09-18-2023 08:39 AM
Hi, there,
I've a couple of WS-C4507R+E switches (Version 03.08.07.E.152-4.E7) with installed standby supervisor engine.
Verifying the ios-xe image on the primary supervisor engine works, but verifying and image on the slavebootflash doesn't work:
HOSTNAME#verify bootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
Digital signature successfully verified in package cat4500es8-base.SPA.03.08.07.E.pkg
Digital signature successfully verified in package cat4500es8-firmware.SPA.03.08.07.E.pkg
Digital signature successfully verified in package cat4500es8-infra.SPA.03.08.07.E.pkg
Digital signature successfully verified in package cat4500es8-universalk9.SPA.152-4.E7.pkg
Digital signature successfully verified in file bootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
HOSTNAME#verify slavebootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
Error Verifying file slavebootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
Is this a expected behavior?
Do i have to attach (attach module 4", "session module 4") to the standby supervisor engine first and execute the verify command from the standby supervisor engine itself?
Solved! Go to Solution.
09-19-2023 02:33 AM - edited 09-19-2023 02:34 AM
Try this:
verify /md5 slavebootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin b2251364febbdfb5b6d4149ddd0e7a71
If this still comes up as corrupt, copy the IOS into a USB and stick it into the standby-supervisor card's USB port.
And then re-run the verify.
09-18-2023 08:48 AM
where did you copy the image from ? primary bootflash ?
i would check the size of the file ? compare primary and seconday bootflash :
make sure you can able to dir slavebootflash:
09-18-2023 09:04 AM
On most of the switches the image was copied from a usb stick to the primary bootflash.
Since the Supervisor Engines run in SSO mode the image was automatically copied from primary bootflash to the standby
The size of the files are equal.
The image seems to be ok, because we can switch between the supervisor engines without problems.
dir slavebootflash also works.
09-18-2023 04:02 PM
Post the complete output to the following commands:
dir bootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
dir slavebootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
09-19-2023 12:44 AM
HOSTNAME#dir bootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
Directory of bootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
38405 -rw- 514855624 Jun 9 2020 07:30:45 +02:00 cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
1732517888 bytes total (1214300160 bytes free)
HOSTNAME#$otflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
Directory of slavebootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
23045 -rw- 514855624 Jun 9 2020 07:39:00 +02:00 cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
1732517888 bytes total (1214300160 bytes free)
HOSTNAME#
I tried it on multiple switche - output (regarding size and names) is the same
09-19-2023 02:33 AM - edited 09-19-2023 02:34 AM
Try this:
verify /md5 slavebootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin b2251364febbdfb5b6d4149ddd0e7a71
If this still comes up as corrupt, copy the IOS into a USB and stick it into the standby-supervisor card's USB port.
And then re-run the verify.
09-21-2023 07:24 AM
Hi @Leo Laohoo
this commands works with both primary and standby sup / bootflash. The checksums are correct.
Do you have an explanation why i need to provide /md5 and a hash for the check of slavebootflash but not for (primary) bootflash?
My expectation is that I either need to provide /md5 and the hash all the time regardless if primary or secondary supervisor flash is checked or I don't need to provide /md5 and the hash regardless if primary or secondary supervisor flash is checked.
09-21-2023 03:19 PM
@LuensmannIT wrote:
this commands works with both primary and standby sup / bootflash.
Let me clarify, if you entered the command into the primary and secondary the output says "Verified"?
If it does, then it is a bug.
09-28-2023 11:47 AM
Primary:
verify /md5 bootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin b2251364febbdfb5b6d4149ddd0e7a71
Verified (bootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin) = b2251364febbdfb5b6d4149ddd0e7a71
verify bootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
Digital signature successfully verified in package cat4500es8-base.SPA.03.08.07.E.pkg
Digital signature successfully verified in package cat4500es8-firmware.SPA.03.08.07.E.pkg
Digital signature successfully verified in package cat4500es8-infra.SPA.03.08.07.E.pkg
Digital signature successfully verified in package cat4500es8-universalk9.SPA.152-4.E7.pkg
Digital signature successfully verified in file bootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
Secondary:
verify /md5 slavebootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin b2251364febbdfb5b6d4149ddd0e7a71
Verified (slavebootflash:cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin) = b2251364febbdfb5b6d4149ddd0e7a71
verify slavebootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
Error Verifying file slavebootflash:/cat4500es8-universalk9.SPA.03.08.07.E.152-4.E7.bin
09-28-2023 05:49 PM
RMA the secondary Supervisor card. The flash if f*cked.
09-29-2023 01:51 AM
Hmmm, it's happening on all 24 WS-C4507R+E switches (only standby sup) in production.
Having 24 times a f*cked up flash at the same time seems to be very weird.
Maybe it's indeed a bug. I will try to update the ios-xe image in a lab enviroment.
Could take quite a bit but i keep to updated.
09-29-2023 03:54 AM
Upgrade the firmware and try.
I have never seen a behaviour like that before.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: