4.3. Software Upgrades

FB2900 users benefit from FireBrick's pro-active software development process, which delivers fast fixes of important bugs, and implementation of many customer enhancement requests and suggestions for improvement. As a matter of policy, FireBrick software upgrades are always free to download for all FireBrick customers.

To complement the responsive UK-based development process, the FB2900 is capable of downloading and installing new software directly from Firebrick's servers, providing the unit has Internet access.

This Internet-based upgrade process can be initiated manually (refer to Section 4.3.3.1), or the FB2900 can download and install new software automatically, without user intervention.

If the unit you want to upgrade does not have Internet access, then new software can be uploaded to the unit via a web browser instead - see Section 4.3.4.

Caution

Software upgrades are best done using the Internet-based upgrade process if possible - this ensures the changes introduced by Checkpoint releases are automatically accounted for (see Section 4.3.1.1)

Software upgrades will trigger an automatic reboot of your FB2900 - this will cause an outage in routing, and can cause connections that are using NAT to drop. However, the FB2900 reboots very quickly, and in many cases, users will be generally unaware of the event. You can also use a profile to restrict when software upgrades may occur - for example, you could ensure they are always done overnight. The reboot will close all L2TP connections and BGP sessions first. The upgrade will wait for all VoIP calls to complete before rebooting.

4.3.1. Software release types

There are three types of software release : factory, beta and alpha. For full details on the differences between these software releases, refer to the 'Factory, Beta or Alpha?' section on the FireBrick software downloads website

Note

In order to be able to run alpha releases, your FB2900 must be enabled to run alpha software - this is done by changing the entry in the FireBrick capabilities database (hosted on FireBrick company servers) for your specific FB2900, as identified by the unit's Serial Number. Normally your FB2900 will be running factory or possibly beta software, with alpha software only used under advice and guidance of support personnel while investigating/fixing possible bugs or performance issues. You can see whether your FB2900 is able to run alpha releases by viewing the System/Unit Info page, and look for the row labelled "Allowed" - if the text shows "Alpha builds (for testing)" then your FB2900 can run alpha releases.

4.3.1.1. Checkpoint releases

We aim to make upgrading software as smooth as possible. However, it may not always be possible to upgrade from very old software to the latest version. This is because there may have been significant changes to the configuration format to enable more options, changes to software signing keys, or changes to the way the upgrade process operates etc. If the FireBrick software ends up a long way behind, then it will need to have certain intermediate versions installed. We call these versions 'checkpoint releases'.

On the FB2900 software downloads website, if you select the version you are going from and to, it will tell you about any checkpoints that may be required along the way. If you're using automatic upgrades or you're upgrading regularly, the upgrade process should handle everything for you and this is something you don't have to worry about.

When required, the web UI based upgrade process will automatically upgrade to the next available checkpoint version. If your current software version is several checkpoint releases behind the latest version, the upgrade process will be repeated for each checkpoint release, and then to the latest version if that is later than the latest checkpoint release.

Note

If you have saved copies of configurations for back-up purposes, we recommend saving a new config before and after upgrading.

If you use automated methods to configure your FB2900, you will need to check the documentation to see whether those methods need updating for the updated version.

4.3.1.2. Configuration changes on upgrade

Sometimes part of the configuration format may change, and the config will need to be transformed during an upgrade. See Section 3.4 for details.

Since version 2.06.019, configurations that are not at the latest patch version are transformed dynamically into the new format, without being re-saved to flash if the patch version is sufficiently recent. This means that if you want to revert to previous software versions, the original config data will still be in the flash so older software will still be able to understand that configuration fully.

However, if you save the config, it will be updated to the new format and older software won't be able to understand anything that has moved or changed in the latest patch version.

Downgrading the software past a release that makes configuration changes will (provided the running version is recent enough to have this feature) show a warning that the current configuration patch version is too recent. In this case check that the configuration looks correct for the running version, and correct or remove the patch attribute (this can be done in the XML editor, or by making any change in the UI based editor).

Note

Since a few old configs are kept as backups, you can still view and hence re-create the previous config from older software - so it is possible to remedy that situation if you don't need your recent changes, or are willing to re-apply them.

If reverting software, be aware that the dynamic transformation described above is not designed to provide backward compatibility indefinitely. However, it should ensure that the config stays in a format that can be understood by at least 2 factory releases prior to the running version.

If upgrading software, also be aware that config transforms will not always update from very old versions. If you upgrade via all checkpoint releases then you shouldn't have any issues. However, ignoring checkpoints could cause you problems with some parts of the configuration being lost.

4.3.2. Identifying current software version

The current software version is displayed on the main Status page, shown when you click the Status main menu-item itself (i.e. not a submenu item). The main software application version is shown next to the word "Software", e.g. :-

Software     FB9001 TEST Gallox (V2.06.025 2026-08-10T10:56:52)

The software version is also displayed in the right hand side of the 'footer' area of each web page, and is shown immediately after you log in to a command-line session.

4.3.3. Internet-based upgrade process

Note

'Out of the box' the FB2900 is configured to automatically download and install new factory releases. This is a safe option, and we expect many users to be happy with this - however, if you would prefer, this process can be disabled - refer to Section 4.3.3.2.

If automatic installs are allowed, the FB2900 will check for new software on boot up and approximately every 24 hours thereafter - your FB2900 should therefore pick up new software at most ~ 24 hours after it is released (assuming no delay is configured). You can choose to allow this process to install only new factory-releases, factory or beta releases, or any release, which then includes alpha releases (if your FB2900 is enabled for alpha software - see Section 4.3.1) - refer to Section 4.3.3.2 for details on how to configure auto upgrades.

Caution

Alpha releases may be unstable, and so we do not generally recommend setting your FB2900 to automatically install alpha releases. However alphas also get the fastest rate of fixes, so if you are running them it is worth doing reasonably regular updates.

4.3.3.1. Manually initiating upgrades

Whenever you browse to the main Status page, the FB2900 checks whether there is newer software available, given the current software version in use, and whether alpha releases are allowed. If new software is available, you will be informed of this in the software table.

To see what new software is available visit the Status Software page. This will show Release notes that are applicable given your current software version, and the latest version available. There is also an "Upgrade" button which will begin the software upgrade process.

4.3.3.2. Controlling automatic software updates

The auto-update element, under the system object, contains settings that affect the automatic software upgrade process :-

Table 4.4. Attributes controlling auto-upgrades

AttributeDescription
modeControls what types of software releases the auto-upgrade process will download/install. This attribute can also be used to disable the auto-upgrade process - use the value of off to achieve this.
  • off : Disables auto upgrades
  • factory : Only download/install factory releases - this is the default if the attribute is not specified
  • beta : Download/install factory or beta releases
  • alpha : Download/install factory, beta or alpha releases
profileSpecifies the name of a profile to use to control when software upgrades are attempted (see Chapter 10 for details on profiles).
delaySpecifies a minimum number of days after release to attempt the upgrade (intended for automating staggered upgrades).

The current setting of mode (in descriptive form) can be seen on the main Status page, labelled as "Auto upgrade".

4.3.4. Manual upgrade

This method is entirely manual, in the sense that the brick itself does not download new software from the FireBrick servers, and responsibilty for loading checkpoint releases as required lies with the user.

In order to do this, you will first need to download the required software image file (which has the file extension .img) from the FireBrick software downloads website onto your PC.

Then go to the Status Software page, the form to upload the image file is at the bottom.