cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2860
Views
1
Helpful
16
Replies

I am trying to upgrade ROMMON on 4331 from 15.4(r3)s5.

sk002
Level 1
Level 1

I am tying to upgrade the ROMMON from 15.4(r3)s5 to isr4200_4300_rommon_1612_2r_SPA.pkg

the output I get when I type in: upgrade rom-monitor filename bootflash:isr4200_4300_rommon_1612_2r_SPA.pkg all


Chassis model ISR4331/K9 has a single rom-monitor.

Upgrade rom-monitor

Target copying rom-monitor image file
selected : 0
Booted : 0
Reset Reason: 0

Info: Upgrading only BIOS from the rommon package
4259840+0 records in
4259840+0 records out
4259840 bytes (4.3 MB) copied, 10.7823 s, 395 kB/s
262144+0 records in
262144+0 records out
262144 bytes (262 kB) copied, 0.777734 s, 337 kB/s
655360+0 records in
655360+0 records out
655360 bytes (655 kB) copied, 1.78389 s, 367 kB/s
File is a FIPS ROMMON image

what could be the problem? 

I also have tried an older version of ROMMON and same thing happens...

16 Replies 16

M02@rt37
VIP
VIP

Hello @sk002,

The output you provided indicates that the ROMMON upgrade process is copying the ROMMON image file successfully, but it states that the file is a "FIPS ROMMON" image. FIPS for Federal Information Processing Standards is a set of security standards used in certain government and industry applications.

The presence of a FIPS ROMMON image suggests that the ROMMON you are trying to upgrade to is specifically designed to meet FIPS compliance requirements. This could be the reason why the upgrade process is not completing as expected.

Ensure that the ROMMON image you are trying to upgrade to is compatible with your specific router model and software version. Check the compatibility matrix provided by Cisco to verify that the ROMMON version you are attempting to install is supported on your device.

https://www.cisco.com/c/en/us/td/docs/routers/access/4400/software/configuration/xe-16-12/isr4400swcfg-xe-16-12-book/installing_the_software.html

Some ROMMON versions may have specific licensing requirements. Make sure you have the appropriate licenses for the ROMMON version you are trying to install.

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

I looks like all my ROMMON packs FIPS ROMMON. is there a way I can install the FIPS ROMMON on my router?

I have to use the FIPS ROMMON.

Ok @sk002,

Do you have reloaded the routeur ?

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

yes

 

Ok @sk002,

Do yo have check the matrix compatibility? Because upgrade fail before Load Test and the Authenticity check of the image.

https://www.cisco.com/c/en/us/td/docs/routers/access/4400/software/configuration/xe-16-12/isr4400swcfg-xe-16-12-book/installing_the_software.html

 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

is there an upgrade path that I can't find.

On the boot I get this: Detected old ROMMON version 15.4(3r)S5, upgrade required.

I don't have anything older then is: isr4300-rommon.162-2r.pkg

Rich R
VIP
VIP

Share the output of "show platform", "sh rom-monitor r0" and "sh rom-monitor f0" and "sh ver" so we can see what IOS you're using.  I suspect you may be using too old an IOS to support that ROMMON.  You might need an intermediate ROMMON, then IOS upgrade, then latest ROMMON.
For example first upgrade to ROMMON https://software.cisco.com/download/home/285018115/type/282046486/release/16.7(5r)
Then IOS https://software.cisco.com/download/home/285018115/type/282046477/release/Fuji-16.9.8
Then ROMMON https://software.cisco.com/download/home/285018115/type/282046486/release/16.12(2r)
Then you can upgrade to latest IOS which will install the latest ROMMON automatically when you boot the new IOS, which means the boot time will take a few minutes extra (think 10 minutes).  The latest version is not downloadable, it's packaged with the IOS.

Refer to https://www.cisco.com/c/en/us/td/docs/routers/access/4400/cpld/isr4400_hwfp.html for more info.

I have already checked and installed previous versions, including isr4300-rommon.162-2r.pkg, but I still encountered the same error. I might need to retry the download, although I've successfully performed this process with other routers before with the same .pkg



Router#show platform
Chassis type: ISR4331/K9

Slot Type State Insert time (ago)
--------- ------------------- --------------------- -----------------
0 ISR4331/K9 ok 00:03:19
0/0 ISR4331-3x1GE ok 00:01:02
1 ISR4331/K9 ok 00:03:19
R0 ISR4331/K9 ok, active 00:03:19
F0 ISR4331/K9 ok, active 00:03:19
P0 PWR-4330-AC ok 00:02:38
P2 ACS-4330-FANASSY ok 00:02:38

Slot CPLD Version Firmware Version
--------- ------------------- ---------------------------------------
0 15030325 15.4(3r)S5
1 15030325 15.4(3r)S5
R0 15030325 15.4(3r)S5
F0 15030325 15.4(3r)S5

Router#


Router#sh rom-monitor r0

System Bootstrap, Version 15.4(3r)S5, RELEASE SOFTWARE
Copyright (c) 1994-2015 by cisco Systems, Inc.

Router#

 

Router#sh rom-monitor f0

System Bootstrap, Version 15.4(3r)S5, RELEASE SOFTWARE
Copyright (c) 1994-2015 by cisco Systems, Inc.

Router#

Router#show version
Cisco IOS XE Software, Version 16.03.06
Cisco IOS Software [Denali], ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 16.3.6, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2018 by Cisco Systems, Inc.
Compiled Wed 28-Feb-18 16:17 by mcpre


Cisco IOS-XE software, Copyright (c) 2005-2018 by cisco Systems, Inc.
All rights reserved. Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0. The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY. You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0. For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


ROM: IOS-XE ROMMON

Router uptime is 3 minutes
Uptime for this control processor is 6 minutes
System returned to ROM by LocalSoft
System image file is "bootflash:/isr4300-universalk9.16.03.06.SPA.bin"
Last reload reason: LocalSoft

 

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

 

Suite License Information for Module:'esg'

--------------------------------------------------------------------------------
Suite Suite Current Type Suite Next reboot
--------------------------------------------------------------------------------
FoundationSuiteK9 None None None
securityk9
appxk9

AdvUCSuiteK9 None None None
uck9
cme-srst
cube


Technology Package License Information:

-----------------------------------------------------------------
Technology Technology-package Technology-package
Current Type Next reboot
------------------------------------------------------------------
appxk9 None None None
uck9 None None None
securityk9 securityk9 Permanent securityk9
ipbase ipbasek9 Permanent ipbasek9

cisco ISR4331/K9 (1RU) processor with 1650898K/6147K bytes of memory.
Processor board ID FDO2035A0L3
3 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3207167K bytes of flash memory at bootflash:.
0K bytes of at webui:.

Configuration register is 0x2102

Router#

I also tried the ROMMON you sent. isr4200_4300_rommon_167_5r_SPA.pkg

Router#$-monitor filename bootflash:isr4200_4300_rommon_167_5r_SPA.pkg all
Chassis model ISR4331/K9 has a single rom-monitor.

Upgrade rom-monitor

Target copying rom-monitor image file
selected : 0
Booted : 0
Reset Reason: 0

Info: Upgrading only BIOS from the rommon package
4259840+0 records in
4259840+0 records out
4259840 bytes (4.3 MB) copied, 10.8327 s, 393 kB/s
262144+0 records in
262144+0 records out
262144 bytes (262 kB) copied, 0.778485 s, 337 kB/s
655360+0 records in
655360+0 records out
655360 bytes (655 kB) copied, 1.80728 s, 363 kB/s
File is a FIPS ROMMON image
Router#

I just tried upgrade on a 4451 running 16.3.6:

upgrade rom-monitor filename bootflash:isr4400_rommon_1612_2r_SPA.pkg all
Chassis model ISR4451-X/K9 has a single rom-monitor.

Upgrade rom-monitor

Target copying rom-monitor image file
selected : 1
Booted : 1
Reset Reason: 0

Info: Upgrading only BIOS from the rommon package
4259840+0 records in
4259840+0 records out
4259840 bytes (4.3 MB) copied, 5.31654 s, 801 kB/s
262144+0 records in
262144+0 records out
262144 bytes (262 kB) copied, 0.584782 s, 448 kB/s
655360+0 records in
655360+0 records out
655360 bytes (655 kB) copied, 1.02714 s, 638 kB/s
File is a FIPS ROMMON image

The only difference is the Selected and Booted being 1 compared to your 0 - is that what you refer to as the error?  Or is there some other error message you're seeing?  What do you see on console after trying the upgrade then reloading?
Have you tried updating CPLD first?

this is the only output I get. I have tried to update CPLD and it doesn't need the updating.

Router#$-monitor filename bootflash:isr4200_4300_rommon_1612_2r_SPA.pkg all
Chassis model ISR4331/K9 has a single rom-monitor.

Upgrade rom-monitor

Target copying rom-monitor image file
selected : 0
Booted : 0
Reset Reason: 0

Info: Upgrading only BIOS from the rommon package
4259840+0 records in
4259840+0 records out
4259840 bytes (4.3 MB) copied, 10.8804 s, 392 kB/s
262144+0 records in
262144+0 records out
262144 bytes (262 kB) copied, 0.776497 s, 338 kB/s
655360+0 records in
655360+0 records out
655360 bytes (655 kB) copied, 1.75752 s, 373 kB/s
File is a FIPS ROMMON image
Router#

here is the whole output from the upgrade command to the end of reload:

 

Router#$-monitor filename bootflash:isr4200_4300_rommon_1612_2r_SPA.pkg
upgrade rom-monitor filename bootflash:isr4200_4300_rommon_1612_2r_SPA.pkg
% Incomplete command.

Router#$-monitor filename bootflash:isr4200_4300_rommon_1612_2r_SPA.pkg all
Chassis model ISR4331/K9 has a single rom-monitor.

Upgrade rom-monitor

Target copying rom-monitor image file
selected : 0
Booted : 0
Reset Reason: 0

Info: Upgrading only BIOS from the rommon package
4259840+0 records in
4259840+0 records out
4259840 bytes (4.3 MB) copied, 10.7659 s, 396 kB/s
262144+0 records in
262144+0 records out
262144 bytes (262 kB) copied, 0.780605 s, 336 kB/s
655360+0 records in
655360+0 records out
655360 bytes (655 kB) copied, 1.7635 s, 372 kB/s
File is a FIPS ROMMON image
Router#
Router#reload
Proceed with reload? [confirm]

*May 22 16:15:31.956: %SYS-5-RELOAD: Reload requested by console. Reload Reason: Reload Command.May 22 16:15:52.772 R0/0: %PMAN-5-EXITACTION: Process manager is exiting: process exit with reload chassis code

 

Initializing Hardware ...

System integrity status: 00000610
Rom image verified correctly


System Bootstrap, Version 15.4(3r)S5, RELEASE SOFTWARE
Copyright (c) 1994-2015 by cisco Systems, Inc.

Current image running: Boot ROM0

Last reset cause: LocalSoft
Cisco ISR4331/K9 platform with 4194304 Kbytes of main memory


File size is 0x1b65995b
Located isr4300-universalk9.16.03.06.SPA.bin
Image size 459643227 inode num 18, bks cnt 112218 blk size 8*512
#########################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################################
Boot image size = 459643227 (0x1b65995b) bytes

Package header rev 1 structure detected
Calculating SHA-1 hash...done
validate_package: SHA-1 hash:
calculated 5e64a8eb:e6e57a91:8cddb527:5427e572:1f70da9b
expected 5e64a8eb:e6e57a91:8cddb527:5427e572:1f70da9b

RSA Signed RELEASE Image Signature Verification Successful.
Package Load Test Latency : 8407 msec
Image validated
Detected old ROMMON version 15.4(3r)S5, upgrade required
Upgrading to newer ROMMON version required by this version of IOS-XE, do not power cycle the system. A reboot will automatically occur for the new ROMMON to take effect.
selected : 0
Booted : 0
Reset Reason: 0

Info: Upgrading entire flash from the rommon package
File is a FIPS ROMMON image

Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134-1706

 

Cisco IOS Software [Denali], ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 16.3.6, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2018 by Cisco Systems, Inc.
Compiled Wed 28-Feb-18 16:17 by mcpre

 

Cisco IOS-XE software, Copyright (c) 2005-2018 by cisco Systems, Inc.
All rights reserved. Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0. The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY. You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0. For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.

 

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco ISR4331/K9 (1RU) processor with 1650898K/6147K bytes of memory.
Processor board ID FDO2035A0L3
3 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3207167K bytes of flash memory at bootflash:.
0K bytes of at webui:.

%INIT: waited 0 seconds for NVRAM to be available

 

Press RETURN to get started!


