08-15-2014 07:07 AM - edited 03-07-2019 08:24 PM
Hi
I have three switches WS-C2960S-FPS-L with IOS 12.2(55)SE6, which I would like to upgrade to 15.0(2)SE6.
Switch is in reboot cycle after starting with new IOS.
...done Initializing flashfs.
Checking for Bootloader upgrade..
Boot Loader upgrade not required (Stage 2)
%Software-forced reload
Buffered messages:
Queued messages:
Mar 30 01:27:39.897: %SYS-3-LOGGER_FLUSHING: System pausing to ensure console debugging output.
*Mar 1 00:00:18.250: Read env variable - LICENSE_BOOT_LEVEL =
Mar 30 01:27:38.283: %IOS_LICENSE_IMAGE_APPLICATION-6-LICENSE_LEVEL: Module name = c2960s_lanbase Next reboot level = lanbase and License = lanbase
Mar 30 01:27:38.540: %CRYPTO-0-SELF_TEST_FAILURE: Encryption self-test failed (Software self-integrity test)
Mar 30 01:27:38.807: %CRYPTO-0-SELF_TEST_FAILURE: Encryption self-test failed (RBG: unable to initialize rbg)
Mar 30 01:27:38.807: %CRYPTO-0-SELF_TEST_FAILURE: Encryption self-test failed (SP 800-90 DRBG)
: Unexpected exception to CPUvector 2000, PC = 1CA83C8
-Traceback= 0x1CA83C8z 0x1CA83C8z 0x4C72FCz 0x1340B74z 0x1340D34z 0x1340E50z 0x38A1F8z 0x38A66Cz 0x1CA9684z 0x1CA3DD8z
: Unexpected exception to CPUvector 2000, PC = 13802F4
-Traceback= 0x13802F4z 0x1576500z 0x1CA9684z 0x1CA3DD8z
If I upgrade only to 15.0(2)SE, the switches are booting fine. I've tried alos other IOS versions above 15.0(2)SE, always same problem.
I think it has something to do with the current Bootloader:
ROM: Bootstrap program is Alpha board boot loader
BOOTLDR: C2960S Boot Loader (C2960S-HBOOT-M) Version 12.2(53r)SE, RELEASE SOFTWARE (fc3)
The switches where the upgrade is not working, have all the above bootloader.
I have another switch of the same type with bootloader:
BOOTLDR: C2960S Boot Loader (C2960S-HBOOT-M) Version 12.2(55r)SE, RELEASE SOFTWARE (fc1)
Upgrading this one is no problem.
Version 15.0(2)SE1 is first version which are FIPS certified.
Any suggestions?
Regards
Peter
08-15-2014 07:18 AM
Bootloader has NOTHING to do with your issue.
My recommendation is to either use IOS 15.0(2)SE4, 15.2(2)E or 12.2(55)SE9.
08-15-2014 09:45 AM
But why are all the IOS, which are not working with this 3 switches, are just fine with another switch same type with other bootloader?
08-15-2014 03:27 PM
Your bootloader gets upgraded automatically when you upgrade/downgrade your IOS. So bootloader is not the issue.
Why is it working to some appliances but not with other? That's because of the IOS you're using. It is as simple as that. 15.0(1)SE is a very bad IOS train.
08-17-2014 01:10 AM
I also tried c2960s-universalk9-tar.152-1.E3. I know that bootloader will upgrade automatically, but it doeas not upgrade when bootloader is
BOOTLDR: C2960S Boot Loader (C2960S-HBOOT-M) Version 12.2(53r)SE, RELEASE SOFTWARE (fc3)
message on console:
Checking for Bootloader upgrade..
Boot Loader upgrade not required (Stage 2)
%Software-forced reload
....
see file Loop_2960S_15_02.txt attached
If I try a switch with already newer bootloader also same serie 2960S, upgrade is working with all this IOS releases.
Bootloader was
BOOTLDR: C2960S Boot Loader (C2960S-HBOOT-M) Version 12.2(55r)SE, RELEASE SOFTWARE (fc1)
see file Log2960S_15_02_OK.txt attached
This is why I think it has something to do with the bootloader already running on the switch. The first version which does not work with old bootloader is the first version with FIPS.
08-17-2014 05:47 AM
Please don't use 15.2(1)E train IOS. I've already mentioned what IOS you should consider.
08-19-2014 05:13 PM
I tried now different IOS version with different model revision of these switches:
IOS till 15.0(2)SE are working on every switch. 15.0(2)SE1 with FIPS support ist not working on switches with older Model revision.
The switches with booting in loop after upgrade has model revision: D0
The switches with working upgrade has model revision G0 or H0
I tried 15.2(2)EX5, 15.2.(2)E,15.2(1)E3,15.0(2)SE6 this one has all same error with looping after upgrade, if I tried on model revision D0
On model revision G0 or H0 they are booting fine.
08-21-2014 10:32 AM
Hello Peter,
have you try to contact the Cisco TAC for an official check/verification about the problem ?
As the these switches WS-C2960S-48TS-S and WS-C2960S-48FPS-L have "Enhanced Limited Lifetime Warranty HW (ELLW) ( WARR-ELTD-LIFE-HW)" you can ask for a check/Hardware Replacement.
Best Regards
P.S.: please can you insert in email loop also me roberto@ipnetworks.it
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide