<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICX 7150-C12P: bootloader command &amp;quot;update_primary&amp;quot; does not work due to FIPS in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109125#M7613</link>
    <description>&lt;P&gt;Hello Smiley,&lt;/P&gt;&lt;P&gt;Is there a way to do this via the bootloader prompt?&lt;/P&gt;</description>
    <pubDate>Mon, 01 Sep 2025 13:44:31 GMT</pubDate>
    <dc:creator>bayvilleopener</dc:creator>
    <dc:date>2025-09-01T13:44:31Z</dc:date>
    <item>
      <title>ICX 7150-C12P: bootloader command "update_primary" does not work due to FIPS</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109103#M7606</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I received a used ICX 7150-C12P. I've been trying to use the&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;update_primary&lt;/EM&gt;&lt;SPAN&gt; command but it returns&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;FIPS:update_primary command is disabled in FIPS/CC mode&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;even after disabling FIPS.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've fully booted into FastIron, cleared the keys, disabled FIPS, wrote to memory, and &lt;/SPAN&gt;&lt;EM&gt;reload&lt;/EM&gt;&lt;SPAN&gt;ed (after rebooting, &lt;/SPAN&gt;&lt;EM&gt;fips show&lt;/EM&gt;&lt;SPAN&gt; says that everything is turned off). I still get the same message when trying to &lt;/SPAN&gt;&lt;EM&gt;update_primary&lt;/EM&gt;&lt;SPAN&gt;. Does anyone have any experience with FIPS? I would appreciate any guidance. Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;REPLICATION&lt;/U&gt;&lt;/P&gt;&lt;P&gt;1) Here is everything that I have done in FastIron to disable FIPS:&lt;/P&gt;&lt;PRE&gt;enable&lt;BR /&gt;configure terminal&lt;BR /&gt;fips zeroize&lt;BR /&gt;crypto key zeroize all&lt;BR /&gt;no fips enable&lt;BR /&gt;write memory&lt;BR /&gt;reload&lt;/PRE&gt;&lt;P&gt;2) Here is everything I did in the bootloader after that:&lt;/P&gt;&lt;PRE&gt;setenv ipaddr 192.168.0.34&lt;BR /&gt;setenv netmask 255.255.255.0&lt;BR /&gt;&lt;SPAN&gt;setenv serverip 192.168.0.24&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;setenv image_name ICX7xxx/SPR08090mc.bin&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;setenv uboot ICX7xxx/mnz10118.bin&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;setenv fipsreset&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;update_uboot&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;saveenv&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;reset&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;3) More bootloader commands after the&amp;nbsp;reset:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;factory set-default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;setenv fipsreset&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;update_primary&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;At this point,&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;update_primary&lt;/EM&gt; returns&amp;nbsp;&lt;EM&gt;FIPS:update_primary command is disabled in FIPS/CC mode&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Here is the &lt;/SPAN&gt;&lt;EM&gt;show version&lt;/EM&gt;&lt;SPAN&gt; output if it is pertinent:&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;PRE&gt;ICX7150-C12 Switch&amp;gt;show version
  Copyright (c) Ruckus Networks, Inc. All rights reserved.
    UNIT 1: compiled on Oct  3 2023 at 04:49:31 labeled as SPS09010h_cd2
      (29360128 bytes) from Primary SPS09010h_cd2.bin (UFI)
        SW: Version 09.0.10h_cd2T211
      Compressed Primary Boot Code size = 786944, Version:10.1.26T225 (mnz10126)
       Compiled on Tue Nov 29 12:43:26 2022

  HW: Stackable ICX7150-C12-POE
==========================================================================
UNIT 1: SL 1: ICX7150-C12-2X10GR POE 12-port Management Module
      Serial  #:XXXXXXXXXXX [REDACTED]
      Software Package: BASE_SOFT_PACKAGE  
      Current License: 2X10GR
      P-ASIC  0: type B160, rev 11  Chip BCM56160_B0
==========================================================================
UNIT 1: SL 2: ICX7150-2X1GC 2-port 2G Module
==========================================================================
UNIT 1: SL 3: ICX7150-2X10GF 2-port 20G Module
==========================================================================
1000 MHz ARM processor ARMv7 88 MHz bus
    8 MB boot flash memory
    2 GB code flash memory
    1 GB DRAM
STACKID 1  system uptime is 1 day(s) 41 minute(s) 44 second(s)
The system started at 06:05:40 GMT+00 Tue Oct 03 2023
                                                                 