*May 22 16:19:51.918: %SMART_LIC-6-AGENT_READY: Smart Agent for Licensing is initialized
*May 22 16:19:52.919: %LICENSE-6-EULA_ACCEPT_ALL: The Right to Use End User License Agreement is accepted
*May 22 16:19:52.978: %IOS_LICENSE_IMAGE_APPLICATION-6-LICENSE_LEVEL: Module name = esg Next reboot level = securityk9 and License = securityk9
*May 22 16:19:53.004: %IOS_LICENSE_IMAGE_APPLICATION-6-LICENSE_LEVEL: Module name = esg Next reboot level = ipbasek9 and License = ipbasek9
*May 22 16:19:54.266: %ISR_THROUGHPUT-6-LEVEL: Throughput level has been set to 300000 kbps
*May 22 16:19:59.948: dev_pluggable_optics_selftest attribute table internally inconsistent @ 0x125

*May 22 16:20:02.209: %NBAR-6-CACHE_SYNC_INFO: Cache synchronization. Initialized.
*May 22 16:20:03.286: %SPANTREE-5-EXTENDED_SYSID: Extended SysId enabled for type vlan
*May 22 16:20:04.294: %LINK-3-UPDOWN: Interface Lsmpi0, changed state to up
*May 22 16:20:04.321: %LINK-3-UPDOWN: Interface EOBC0, changed state to up
*May 22 16:20:04.322: %LINK-3-UPDOWN: Interface GigabitEthernet0, changed state to down
*May 22 16:20:04.334: %LINK-3-UPDOWN: Interface LIIN0, changed state to up
*May 22 16:20:05.931: %IOSXE_MGMTVRF-6-CREATE_SUCCESS_INFO: Management vrf Mgmt-intf created with ID 1, ipv4 table-id 0x1, ipv6 table-id 0x1E000001
*May 22 16:20:05.984: %LINEPROTO-5-UPDOWN: Line protocol on Interface Lsmpi0, changed state to up
*May 22 16:20:05.984: %LINEPROTO-5-UPDOWN: Line protocol on Interface EOBC0, changed state to up
*May 22 16:20:05.985: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed state to down
*May 22 16:20:05.985: %LINEPROTO-5-UPDOWN: Line protocol on Interface LIIN0, changed state to up
*May 22 16:19:57.488: %CMLIB-6-THROUGHPUT_VALUE: SIP1: cmand: Throughput license found, throughput set to 300000 kbps
*May 22 16:20:08.725: %SYS-5-CONFIG_I: Configured from memory by console
*May 22 16:20:08.733: %IOSXE_OIR-6-REMSPA: SPA removed from subslot 0/0, interfaces disabled
*May 22 16:20:08.736: %SPA_OIR-6-OFFLINECARD: SPA (ISR4331-3x1GE) offline in subslot 0/0
*May 22 16:20:08.742: %IOSXE_OIR-6-INSCARD: Card (fp) inserted in slot F0
*May 22 16:20:08.742: %IOSXE_OIR-6-ONLINECARD: Card (fp) online in slot F0
*May 22 16:20:08.819: %IOSXE_OIR-6-INSCARD: Card (cc) inserted in slot 0
*May 22 16:20:08.819: %IOSXE_OIR-6-ONLINECARD: Card (cc) online in slot 0
*May 22 16:20:08.822: %IOSXE_OIR-6-INSCARD: Card (cc) inserted in slot 1
*May 22 16:20:08.822: %IOSXE_OIR-6-ONLINECARD: Card (cc) online in slot 1
*May 22 16:20:08.951: %IOSXE_OIR-6-INSSPA: SPA inserted in subslot 0/0
*May 22 16:20:10.178: %LINK-5-CHANGED: Interface GigabitEthernet0, changed state to administratively down
*May 22 16:20:13.040: %SYS-6-BOOTTIME: Time taken to reboot after reload = 283 seconds
*May 22 16:20:13.571: %SPA_OIR-6-ONLINECARD: SPA (ISR4331-3x1GE) online in subslot 0/0
*May 22 16:20:16.514: %PNP-6-PNP_DISCOVERY_STOPPED: PnP Discovery stopped (Startup Config Present)
CRYPTO_PKI: setting trustpoint policy for TP-self-signed-1654909243 to specify TP-self-signed-1654909243 keypair usageFailed to generate persistent self-signed certificate.
Secure server will use temporary self-signed certificate.

*May 22 16:20:23.786: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
*May 22 16:20:23.786: %CRYPTO-6-GDOI_ON_OFF: GDOI is OFF
Router>

 

sk002
Level 1
Level 1

is this fixable? what can I do?

Review Cisco Networking products for a $25 gift card