cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1243
Views
0
Helpful
2
Replies

Cannot pscp IOS to 7204VXR

francisfox
Level 1
Level 1

I am having a couple of problems loading IOS onto a 7204

1. I am trying to upgrade the IOS on a 7204 VXR with a NPE-G2 engine from advipservices 12.4(15)T to 12.4(24)T2. We are performing the upgrade from a remote server using pscp.exe, we have tried using Cisco Works with very mixed results and abandoned this method.  Whereas the pscp method has worked for our other devices - 3750, 2960, 3825, SUP720; the 7204 has not.  Every time I load a new 12.4(24)T2 IOS it verifies with a different MD5 hash. The source IOS on the server verifies with the correct hash.  I have also seen the following message reported on the 7204

Error register 0

Status register 51E0

Has anyone seen this before? Unusually it throws no hits in google

2. I have a flash card with a verified 12.4(24)T2 IOS on it. When I boot the 7204 with this IOS and then attempt to reload the old IOS using pscp (a rollback procedure that we must test), the pscp fails reporting "write failed" anytime up to 90% completed.  You can see the file being written to the 7204 (disk2:) then the copy just fails.

Note: Don't know if this is relevant but we use SecureCRT to ssh to our devices.  All other Cisco devices can be ssh'd to with SecureCRT settings out of the box.  With the 7204 we have to promote the standard "Diffie-Hellman" key exchange to the top of the list, above "Diffie-Hellman-group" and "Diffie-Hellman-group 14".  When running pscp verbose it reports the following

pscp -C -2 -v -scp c7200p-advipservicesk9-mz.124-24.T2.bin NetAdmin@192.168.0.1:disk2:/c7200p-advipservicesk9-mz.124-24.T2.bin
Looking up host "192.168.0.1"
Connecting to 192.168.0.1 port 22
Server version: SSH-2.0-Cisco-1.25
We believe remote version has SSH-1 ignore bug
We believe remote version needs a plain SSH-1 password
We believe remote version can't handle SSH-1 RSA authentication
We claim version: SSH-2.0-PuTTY_Release_0.60
Using SSH protocol version 2
Using Diffie-Hellman with standard group "group1"
Doing Diffie-Hellman key exchange with hash SHA-1
Host key fingerprint is:
ssh-rsa 1024 51:fe:53:00:34:1d:fe:77:aa:ec:33:e4:65:97:39:60
Initialised AES-256 CBC client->server encryption
Initialised HMAC-SHA1 client->server MAC algorithm
Initialised AES-256 CBC server->client encryption
Initialised HMAC-SHA1 server->client MAC algorithm
Using username "NetAdmin".
Using keyboard-interactive authentication.
Password:
Access granted
Opened channel for session
Started a shell/command
Using SCP1
Connected to 10.107.60.253

Sending file c7200p-advipservicesk9-mz.124-24.T2.bin, size=37934960
c7200p-advipservicesk9-mz | 37045 kB | 298.8 kB/s | ETA: 00:00:00 | 100%
Sent EOF message
Server sent command exit status 0
Disconnected: All channels closed

2 Replies 2

yjdabear
VIP Alumni
VIP Alumni

The two issues seem related. Can you post "sh ip ssh" from the 7200?

sh ip ssh


SSH Enabled - Version 2.0

Authentication timeout: 60 secs; Authentication retries: 3

BTW: tried to use Cisco Works again and it appears out version does not recognise the NPE-G2 variant of the IOS on our router, the one with the name starting c7200p..., it does recognise vanilla IOS starting c7200...

We are running with LMS 2.6, RME 4.0.5, DFM 2.0.6