sk182556 - Dynamic Routing outage in a Security Group during the Zero Downtime (MVC) Upgrade to R81.20 or Downgrade from R81.20
Dynamic Routing outage in a Security Group during the Zero Downtime (MVC) Upgrade to R81.20 or Downgrade from R81.20
Product: Maestro HyperScale Firewall, Scalable Chassis
Version: R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2024-12-13
Symptoms
- Dynamic Routing outage may occur in a Security Group during the Zero Downtime (MVC) Upgrade to R81.20 or Downgrade from R81.20 - the required dynamic routes are not present in the routing table on the Standby Security Group Member Members during the upgrade / downgrade.
Cause
Security Group Members in the Active status are not able to synchronize the route information for any Dynamic Routing protocol to Security Group Members of a different version.
This issue occurs in a Security Group in these scenarios:
- Upgrade from R81 to R81.20
- Downgrade from R81.20 to R81
- Upgrade from R81.10 to R81.20
- Downgrade from R81.20 to R81.10
- On R81.20 with the R81.20 Jumbo Hotfix Accumulator - installation of a higher Take of the R81.20 Jumbo Hotfix Accumulator
- On R81.20 with the R81.20 Jumbo Hotfix Accumulator - uninstall of the latest Take of the R81.20 Jumbo Hotfix Accumulator to revert to a lower Take
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 89
- Jumbo Hotfix Accumulator for R81.10 starting from Take 170
- Jumbo Hotfix Accumulator for R81 starting from Take 106
If you choose not to upgrade, the following workaround is available:
Perform the upgrade / downgrade on all Security Group Members at the same time.
This option requires a downtime and does not preserve the current connections.
Related Documentation
- Upgrade and Downgrade Procedures:
| Platform | Upgrade to R81.20 | Downgrade from R81.20 |
| Maestro | Link | Link |
| Scalable Chassis | Link | Link |
Article Properties
Access Level: General
Status: Approved
Date Created: 2024-07-31
Last Modified: 2024-12-13