RPD Secure Software Download
The cnBR Manager provides automated ways to securely download and activate software images to RPDs.
The secure software download (SSD) feature helps you to authenticate the source of a file and verify the integrity of the downloaded code before you use it in your system. The SSD feature is applicable to Remote PHY (R-PHY) devices installed in unsecure locations.
Prerequisites
To use SSD, the following prerequisites must be met:
-
For Non-Express mode: The RPD software image is available at an external TFTP or HTTP image server. The image server is where the software image is stored, and can be accessed by RPD.
-
For Express mode: The RPD software image is available in the Cisco Operations Hub. Ensure that RPD has connectivity to the management IP of Cisco Operations Hub.
-
Ensure that code validation certificates are available. For more information, go through the Add Code Validation Certificates topic.
Upload Software Image for RPD
For Express-mode of SSD, upload the software image to the cnBR Manager. Complete the following steps:
Procedure
Step 1 |
Enter the Cisco Operations Hub URL |
Step 2 |
On the Cisco Operations Hub, click the Cisco Operations Hub main menu button. |
Step 3 |
Choose cnBR Manager > Remote PHY Devices to open Remote PHY Devices page. |
Step 4 |
Click Image Management to open RPD Image pane. |
Step 5 |
Click Choose file to select the RPD software image file that you want to upload. |
Step 6 |
Click Upload. To delete any of the listed software image files, click the X icon that appears against the image name. |
Download Software Image for RPD
Download the software image from the specified server. The software image is available on an external TFTP or HTTP image server.
To download an RPD software image using SSD, complete the following steps:
Procedure
Step 1 |
Manually upload the software image to the external image server. |
||
Step 2 |
Add code validation certificates. |
||
Step 3 |
Upgrade the software image.
|
Add Code Validation Certificates
To authenticate the source and verify the integrity of the software image, Cisco cnBR uses the following two types of RPD code validation certificates (CVC).
-
M-CVC: The type of CVC released along with the Cisco RPD software image. Contact Cisco Support to get the M-CVC.
-
C-CVC: The type of CVC created and signed through Manufacturer’s Statement of Origin (MSO). When CVCs are available, upload them using the following procedure:
Procedure
Step 1 |
Enter the Cisco Operations Hub URL |
Step 2 |
On the Cisco Operations Hub, click the Cisco Operations Hub main menu button. |
Step 3 |
Choose cnBR Manager > Remote PHY Devices to open Remote PHY Devices page. |
Step 4 |
Click Code Validation Check to open RPD Code Validation Check pane. |
Step 5 |
Copy the contents from the CVC file to the appropriate text box and click Add. |
Upgrade the Software Image
To upgrade the software, complete the following steps:
Procedure
Step 1 |
Enter the Cisco Operations Hub URL |
Step 2 |
On the Cisco Operations Hub, click the Cisco Operations Hub main menu button. |
Step 3 |
Choose cnBR Manager > Remote PHY Devices to open Remote PHY Devices page. |
Step 4 |
Click Secure Software Download to open RPD Secure Software Download pane. |
Step 5 |
Scroll down the page and use the toggle button to choose to upgrade using either of the following options:
|
Upgrade RPD in Express Mode
Complete the following steps to upgrade the RPD software in Express mode:
Note |
Express mode works only with HTTP on PORT 80. |
Procedure
Step 1 |
In the RPD Secure Software Download pane, click On in the toggle button to choose the Express Mode option. |
||||
Step 2 |
Enter the following details in the appropriate text fields:
Ensure that the RPD is able to reach the Cisco Operations Hub management IP. |
||||
Step 3 |
Filter out the required RPDs by using the search field in the RPD Summary section. The list depicts the target RPDs for upgrade. |
||||
Step 4 |
Click Upgrade Now to upgrade the image without a reboot. Alternatively, you can also choose to upgrade during the next reboot by clicking Save Configuration. |
Upgrade RPD in Non-Express Mode
Complete the following steps to upgrade the RPD software in Non-Express mode:
Procedure
Step 1 |
In the RPD Secure Software Download pane, click Off in the Express Mode toggle button to choose the non-Express Mode option. |
||||||||||||
Step 2 |
Enter the following details in the appropriate text fields:
Ensure that the RPD is able to reach the Cisco Operations Hub management IP. |
||||||||||||
Step 3 |
Filter out the target RPDs by using the search field in the RPD Summary section. The RPDs in this list of RPDs are the target RPDs for upgrade. |
||||||||||||
Step 4 |
Click Upgrade Now to upgrade the image without a reboot. Alternatively, you can also choose to upgrade during the next reboot, by clicking Save Configuration. |
Monitor RPD and SSD State
The RPD SSD window provides options to monitor and trigger SSD operations. A dashboard, displaying three pie charts, provides details of the RPD status and metrics. Access this dashboard under the Cisco Operations Hub > cnBR Manager > Remote PHY Devices > Secure Software Download.
-
RPD State: Displays the states of RPDs that are upgraded. During the upgrade process, the RPD becomes offline and then returns online.
-
Software Version: Shows the number of RPDs for each RPD software version.
-
SSD State: Shows various phases of the SSD progress of RPDs.
RPD Summary
The RPD Summary table provides details of RPDs which can be upgraded. You can also search for a specific RPD or set of RPDs that can be upgraded. The following table explains the fields in the RPD Summary pane.
This table explains the fields in the RPD Summary pane.
Field |
Description |
---|---|
Name |
Name of the RPD. |
MAC Address |
MAC address of the RPD. |
Service Group |
Service group ID of the RPD. |
IPv4 Address |
IPv4 address of the RPD. |
IPv6 Address |
IPv6 address of the RPD. |
State |
Status of the RPD:
|
CCMTS ID |
Host name of the Cisco cnBR application. Example: |
SSD State |
Phase of the SSD progress. |
Software Version |
Version of the software running on the RPD. |
Online Timestamp |
Time when the RPD became online. |