Readme File IBM Flex System FC3171 8Gb SAN Switch IBM Flex System FC3171 8Gb SAN Pass-thru Firmware Version: 9.1.0.26.00 Document Title: qlgc_fw_flex_9.1.0.26.00_anyos_noarch.txt ________ CONTENTS ________ 1.0 Overview 2.0 Change History 3.0 Installation and Setup Instructions 4.0 Configuration Information 5.0 Known Issues 6.0 Unattended Mode 7.0 Web Support Site 8.0 Trademarks and Notices 9.0 Disclaimer _______________ 1.0 Overview _______________ This README describes the firmware for the IBM Flex System FC3171 8Gb SAN Switch and IBM Flex System FC3171 8Gb SAN Pass-thru and procedure for updating firmware on the switch. Inbound insecure protocols are disabled by default (ftp, telnet, http, snmpv1/2, etc) Use secure protocols (sftp, ssh, https, snmpv3, etc) Use https:// to access the GUI. HTTP is disabled To access the CLI use ssh to the switch IP. **When using HTTPs, if an error is shown regarding an "Invalid Certificate", first ensure the date and time is set correctly on the switch, CMM, FSM, and Management station you are accessing the switch from. If the error message is still seen, SSH to the switch and run "create certificate" once the switch time is set correctly. To check the date on the switch, login to the CLI and run "date". **If there are problems with the FSM gaining SMI-S access to the switch, ensure that the switch has Inband Mgmt Enabled. Note, inband mgmt is only applicable on full-fabric switches. The Inband Mgmt setting can be verified by running: set debug on show config switch The following entry should be true InbandEnabled True If the entry is not true run the following commands admin start config edit set config switch Press enter till the cursor is at InbandEnabled type in True Press enter through rest of entries config save config act Reboot the switch Default login: USERID/PASSW0RD <- Note zero after the W and before the R admin/password images/images (for uploading fw to the switch, only works for ftp or sftp) Default SNMPv3 login: User: snmpadmin1 AuthProto: SHA AuthPhrase: admin1pass PrivProto: DES PrivPhrase: PASSW0RD <- Note number zero after W and before R ____________________ 2.0 Change History ____________________ See Change history file for updates _________________________________________ 3.0 Installation and Setup Instructions _________________________________________ ********Important********* The 9.1.0.26.00 version of firmware contains an update to the CPLD device on the switch. The CPLD update cannot be disrupted so the update is done manually to ensure complete control over the process. To complete the update, a virtual reseat of the switch is required. The virtual reseat is a disruptive process. Please follow these steps to update the CPLD: 1). Update switch to 9.1.0.26.00 and reboot 2). Login to switch CLI and run these commands: a). admin start b). set advanced on c). cpld install 3). When CPLD install completes successfully, login to the CMM CLI and run these commands: a). env -T system:switch[x] where x is switch slot b). service -vr (the switch will now reboot). 4). To verify the CPLD version after the virtual reseat run the following commands from the switch CLI a). show setup mfg Look for the line CPLD Revision, it should end in 0x22 NOTE: Prior to downloading the firmware to the switch module, ensure that the advanced management option "Preserve IP Address across all resets" is set to 'enabled' via the Management Module interface. This will ensure that your currently configured IP Address will remain available after the switch firmware is upgraded. NOTE: Capitalization of command, password, and username is important - must use as shown in procedures below. Methods to Update - CMM (GUI/CLI) Ensure you are using the correct syntax for the URL that is provided to the switch. Refer to the CMM documentation/help text. After transfering the image to the switch make sure to activate the appropriate image. The FC3171 only has one image to activate so img 1 is the image to activate. - Switch GUI - Switch CLI Instructions: command "image install" grabs file from external server unpacks and installs command "image fetch" then run "image unpack " will grab from external server 1. Download new firmware file ("qlgc_fw_flex_9.1.0.26.00_anyos_noarch.bin") - Ensure that the filename that has been saved to the disk is qlgc_fw_flex_9.1.0.26.00_anyos_noarch.bin and does not contain additional characters. 2. Open command prompt window/console from a SFTP capable box. 3. Change directory in window/console to the directory where the new switch firmware file is located. 4. SFTP the file to the switch, refer to your SFTP client help for syntax. The login credentials are images/images 5. SSH to the switch using command: "ssh xxx.xxx.xxx.xxx" where xxx.xxx.xxx.xxx represents IP address of FC switch. 6. To log in to FC switch: o At prompt "username", type "USERID" and press the enter key. o At the prompt "password", type "PASSW0RD" and press enter key NOTE: Zero is 6th character in password, not capital O. 7. After logged in, enter the following commands: o At prompt, type "admin start" and press the enter key. o At the prompt, type "image list" and press enter key NOTE: "image list" command should display firmware file that was uploaded in step 4 resident on switch. 8. Now enter following commands: o At prompt, type "image unpack " where is the name of file that was uploaded in step 4 and press enter key. 9. Wait for confirmation that the switch firmware has successfully updated 10. After receiving confirmation, type "reset", this will perform a disruptive code load and reset the switch. _______________________________ 4.0 Configuration Information for SAN Switch Module (full fabric mode) _______________________________ Detailed information on configuring the Switch Module can be found in the IBM Flex System FC3171 8Gb SAN Switch Users Guide NOTES: - If you have fabrics that cross time zones, please be aware that this will cause time stamp differences in the various switch logs. - When shutting down or booting up a server, additional port statistics (decode errors, link resets, etc) can be seen. Ensure that the internal blades are properly shutdown to avoid excessive port statistics. - A switch configuration backup does not archive the primary or secondary secrets for any security groups. As a result, the security secrets need to be reconfigured in Clish after a config restore. Otherwise the restored switch will isolate from the fabric due to an invalid attach due to the missing secrets. _______________________________ 5.0 Known Issues for SAN Switch Module _______________________________ Known Issues with Brocade/QLogic interoperation: ------------------------------------------------------- - Connecting a IBM Flex System FC3171 8Gb SAN Switch to a Cisco/Brocade switch is unsupported. To work around this either enable transparent mode on the IBM Flex System FC3171 8Gb SAN Switch or use the IBM Flex System FC3171 8Gb SAN Pass-thru which will only run in transparent mode. - When using HTTPs, if an error is shown regarding an "Invalid Certificate", first ensure the date and time is set correctly on the switch, CMM, and Management station you are accessing the switch from. If the error message is still seen, run "create certificate" from the CLI once the switch time is set correctly. _____________________ 6.0 Unattended Mode _____________________ This package does not support Unattended Mode ________________________________________ 7.0 Web Support Site ________________________________________ IBM Support Web Site: http://www.ibm.com/support/ ____________________________ 8.0 Trademarks and Notices ____________________________ The following terms are trademarks of the IBM Corporation in the United States or other countries or both: IBM IBM Flex System Other company, product, and service names may be trademarks or service marks of others. ________________ 9.0 Disclaimer ________________ THIS DOCUMENT IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. IBM DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF FITNESS FOR A PARTICULAR PURPOSE AND MERCHANTABILITY WITH RESPECT TO THE INFORMATION IN THIS DOCUMENT. BY FURNISHING THIS DOCUMENT, IBM GRANTS NO LICENSES TO ANY PATENTS OR COPYRIGHTS. Note to Government Users Note to U.S. Government Users -- Documentation related to restricted rights -- Use, duplication or disclosure is subject to restrictions set forth in GSA ADP Schedule Contract with IBM Corporation.