The system : started=cold start&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 31 Aug 2025 18:41:38 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109103#M7606</guid>
      <dc:creator>bayvilleopener</dc:creator>
      <dc:date>2025-08-31T18:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7150-C12P: bootloader command "update_primary" does not work due to FIPS</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109104#M7607</link>
      <description>&lt;P&gt;Edited title.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2025 18:42:14 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109104#M7607</guid>
      <dc:creator>bayvilleopener</dc:creator>
      <dc:date>2025-08-31T18:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7150-C12P: bootloader command "update_primary" does not work due to FIPS</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109112#M7610</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Bayvilleopener&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for reaching us&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Could you confirm whether you've attempted the firmware upgrade using either the &lt;STRONG&gt;TFTP&lt;/STRONG&gt; or &lt;STRONG&gt;USB&lt;/STRONG&gt; method? Based on the information you've provided, it appears that you have &lt;STRONG&gt;CLI access to the switch.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 12:41:40 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109112#M7610</guid>
      <dc:creator>Chandini</dc:creator>
      <dc:date>2025-09-01T12:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7150-C12P: bootloader command "update_primary" does not work due to FIPS</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109117#M7611</link>
      <description>&lt;P&gt;Hello Chandini,&lt;/P&gt;&lt;P&gt;Yes, I have attempted to upgrade using TFTP via the bootloader prompt.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 12:57:37 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109117#M7611</guid>
      <dc:creator>bayvilleopener</dc:creator>
      <dc:date>2025-09-01T12:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7150-C12P: bootloader command "update_primary" does not work due to FIPS</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109123#M7612</link>
      <description>&lt;P&gt;Hi Bayvilleopener,&lt;BR /&gt;&lt;BR /&gt;Could you please try uploading the relevant signature (.sig) file before the image (.bin) file for firmware upgrade and check?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 13:36:12 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109123#M7612</guid>
      <dc:creator>Smiley</dc:creator>
      <dc:date>2025-09-01T13:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7150-C12P: bootloader command "update_primary" does not work due to FIPS</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109125#M7613</link>
      <description>&lt;P&gt;Hello Smiley,&lt;/P&gt;&lt;P&gt;Is there a way to do this via the bootloader prompt?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 13:44:31 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109125#M7613</guid>
      <dc:creator>bayvilleopener</dc:creator>
      <dc:date>2025-09-01T13:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7150-C12P: bootloader command "update_primary" does not work due to FIPS</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109164#M7623</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Bayvilleopener&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for reaching us&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The method you're currently attempting appears to be a software recovery via the bootloader. As an alternative, I recommend trying the recovery using &lt;STRONG&gt;TFTP or USB through the CLI&lt;/STRONG&gt;. Please verify if this approach helps resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Below are the links you can refer:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;&lt;A href="https://community.ruckuswireless.com/t5/RUCKUS-Support-for-Lennar-Homes/How-to-upgrade-the-RUCKUS-ICX-7150-C12P-Switch-using-TFTP-Server/m-p/47187" target="_blank"&gt;https://community.ruckuswireless.com/t5/RUCKUS-Support-for-Lennar-Homes/How-to-upgrade-the-RUCKUS-ICX-7150-C12P-Switch-using-TFTP-Server/m-p/47187&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT face="courier new,courier" size="2"&gt;&lt;SPAN&gt;&lt;A href="https://community.ruckuswireless.com/t5/RUCKUS-Support-for-Lennar-Homes/How-to-Upgrade-a-RUCKUS-ICX-7150-C12P-Switch-using-a-USB-flash/m-p/46781" target="_blank"&gt;https://community.ruckuswireless.com/t5/RUCKUS-Support-for-Lennar-Homes/How-to-Upgrade-a-RUCKUS-ICX-7150-C12P-Switch-using-a-USB-flash/m-p/46781&lt;/A&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 15:50:27 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109164#M7623</guid>
      <dc:creator>Chandini</dc:creator>
      <dc:date>2025-09-02T15:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: ICX 7150-C12P: bootloader command "update_primary" does not work due to FIPS</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109676#M7642</link>
      <description>&lt;P&gt;The following worked, although I had to use the CLI instead of the bootloader. If anyone can't get past the username/password... try running&amp;nbsp;&lt;EM&gt;factory set-default&lt;/EM&gt; or&amp;nbsp;&lt;EM&gt;no password&lt;/EM&gt; in the bootloader before booting FastIron.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Code:&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;PRE&gt;! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! 
! FLASHING A FIPS-CURSED RUCKUS ICX 7150-C12P WITH FASTIRON v08.0.95s UFI IMAGE...
! I used the following commands to downgrade from v09.0.10h to v08.0.95s...
! v08.0.95s is the current recommended software and stability release for the ICX 7150-C12P as of 1 September 2025...
! See [ https://support.ruckuswireless.com/products?view_type=recommended_releases_table ] for more info...
! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! 

! ! ! Enter global config mode...
enable
conf t

! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !
! Some people may now need to setup an IP address and netmask,
! but I don't think I had to do this because
! I had already entered some setenv parameters in the bootloader from following 
! fohdeesha's guide...
! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !

! ! ! Make sure that FIPS is disabled and enable tftp
crypto key zeroize
no fips enable
no tftp disable

! ! ! Begin transfer/flashing of signature and image...
copy tftp flash &amp;lt;your-server's-ip&amp;gt; SPR08095sufi.sig fips-ufi-primary-sig
copy tftp flash &amp;lt;your-server's-ip&amp;gt; SPR08095sufi.sig fips-ufi-secondary-sig
copy tftp flash &amp;lt;your-server's-ip&amp;gt; SPR08095sufi.bin primary
copy tftp flash &amp;lt;your-server's-ip&amp;gt; SPR08095sufi.bin secondary

! ! ! Verify that the new version of firmware is now in flash memory before writing and restarting...
show flash
write memory
reload&lt;/PRE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;After this, make sure that all of the bootloader parameters are set to their original state and then reboot into the new firmware. I was able to successfully downgrade from v09.0.10h to v08.0.95s. Though, it would be nice to be able to copy signatures and images via the bootloader if that were required.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 16:31:06 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-7150-C12P-bootloader-command-quot-update-primary-quot-does/m-p/109676#M7642</guid>
      <dc:creator>bayvilleopener</dc:creator>
      <dc:date>2025-09-17T16:31:06Z</dc:date>
    </item>
  </channel>
</rss>

