< Home

Troubleshooting Smart Upgrade

Fault Description

In the output of the display smart-upgrade information command used to check the smart upgrade status, Check version result is displayed as netError.

Procedure

  1. Check whether a CA certificate is loaded for the SSL policy.

    By default, the function of verifying the CA certificate of a server is enabled. Therefore, a CA certificate needs to be loaded for an SSL policy. To check whether a CA certificate is loaded for the SSL policy to be bound to smart upgrade and check whether the certificate name is houp_root.cer, run the display ssl policy command. The certificate houp_root.cer is loaded, which is the built-in certificate of the system. If no CA certificate is loaded, run the trusted-ca load pem-ca ca-filename command to load a CA certificate for the SSL policy.

  2. Check the network connectivity between the switch and the HOUP.

    Because the HOUP resides on the public network, the switch must have access to the public network. You can run the ping houp.huawei.com command in the user view to check the network connectivity between the switch and the HOUP.

    If the ping fails, further troubleshoot the environment where the switch resides based on the actual networking.
    • If the switch resides on an intranet, run the smart-upgrade url and smart-upgrade https-port commands to configure the proxy site and HTTPS port of the proxy server for connecting to the switch.
    • If the switch resides on an extranet, check whether each link between the switch and the HOUP is available.
  3. Check whether traffic between the switch and the public network needs to traverse a firewall.

    If traffic between the switch and the public network needs to traverse a firewall, ensure the following:
    1. The switch communicates with the HOUP using HTTP or HTTPS.
    2. The HOUP uses port 443 for communication.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic