1R3C01SPC010.bin" file ready to send (12590404 bytes) in ASCII
mode
226 Transfer finished successfully.
ftp: 12590404 bytes are transmitted, taking 217.71 seconds. Rate: 57.71 k bytes/s.
[ftp]
[ftp]get license.txt
200 PORT command okay
150 "D:\ license.txt" file ready to send (808 bytes) in ASCII mode
226 Transfer finished successfully.
Step 5 In the user view, use the dir command on the USG2100 to view the name and size of the file
on the USG2100. If transferring is successful, the size of the file on the USG2100 should be
the same as the size of the file on the FTP server host.
<USG2100>dir
Directory of flash:/
0
1
2
3
4
usg2100_V1R3C01SPC010.bin
boottimes
vrpcfg.zip
on1015243.dat
license.txt
Issue 01 (2010-5-12)
Page 34 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Upgrade Verification
Item
Check Points
Task Description
If the version information in the command output is the same as the information in IStep
1Figure 1.1, it indicates that the software version is correct.
Configuration Notes
Before running the command, make sure that the host software package of the USG2100 is
loaded successfully. Otherwise, the software versions may not match.
Operation Procedure
Step 1 Obtain the correct host software package and load it to the USG2100.
Step 2 Start the USG2100 after loading the host software package.
Step 3 Enter the display version command in the command line, and check the information that is
displayed.
Issue 01 (2010-5-12)
Page 35 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
----End
Result Verification
If the version information in the command line output is the same as the information in IStep
1Figure 1.1, it indicates that the software version is correct.
Issue 01 (2010-5-12)
Page 36 of 47
Version Rollback
In the case of any problem after the upgrade or if you need to return to the earlier version, see
Upgrade Operations. The version rollback procedure is the same as the upgrade procedure.
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Issue 01 (2010-5-12)
Page 38 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Step 2 Log in to the FTP server through the FTP client. In user mode, log in to the FTP server by
entering ftp <IP address of the FTP server>.
<USG2100>ftp 10.2.1.2
Trying 10.2.1.2 ...
Press CTRL+K to abort
Connected to 10.2.1.2.
220 WFTPD 2.0 service (by Texas Imperial Software) ready for new user
User(10.2.1.2:(none)):123
331 Give me your password, please
Password:
230 Logged in successfully
Step 3 Upload the current configuration file and license file to the FTP server for backup.
Step 4 Obtain the USG2100_V1R1C01B01f.bin file of the version to be rolled back to. Enter get
USG2100_V1R1C01B01f.bin on the FTP client.
[ftp]get USG2100_V1R1C01B01f.bin
200 PORT command okay
150 "D:\ USG2100_V1R1C01B01f.bin" file ready to send (5763764 bytes) in ASCII mode
226 Transfer finished successfully.
ftp: 5763764 bytes are transmitted, taking 98.69 seconds. Rate: 57.71 k bytes/s.
[ftp]
Step 5 Enter the dir command on the USG2100 to view the name and size of the file on the
USG2100.If the transmission succeeds, the size of the file on the USG2100 should be the
same as that of the file on the FTP server host.
<USG2100>dir
Directory of flash:/
0
1
2
3
4
5
6
-rw-rw-rw-rw-rw-rw-rw-
5763764
4
24
905
4159
7690
5509
usg2100_v1r1c01B01f.bin
boottimes
private-data.txt
vrpcfg.zip
on1015243.dat
usg2100ospfreset.cfg
usg2100ospftest.cfg
Step 6 In the user view, enter the startup system-software usg2100_v1r1c01b01f.bin command to
set the host software for the next startup.
Issue 01 (2010-5-12)
Page 39 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
<USG2100>startup system-software USG2100_V1R1C01B01f.bin
You will change the startup software! Continue?[Y/N]:y
%Checking image file flash:/ USG2100_V1R1C01B01f.bin
The image file flash:/USG2100_V1R1C01B01f.bin is correct!
Startup from the system-software flash:/USG2100_V1R1C01B01f.bin?[Y/N]:y
<EGW2100>
Step 8 When starting the device, view the startup process of the Main Processing Unit (MPU) on the
serial port tool. When the following information is displayed, press Ctrl+B to enter the
BootROM main menu.
*************************************************************
*
Unified Security Gateway 2100 Bootrom, Ver1.13
*
*************************************************************
Copyright(C) 2008-2010 by HUAWEI SYMANTEC TECHNOLOGIES CO.,LTD.
CPU type
: MPC8321E
CPU L1 Cache
: 32KB
CPU Clock Speed
: 333MHz
Memory Size
: 256M
Press Ctrl+B to Enter Boot Menu... 4
Password:
=====================<MAIN-BOOTROM MENU>=====================
| <1> Boot With Default Mode
|
| <2> Boot From Flash
|
| <3> Enter Serial SubMenu
|
| <4> Enter Ethernet SubMenu
|
| <5> Change Flash Boot File
|
| <6> Modify Bootrom Password
|
| <7> Restore Factory Setting
|
| <8> Restore Default Config
|
| <0> Reboot
|
=============================================================
Enter your choice(0-8):
Press Ctrl+B within four seconds and enter the password when Password: is displayed to access the
BootROM main menu. The default password for accessing the BootROM main menu is Secospace.
Step 9 In the BootROM main menu, press Ctrl+Z, enter the hidden menu; format the Flash; and then
return to the main menu.
Hidden Menu...
======================<HIDDEN SUB-MENU>======================
Issue 01 (2010-5-12)
Page 40 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
| <1> Delete file from Flash
|
| <2> Init Flash File System Space.
|
| <3> Display Flash Files
|
| <4> Enter Flash-Aging Test
|
| <5> Flash Test
|
| <6> E2PRom Test
|
| <7> CPLD Test
|
| <8> DDR memory Test
|
| <9> System Clock Test
|
| <a> System Led Test
|
| <b> Show System-Aging Result
|
| <c> VRPSoftware Backup
|
| <d> Recover console0 password
|
| <e> Big Bootrom Backup
|
| <f> Small Bootrom Upgrade
|
| <g> VRPSoftware Backup Test
|
| <0> Exit To Main Menu
|
=============================================================
Enter your choice(0-g): 2
Init Flash File System Space...
Formatting Flash, Please Waiting ...Done.
======================<HIDDEN SUB-MENU>======================
| <1> Delete file from Flash
|
| <2> Init Flash File System Space.
|
| <3> Display Flash Files
|
| <4> Enter Flash-Aging Test
|
| <5> Flash Test
|
| <6> E2PRom Test
|
| <7> CPLD Test
|
| <8> DDR memory Test
|
| <9> System Clock Test
|
| <a> System Led Test
|
| <b> Show System-Aging Result
|
| <c> Recover console0 password
|
| <d> Big Bootrom Backup
|
| <e> Small Bootrom Upgrade
|
| <0> Exit To Main Menu
|
=============================================================
Enter your choice(0-f):0
=====================<MAIN-BOOTROM MENU>=====================
| <1> Boot With Default Mode
|
| <2> Boot From Flash
|
| <3> Enter Serial SubMenu
|
| <4> Enter Ethernet SubMenu
|
| <5> Change Flash Boot File
|
| <6> Modify Bootrom Password
|
| <7> Restore Factory Setting
|
| <8> Restore Default Config
|
| <0> Reboot
|
=============================================================
Issue 01 (2010-5-12)
Page 41 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Enter your choice(0-8):
Step 10 In the BootROM main menu, enter 4 to enter the Ethernet submenu.
Enter your choice(0-8):4
Boot From Net Port.
=====================<NETWORK SUB-MENU>======================
| <1> Download Program To SDRAM And Run
|
| <2> Download Program To Flash
|
| <3> Change Boot Parameter...
|
| <0> Exit To Main Menu
|
| <Be Sure To Modify Parameter Before Downloading! >
|
=============================================================
Enter your choice(0-3):
Step 11 Enter 3 in the Ethernet submenu, change the parameters of the Ethernet interface. The
parameters are displayed as follows:
When flags (f) is set to 0x0, the download mode is FTP, which requires FTP password; when
flags (f) is set to 0x80, the download mode is TFTP.
Change boot parameter through net port
Note: Two protocols for download, tftp & ftp.
You can modify the flags following the menu.
tftp--0x80, ftp--0x0.<Please Make Sure Typing in Lowercase !>
Available Boot Device: [qefcc1]
'.' = clear field; '-' = go to previous field; ^D = quit
boot device
: qefcc1
(You do not need to change the
parameter value.)
processor number
: 0
(You do not need to change the
parameter value.)
host name
:
(Host name)
file name
: USG2100_V1R1C01B01f.bin (File to be downloaded on the
server)
inet on ethernet (e) : 192.168.23.143
(IP address of the board)
inet on backplane (b) :
(NONE)
host inet (h)
: 192.168.23.142
(IP address of the server)
gateway inet (g)
:
(NONE)
user (u)
: 123
(User name of the server)
ftp password (pw) (blank = use rsh): 123
(Password corresponding to the
server)
flags (f)
: 0x0
(Download mode: 0x0 FTP; 0x80 TFTP)
target name (tn)
: USG2100_V1R1C01B01f.bin (Name of the file saved on the
board)
startup script (s)
:
(NONE)
other (o)
:
(NONE)
Issue 01 (2010-5-12)
Item
FTP Mode
TFTP Mode
Filename
Inet on Ethernet
Page 42 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Item
FTP Mode
TFTP Mode
user (u)
None
None
flags (f)
Step 12 Enter 2 in the Ethernet submenu, and the host software package is downloaded to the Flash.
If you enter 1 in the Ethernet submenu, host software package is downloaded to the USG2100 and
loaded directly. After the restart, theUSG2100 resumes the original host software package for the startup.
If you enter 2 in the Ethernet submenu, the host software package is downloaded to the Flash. After the
restart, theUSG2100 uses the latest host software package for the startup.(You are recommended to enter
2.)
Bytes Downloaded.
Step 13 Enter 5 in the BootROM main menu. The following information is displayed:
Change Flash Descriptor.
FlashFileName=flash:/usg2100.bin, Modify the File Name if Needed.
<File Name Should meet All Criterions!>
Please Input Correctly, e.g.: Secospace.bin usg2100_v1r1c01b01f.bin
Enter the name of the startup file that is in the Flash. Press Enter, and the USG system writes
the data into the Flash description area. The following information is displayed:
The file name you input is usg2100_v1r1c01b01f.bin,
are you sure? Yes or No(Y/N) Y
Step 14 In the Ethernet submenu, enter 0 to return to the BootROM main system menu. Enter 2 to run
the new host software package. In this case, use the USG2100_V1R1C01B01f.bin version
for the startup.
This step is for checking whether the loaded host software package starts up properly, and for viewing
the version number after the startup. In addition, you can also switch off the device and then restart it, or
press RESET on the main control panel.
After the host software is started, you can further check whether the version is properly
loaded. In addition, you can check the version of the new software that is running on the
device.
Issue 01 (2010-5-12)
Page 43 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Step 15 Load the configuration file, and license file from the server to the Flash through FTP.
<USG2100>ftp 10.2.1.2
Trying 10.2.1.2 ...
Press CTRL+K to abort
Connected to 10.2.1.2.
220 WFTPD 2.0 service (by Texas Imperial Software) ready for new user
User(10.2.1.2:(none)):123
331 Give me your password, please
Password:
230 Logged in successfully
[ftp]get vrpcfg.zip
200 PORT command okay
150 "D:\vrpcfg.zip" file ready to send (891 bytes) in ASCII mode
226 Transfer finished successfully.
FTP: 891 byte(s) received in 4.467 second(s) 199.46byte(s)/sec.
[ftp]get license.dat
200 PORT command okay
150 "D:\license.dat" file ready to send (2093 bytes) in ASCII mode
226 Transfer finished successfully.
FTP: 2093 byte(s) received in 4.466 second(s) 468.65byte(s)/sec.
Step 16 Set the file for the next startup and configuration file.
<USG2100>startup system-software usg2100_v1r1c01b01f.bin
You will change the startup software! Continue?[Y/N]:y
Next startup system software:flash:/usg2100_v1r1c01b01f.bin, Read file from
flash....
<USG2100>
<USG2100>startup saved-configuration vrpcfg.zip
Startup from the saved-configuration flash:/vrpcfg.zip?[Y/N]:y
Step 17 Restart the device. The device automatically runs usg2100_v1r1c01b01f.bin and loads the
original configurations. The rollback is completed.
You need to ensure that the Flash has enough free space during the version upgrade. You need to specify
the name of the system file for the next startup before restarting the system.
----End
Issue 01 (2010-5-12)
Page 44 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Step 2 Log in to the FTP server through the FTP client. In user mode, log in to the FTP server by
entering ftp <IP address of the FTP server>.
<USG2100>ftp 10.2.1.2
Trying 10.2.1.2 ...
Press CTRL+K to abort
Connected to 10.2.1.2.
220 WFTPD 2.0 service (by Texas Imperial Software) ready for new user
User(10.2.1.2:(none)):123
Issue 01 (2010-5-12)
Page 45 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
331 Give me your password, please
Password:
230 Logged in successfully
Step 3 Upload the preceding version to the Flash. Enter get USG2100_V1R1C01SPC001.bin on the
FTP client. (Suppose that the preceding used version is USG2100_V1R1C01SPC001.bin.).
[ftp]get USG2100_V1R1C01SPC001.bin
200 PORT command okay
150 "D:\ USG2100_V1R1C01SPC001.bin" file ready to send (5725908 bytes) in ASCII
mode
226 Transfer finished successfully.
ftp: 5725908 bytes are transmitted, taking 96.69 seconds. Rate: 54.71 kbytes/s.
[ftp]
Step 4 Use the dir command on the USG2100 to view the name and size of the file on the USG2100
after the file is successfully transferred. If the transmission succeeds, the size of the file on
the USG2100 should be the same as that of the file on the FTP server host
<USG2100>dir
Directory of flash:/
0
1
2
3
4
5
6
Step 6 Restart the device. The device automatically runs usg2100_v1r1c01spc001.bin and loads the
original configurations. The rollback is completed.
You need to ensure that the Flash has enough free space during the version upgrade. You need to specify
the name of the system file for the next startup before restarting the system.
----End
Issue 01 (2010-5-12)
Page 46 of 47
USG2100 V100R003C01SPC010
Version Upgrade Instructions
Figure 1.1
Upgrade Record
Site office
Upgrade date
Version before
upgrade
Version after
upgrade
Upgrade
engineer
Upgrade
succeeded or
not
Check Item
Conclusion
Anomaly
Handling
Checklist before
upgrade
Checklist of upgrade
operations
Checklist after
upgrade
Issue 01 (2010-5-12)
Page 47 of 47