background image

Supported Upgrade Paths

You can upgrade directly from any of the following versions:

5.0r2

5.0r1

4.1r4

Beginning with IDP OS Release 5.0, IDP Series does not support bridge, proxy-arp, or
router mode. Before upgrading to IDP OS 5.1, you must redeploy the IDP Series device in
transparent or sniffer mode.

NOTE:

The upgrade paths assume your current IDP Series device has been

in use and the device had been added to NSM. You might encounter
unexpected behavior during the upgrade if you are upgrading from a newly
reimaged, undeployed IDP OS 4.2 or 4.1 device (such as a 2009 factory image
of the IDP OS). In these cases, we recommend you add the IDP device to NSM
and import the device configuration into NSM prior to performing the upgrade.
Doing so will avoid the file permissions issue described in KB 15071.

Table 2 on page 5 describes the changes to files and directories you will notice when
you upgrade.

Table 2: Changes to Files and Directories

Files and Directories

Upgrade Path

No changes to attend to before upgrade.

From 5.0r2

Before you upgrade, take note of the following changes and recommended actions:

IDP 5.1r1 stores packet logs in numbered subdirectories of

/usr/idp/device/var/pktlogs/

. To implement

this change, your existing

/usr/idp/device/var/pktlogs/

directory will be overwritten. If you have

been using the option to maintain packet data locally and send to NSM on demand, copy any packet
logs you want saved from

/usr/idp/device/var/pktlogs/

to a remote location before you upgrade.

Previously collected packet capture logs will not be available to NSM. This action is not required if
you have been using the option to always include packet data when NSM sends the event log.

Your custom settings in the

/usr/idp/device/bin/user_funcs

file are preserved when you upgrade.

No action is required.

From 5.0r1

5

Copyright © 2011, Juniper Networks, Inc.

Supported Upgrade Paths

Содержание IDP OS 5.1R1

Страница 1: ...4 Supported Upgrade Paths 5 Downgrading or Reverting 6 Licensing 6 Compatibility with Network and Security Manager 6 Compatibility with Juniper Networks Infranet Controller 7 Browser Requirements 7 Up...

Страница 2: ...r from the primary path to the backup path in cases of failure For details see IDP Series Deployment Scenarios High availability Beginning in IDP OS Release 5 1 you can operate the IDP Series device i...

Страница 3: ...ication Beginning with IDP OS Release 5 1 You can create rules that match extended application objects also called nested application objects You can apply a new action to matching rules DiffServ Rate...

Страница 4: ...0 10 gigabyte fiber interfaces do not support interface signaling or peer port modulation Also not supported in IDP OS Release 5 0 x Authentication to the ACM via RADIUS with RSA SecurID authenticatio...

Страница 5: ...hanges to files and directories you will notice when you upgrade Table 2 Changes to Files and Directories Files and Directories Upgrade Path No changes to attend to before upgrade From 5 0r2 Before yo...

Страница 6: ...s no longer supported in IDP 5 1 The upgrade process saves a backup of your previous usr idp device bin user_funcs file but installs a new user_funcs file in order to provide appropriate content for I...

Страница 7: ...Start utility and IDP Reporter have been tested on the following browsers Internet Explorer 7 x 6 x Firefox 3 x 2 x Upgrading IDP Software During upgrade the IDP Series appliance is gracefully shut do...

Страница 8: ...password b Enter the IDP Series device serial number to display a view of applicable software releases available for download c Click the applicable link to display the software download page d Downlo...

Страница 9: ...the BIOS setting Console redirection Continue Console redirection after POST to ON To resolve this issue press the Delete key to enter BIOS and set this option to OFF Next Steps If you are upgrading...

Страница 10: ...vailable for download c Click the applicable link to display the software download page d Save the sensor_version sh file where version is the number that identifies the software release version 2 Con...

Страница 11: ...r2 skip this step You completed it when you upgraded to IDP 5 0 If you are upgrading from IDP OS Release 4 1r4 1 a Run through the ACM wizard to reconfigure your virtual routers In IDP 5 0 and later y...

Страница 12: ...O modules 308133 Unexpected Behavior Resolved an issue where the SYN Protector rulebase had failed to reset the destination server connections when configured in Passive mode 417818 Resolved an issue...

Страница 13: ...s reached In this release we have changed the delay threshold from 1024 to 100 instances 388321 Syslog NIC state events reported in syslog messages had not indicated that the virtual router has return...

Страница 14: ...ith APE rules would eventually result in policy push errors 494931 Resolved an issue where running sciocpu utilization command in single core platforms caused a drop in throughput and increase in late...

Страница 15: ...uters page should not display the user interface group for NIC State When no installed I O module supports bypass NIC state is non configurable 286327 ACM does not reject poorly formed alias names In...

Страница 16: ...uplex settings match We have observed traffic dropping if the IDP Series interfaces are configured as 100 10 1000 half full duplex AUTO OFF and the peer switch or firewall is configured as AUTO ON 431...

Страница 17: ...ata1 00 cmd 61 30 08 8d 6e 16 00 00 00 00 00 40 tag 1 cdb 0x0 data 24576 out res 50 00 38 a5 70 16 00 00 00 00 00 40 Emask 0x2 HSM violation You can safely ignore these messages 288824 During upgrade...

Страница 18: ...ted in syslog messages do not indicate which IDP engine restarted 427100 Database limit exceeded alert log are not displayed in Profiler logs 429086 We have observed a minor loss of application volume...

Страница 19: ...3 rxBytes 14757418499789 rxOverflow 0 rxQueued 0 txComplete 18487802326 txCompleteBytes 14691015670286 allocQueueSize 1023 txPackets 18487802326 txBytes 14692307273740 Device Id 0 eth2 Stats Link Stat...

Страница 20: ...hutdown Operation The shutdown h now command might not behave as expected if you deploy IDP8200 with any of the following fiber I O modules IDP 1GE 4SX BYP IDP 10GE 2XFP or IDP 10GE 2SR BYP Instead of...

Страница 21: ...scribes how to use IDP Reporter an on box reporting platform that includes predefined reports on attack detection and application usage You can also use IDP Reporter to schedule regular publication of...

Страница 22: ...act Juniper Networks Technical Assistance Center JTAC by E mail support juniper net or telephone 1 888 314 JTAC within the United States or 1 408 745 9500 from outside the United States Copyright 2009...

Отзывы: