Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

New FO PIX upgrade

I have a single UR PIX 515e running 6.3.3 in production. I'm adding a FO PIX 515e but it's running 6.3.1. I tried to add an IP address to the new FO PIX, it accepted the configuration and the inside interface got a link with my laptop. But TFTP and ICMP traffic would not pass to the PIX. How do I upgrade the FO PIX to 6.3.3 without the UR PIX.

1 ACCEPTED SOLUTION

Accepted Solutions
New Member

Re: New FO PIX upgrade

Try to do a 'failover active' on the pix without having it connected to the production network.

Hope this helps.

8 REPLIES
Silver

Re: New FO PIX upgrade

You don't need to have the FO pix plugged into the UR just to upgrade the software. Without the failover cable attached, the FO will "randomly" reboot itself to prevent it being used alone. (message can be seen at boot time on the console) This won't affect you're upgrade process.

Simply plug a crossover cable on the inside interface to your laptop, assign an IP, and ping your laptop to test. By default, the Pix accepts ping request/replies. Once you can ping successfully, use tftp to pull the image on.

Make sure the interface is enabled..

interface ethernet1 100auto

New Member

Re: New FO PIX upgrade

The FO PIX's inside interface was enabled and up/up. I couldn't ping from the FO PIX or the Laptop. Remember the FO PIX was never connected to a UR PIX to get a configuration. Can the FO PIX configuration work (meaning pass traffic) without ever being connected to a UR PIX?

Silver

Re: New FO PIX upgrade

Yes. The FO can operate solo but will reboot itself at random intervals to avoid licensing abuse. Otherwise, you wouldn't be able to replace the UR when it fails.

Just for fun, try connecting the secondary end of the cable to the FO without it being connected on the UR. The Pix can tell when the cable is connected even if nothing is on the other end. This simulates the scenario where the UR dies and is removed for replacement.

New Member

Re: New FO PIX upgrade

Try to do a 'failover active' on the pix without having it connected to the production network.

Hope this helps.

New Member

Re: New FO PIX upgrade

Hi,

I am faced the same problem yesterday. I managed to resolve it.

Reload PIX,press ESC or BREAK to ROM mode, using ROM mode to upgrade the PIX OS on FO PIX.

Regards.

New Member

Re: New FO PIX upgrade

Thanks! do you have a link for instructions on doing the upgrade through ROM mode?

Silver

Re: New FO PIX upgrade

Enter rommon using a sequence like any other IOS device. The commands are available using "?" at the prompt. Here is a link that explains it.

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a0080089cf6.html#xtocid4

New Member

Re: New FO PIX upgrade

Thanks! I didn't have to do that. The problem was the FO PIX needed to be made active. One of the messages above was correct "failover active" and the FO PIX started passing traffic.

THANKS! to all

127
Views
0
Helpful
8
Replies
CreatePlease to create content