SRX

 View Only
  • 1.  issu failing on SRX1500

    This message was posted by a user wishing to remain anonymous
    Posted 10 days ago
    This message was posted by a user wishing to remain anonymous

    Hi there,

    We're trying to run an issu on a SRX1500 chassis cluster from version 25.2.R1.9 to 25.4R1.12.  When running the request system software etc command we get:

    web management gatekeeper process: cp: /var/db/httpd-gk/*: No such file or directory

    mgd: error: configuration check-out failed

    Validation failed

    node0:

    JSRPD exited in-service-upgrade window

    In the logs the only error we see:

    no handler for gencfg_cfg_msg_gen_handler: minor_type 105 check result

    Any assistance gratefully received.



    -------------------------------------------


  • 2.  RE: issu failing on SRX1500

    Posted 10 days ago

    You can try turning off web-management completely for the duration of the upgrade and turning it back on afterwards. This really rings a bell. I think there was a KB article about something like that, but I'm not 100% sure and I can't find it right now.

    Also, watch out for this: https://community.juniper.net/discussion/j-web-not-working-on-srx320-after-upgrade-to-junos-254



    ------------------------------
    Nikolay Semov
    ------------------------------



  • 3.  RE: issu failing on SRX1500

    Posted 4 days ago

    Thanks for the response.  We attempted to shutdown the httpd service before upgrading, but unfortunately got the same error messages.  We've also confirmed the folder and files exist in the location stated.  But not sure what file it would actually be looking for?



    ------------------------------
    ANDREW MCGREGOR
    ------------------------------



  • 4.  RE: issu failing on SRX1500

    Posted 4 days ago

    Interesting choice of words... Did you remove web-related configuration or just stop the service outside of the configuration?

    It looks like the upgrade is failing while verifying your existing configuration against the new version of JunOS, essentially trying a mock commit, of sorts. It's possible that while doing that one of its tasks is to copy some files or do something that would be valid against the file system as it would exist in the new version, but not necessarily valid (or permitted) during that mock commit. Every now and then Juniper would post an upgrade-related KB article saying to do an upgrade with the no-validate option which skips this mock commit of the configuration. I don't recall if that's an option for an ISSU; I have a feeling it's not, but not sure.



    ------------------------------
    Nikolay Semov
    ------------------------------



  • 5.  RE: issu failing on SRX1500

    Posted 6 days ago

    Running such new Junos is risky. The suggested version is Junos 23.4R2-S5 so chances are you're hitting a bug that is known but not resolved.

    https://supportportal.juniper.net/s/article/Junos-Software-Versions-Suggested-Releases-to-Consider-and-Evaluate#srx_series

    If you really need this very new Junos version (25.4R1), ISSU may not be the best way to upgrade. A chassis cluster upgrade can be performed without traffic loss via other methods than ISSU. In-service-upgrade is another method to do the same.

    https://www.juniper.net/documentation/us/en/software/junos/chassis-cluster-security-devices/topics/task/chassis-cluster-upgrading-and-aborting-backup-and-primary-device-with-icu.html#id-upgrading-icu-using-a-build-available-locally-on-a-primary-node-in-a-chassis-cluster

    Upgrading the secondary node first and failing over to that is another, but with sessions potentially lost.

    -------------------------------------------



  • 6.  RE: issu failing on SRX1500

    Posted 4 days ago

    Thanks for the response, and agree that running such a new version is risky.  We'll give a alternative method of upgrading a try.



    ------------------------------
    ANDREW MCGREGOR
    ------------------------------