ArubaOS-CX Firmware Upgrade: Standalone, VSF and VSX - 夜莺博客

ArubaOS-CX Firmware Upgrade: Standalone, VSF and VSX

ArubaOS-CX keeps two software image banks, so a firmware upgrade does not have to be a leap of faith: you stage the candidate image into the inactive bank, verify its checksum, and only then reboot into it. What turns this simple model into an outage is the topology — a VSF stack or a VSX pair has its own coordinated upgrade procedure, and skipping it produces split stacks and dual-primary states. This article covers the validation steps, the standalone procedure and the coordinated path for VSF and VSX.

Step 1 — Validate Platform, Image and Upgrade Path

switch# show version
switch# show images
switch# show boot-history
switch# show system
switch# show vsf          # on a VSF stack
switch# show vsx brief    # on a VSX pair

Record four things before downloading anything: the exact switch family and product number, the currently running image, which bank is active, and whether the device is part of a VSF/VSX/standalone topology. Then read the target release's release notes for minimum source versions, intermediate upgrade requirements (large-version jumps often need a hop), LSR/SSR feature changes and downgrade limitations. Aruba's "major branch" is the second integer in the version string, and crossing it usually requires more care than a patch-level move.

Step 2 — Stage the Image in the Inactive Bank

The examples below assume primary is the known-good running image and secondary is the inactive destination. Substitute the correct bank and VRF from your baseline.

# Inspect what is where first
switch# show images
---------------------------------------------------------------------------
ArubaOS-CX Primary Image
---------------------------------------------------------------------------
Version : FL.10.06.0010
Size    : 643 MB
Date    : 2020-12-14 10:06:34 PST
SHA-256 : 78dc27c5e521e92560a182ca44dc04b60d222b9609129c93c1e329940e1e11f9

# Copy from a secured file server (preferred over TFTP)
switch# copy sftp://netadmin@fileserver/images/ArubaOS-CX_6400-6300_10_13_0002.stable.swi secondary vrf mgmt

# TFTP only where policy permits and the file is not sensitive
switch# copy tftp://10.10.10.50/ArubaOS-CX_6400-6300_10_13_0002.stable.swi secondary vrf mgmt

# Monitor progress
switch# show image status
Image Upgrade State:     download
File Transfer State:     download
State Detail:            In progress
Transfer Progress:       7 %
File Size:               604119040 bytes
Transfer Rate:           869 kbps

switch# show images       # confirm the expected version is in the inactive bank

Wait for the copy to report successful verification and writing. A transfer that was interrupted leaves an image in the bank that boot will refuse — check show image status for a completed state rather than assuming the prompt returning means the file is usable.

Step 3 — Boot the Candidate Image

switch# boot system secondary
# this selects secondary for this reboot and makes it the default for future boots
# save the approved configuration when prompted, confirm the reboot,
# and watch the console until the system is stable

switch# show version
ArubaOS-CX
(c) Copyright 2017-2024 Hewlett Packard Enterprise Development LP
Version      : FL.10.13.0002
Build Date   : ...
Active Image : secondary
Service OS Version : FL.01.07.0002
BIOS Version       : FL.01.0002

switch# show images       # both banks, with the running bank marked

Keep the known-good primary image through the observation period. After acceptance, promote the validated image so primaries stay consistent across the estate:

switch# copy secondary primary
switch# boot set-default primary
switch# show images

VFSS and VSX: Coordinated Upgrades

Do not run the standalone procedure member by member on a stack.

# VSF stack: stage the image on the conductor, then reboot members in order
switch# copy sftp://netadmin@fileserver/img.swi secondary vrf mgmt
switch# show vsf                      # confirm member roles and conductor
switch# boot system secondary         # on the conductor; members follow the stack procedure

# VSX pair: use the VSX-aware command so both peers coordinate
switch# vsx update-software boot-bank secondary
This will trigger the upgrade process on the VSX pair and start a dialogue
explaining what will happen next (including whether any firmware/driver
upgrades are needed, which would cause a second reboot).
# in a VSX upgrade the secondary VSX member always boots first

switch# show vsx brief
switch# show vsx status | include "ISL|Keepalive|Device role"

The ordering is not cosmetic. In a VSX upgrade the secondary member reboots first, traffic continues on the primary, and only then does the primary reboot — that sequencing is what preserves forwarding. Rebooting both members manually destroys the whole benefit of having a pair.

Pre- and Post-Upgrade Checks

# Before
switch# show running-config > flash:pre-upgrade-config.txt
switch# copy running-config startup-config
switch# show vsf / show vsx brief
switch# show interface brief | include down

# After
switch# show version
switch# show vsf / show vsx brief
switch# show interface brief
switch# show lag
switch# show ip route summary
switch# show logging -r | head -50      # most recent events first
  • Image download fails. Check VRF: the management VRF is not the default routing table, and vrf mgmt is mandatory when copying over the OOB network.
  • Switch boots the old version. boot set-default was not applied, so the default bank reverted. Verify with show boot.
  • VSX becomes split after upgrade. The keepalive link was on a path that also rebooted, or the ISL came up before peer detection. Confirm ISL and keepalive interfaces are on separate physical paths before you schedule the window.
  • Features behave differently after the jump. Read the release notes for the branch you crossed; defaults for MSTP, VXLAN or CoPP commonly change between major versions.

Related reading: ArubaOS-CX VSF stacking, ArubaOS-CX VSX configuration and Aruba 2930F firmware upgrade.

原文链接:https://cray-hpe.github.io/docs-csm/en-10/operations/network/management_network/update_management_network_firmware