Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Enabling TPM blocks any Junos upgrade on SRX

$
0
0

Hi Alex,

 

D110 is the newest one, so basically any version anyone might want to upgrade is affected. In my case its D90/D100. 

 

If You enable TPM on JUNOS version older than D110, and then try to upgrade to D110, Your JUNOS regular installation will fail

 

Yes - and to upgrade you need to access the box locally using a console (!)  and clear TPM. Then you need to reinstall Junos from USB/TFTP. After that you need to rebuild the box from scratch using backed up config, secrets etc. 

 

We have quite a lot SRX devices with TPM / master passwords set and they are in remote location (VPN spokes). It makes the requirement of local access very difficult as we will need to send a technician to every one of them. Not to mention that the simple task of upgrading Junos now will require a lot of work (full box rebuild). Probably it would have been easier to RMA them, then to do that. Smiley Wink

 

Before D110 was realesed there was no information that enabling TPM might cause that kind of restrictions/problems. 

 

Regards,

Pawel Mazurkiewicz

 

 


Viewing all articles
Browse latest Browse all 17645

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>