Page MenuHomePhabricator

Upgrade pfw to Junos 20+
Closed, ResolvedPublic

Description

The Junos 20 branch is now in Junos recommended versions for SRX1500 firewalls, see https://kb.juniper.net/InfoCenter/index?page=content&id=KB21476&smlogin=true

Upgrading those firewalls has several advantages:

  • Testing routers redundancy in a planned window
  • Keeping a tight Junos version spread (we currently have 12, 14, 15, 17, 18, 20)
  • Fixing low risk security issues

As we're getting in the "no changes" time of the year, it will probably have to wait for next year. @Jgreen around what time should we ping you for that?

Details

Due Date
May 17 2022, 4:00 AM

Event Timeline

ayounsi created this task.
Restricted Application added a subscriber: Aklapper. · View Herald Transcript

@ayounsi I think it would be fine to do the codfw pfw's this year. Please ping me on IRC when you have some time to discuss.

I chat with @Jgreen in IRC we will be doing the upgrade next week on Tuesday the 1st at 10:30 CT

request system software add <JUNOS package> no-copy unlink

started at 10:38am CT and complete at 10.52am CT ~ 13mins

request system reboot

started at 10:54am CT complete at 11:27am CT ~33mins

Complete

Hostname: pfw3-codfw
Model: srx1500
Junos: 20.4R3-S1.3
Papaul closed this task as Resolved.EditedFeb 1 2022, 5:39 PM
Papaul claimed this task.

Codfw complete

Jgreen set Due Date to May 17 2022, 4:00 AM.Feb 1 2022, 5:53 PM

We're planning to do the upgraded during the Fundraising planned maintenance window of 5/16/2022 to 5/20/2022.

@Jgreen hello do you think this can be done on May the 16th?

Papaul raised the priority of this task from Low to Medium.May 2 2022, 3:11 AM

@Jgreen hello do you think this can be done on May the 16th?

@Papaul, yes that sounds good. We can plan for downtime on that day.

@Cmjohnson @Jclark-ctr I upload the junos-srxsme-20.1R1.11.tgz to apt.wikimedia.org under /srv/junos . if you have time this week can you please copy that image file to a USB and please coordinate with me when that it is done so we can plug the USB to both pfw3a-eqiad and pfw3b-eqiad an copy the image there before Monday 16th.

Thanks

@Cmjohnson @Jclark-ctr the right image is junos-srxentedge-x86-64-20.4R3-S1.3.tgz and not junos-srxsme-20.1R1.11.tgz since codfw is using junos-srxentedge-x86-64-20.4R3-S1.3.tgz

Thanks

@Jgreen hello. I am planning on doing this on the 16th at 10:00am CT . let me know it time works for you.
Thanks

The Junos image is now on both pfw

root@pfw3-eqiad% ls /var/tmp/junos-srxentedge-x86-64-20.4R3-S1.3.tgz
/var/tmp/junos-srxentedge-x86-64-20.4R3-S1.3.tgz
root@pfw3-eqiad%

Junos upgrade complete in Eqiad.