Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Upgrade Junos OS on Switches

You can either manually upgrade switches and Virtual Chassis in a site, or schedule or automate upgrades across multiple sites in your organization.

Note:

Wired Assurance is not compatible with Junos Flex images. To ensure that only a standard Junos image is deployed, we recommend that you upgrade switches through the Mist portal.

Free Up Storage Space on Your Switch

When you initiate a switch upgrade process, Juniper Mist™ runs the request system storage cleanup command on the switch before copying the software image. This process mostly ensures the availability of storage space to accommodate the software image in the /var/tmp folder on the switch. However, in the case of some switches, such as EX2300 and EX3400, the request system storage cleanup command doesn't clear the required space. In this case, you will need to free up more space.

Note:
  • To perform the steps listed in this topic, you must have the root password configured in the site settings on the Organization > Site Configuration page of the Juniper Mist portal.

  • Perform the steps listed in this topic only if your switch doesn't have the required space for the upgrade.

To free up storage space on your switch:

  1. On the Juniper Mist portal, click Switches to go to the list of switches.
  2. Locate the switch on which you want to perform the storage cleanup operation.
  3. Select Utilities > Remote Shell.
  4. Begin a shell session by entering the start shell user root command, followed by the root password.
    This step starts a shell session on the primary FPC member by default.
  5. Check the storage usage, by running the df -h command.

    Generally, the /dev/gpt/junos file system takes up most of the space.

  6. Run the following command to free up the space on the switch:
  7. Check the available storage, using the df -h command. The output now shows lesser space as used under /dev/gpt/junos.
  8. Exit the shell session to return to the CLI operational mode, and then check the storage usage from there.

In the case of a Virtual Chassis upgrade, the preceding steps free up the space only on the primary member (member 0). You also need to initiate a session with each of the other FPC members (such as member 1 and member 2) and repeat the storage cleanup steps. See the following example:

Upgrade Switches in a Site Manually

Note: To schedule or automate switch upgrades across multiple sites in your organization, refer to the instructions provided in Schedule and Automate Switch Upgrades.

Users with Super User or Network Admin privileges for the site can manually upgrade Junos on switches or Virtual Chassis by selecting them from the switch list and clicking the Upgrade Firmware button.

Figure 1: Upgrade Juons on Selected Switches Upgrade Juons on Selected Switches

The switch should be under warranty, have an active maintenance contract, and an active software subscription. In addition, please be sure the switch has the following:

  • The storage space required to accommodate the new image.

  • A stable SSH connection to the Mist cloud.

  • (Optional) A recovery snapshot stored on the OAM volume. See Switch Utilities for details about the snapshot.

Supported Devices and Available Versions

The Juniper Mist™ portal supports upgrading the Junos OS software on the following platforms: EX2300, EX3400, EX4000, EX4100, EX4100-F, EX4300-P, EX4300-MP, EX4400, EX4600, EX4650, EX9200, QFX5110, QFX5120, and EX Series Virtual Chassis.

Juniper Mist does not support nonstop software upgrade (NSSU).

For both standard EOL and EEOL releases, you can upgrade to the next three subsequent releases or downgrade to the previous three releases.

For example, you can upgrade from 21.2 to the next three releases—21.3, 21.4 and 22.1—or downgrade to the previous three releases—21.1, 20.4 and 20.3.

For EEOL releases, you have an additional option—you can upgrade directly from one EEOL release to the next two subsequent EEOL releases, even if the target release is beyond the next three releases. Likewise, you can downgrade directly from one EEOL release to the previous two EEOL releases, even if the target release is beyond the previous three releases. For example, 21.2 is an EEOL release. Hence, you can upgrade from 21.2 to the next two EEOL releases —21.4 and 22.2—or downgrade to the previous two EEOL releases—20.4 and 20.2. Check Junos OS Dates and Milestones to see whether a release has reached EEOL.

For more information about releases, consult these topics:

Steps to Upgrade a Switch

To upgrade the Junos OS software on your switch (or Virtual Chassis):

  1. Click Switches on the left navigation pane in the Juniper Mist portal.
  2. From the Site menu, select the site where you want to perform the upgrade.
  3. Locate the switch to be upgraded, and ensure that it is connected (displays the Connected status).
    If the switch doesn't appear on Mist as connected, troubleshoot the issue as explained in Troubleshoot Your Switch Connectivity.
  4. From the List tab, select the switch that requires a software upgrade, and then click Upgrade Firmware. You can select one or more switches for upgrade.

    Alternatively, you can also upgrade the switch by using the Upgrade Firmware option on the Utilities drop-down list on the switch details page (see Switch Details).

  5. In the Upgrade Switch Firmware window, select the target software version from the Upgrade to Version drop-down list, and then click Start Upgrade. The drop-down list displays the suggested software version for the selected switch, along with all the applicable versions.

    If you don't see the software version you are looking for, write to support@mist.com. We will make the version available from 24 to 48 hours after receiving the request.

    Select the Reboot switch after image copy check box if you want the switch to reboot automatically after the image copy procedure is complete.

    • If you select this option, the switch boots up with the new image.

    • If you do not select this option, the switch remains in a state of pending reboot. In this case, do the following to complete the upgrade:

      1. Click Switches > Switch Name to navigate to the switch details page.

      2. Reboot the switch by clicking the Reboot option displayed at the top of the page. Or, click Utilities > Reboot Switch to initiate a reboot.

        Depending on the switch model, the switch details page may provide options to either reboot the switch or revert the upgrade. If you choose not to proceed with the upgrade, you can revert it. Note that the revert option is only available until the switch is rebooted.

        Graphical interface for managing EX4100-VC-DESK switch showing front panel port status and options to view port groups Backup, Linecard, Primary. Notifications indicate upgrade complete with buttons Reboot Switch and Revert Upgrade. Additional controls include Locate, Utilities, Save, and Close. Green indicators represent active ports; empty boxes signify inactive ports.
    Select Create a recovery snapshot post upgrade if you want the switch to have a recovery snapshot. A recovery snapshot stored in OAM (Operations, Administration, and Maintenance) volume holds a full backup that can be used in case something goes wrong with Junos volume.
    Select I accept End User Agreement.

Once the upgrade starts, the Status column in the switch list view shows the switch status as Upgrading. The column also shows the progress of the upgrade.

If you don't see the Status column in the switch list view, click the hamburger menu in the upper right of the page. Select the Status check box to display the column.

You can also view the switch status (as Upgrading) on the switch details page and the Switch Insights page.

You can view the upgrade events in the Switch Events section of a Switch Insights page. To access the Switch Insights page, open a switch details page and click the Switch Insights link on the Properties tile.

The above image shows a Switch Insights page, which lists switch upgrade events. The Upgraded by User event indicates that a user has initiated the upgrade. The Upgraded event indicates that the upgrade operation is complete. This means that the new software image was copied and the switch was rebooted.

An upgrade will fail if:

  • The switch doesn't have an SSH connection to the Juniper Mist cloud or if an uplink port is flapping.

  • The switch doesn't have enough storage. If the upgrade fails because of insufficient space, the upgrade failure event is displayed on the Switch Insights page as shown below:

    See also: Free Up Storage Space on Your Switch

  • You initiate an upgrade to the same software version that is already running on the switch. In this case, the Switch Events section of the Switch Insights page shows this failure reason:

    Upgrade not needed. Please check current or pending version.

  • The time on the switch is incorrect. In this case, the Switch Events section of the Switch Insights page shows this failure reason:

    OC FWUPDATE WRITEFAILED. See also: [EX/QFX] Certificate errors - Cannot validate Junos Image : Format error in certificate.

Schedule and Automate Switch Upgrades

Note:

To manually upgrade individual switches or a bunch of switches in a site, refer to the instructions provided in Upgrade Switches in a Site Manually.

Juniper Mist allows you to:

  • Create and manage upgrade schedules for the switches that are connected to the Mist cloud. This option is available at the organization and site level.

  • Configure settings to automatically upgrade new switches when they are onboarded. This setting is available only at the organization level.

Schedule Switch Upgrades

You can schedule firmware upgrades (Junos OS upgrades) on your switches for a future date and time. You can also execute the upgrades immediately. You can create upgrade schedules at the organization and site level for switch models that are already connected to cloud.

To schedule a switch upgrade:

  1. Click Organization > Firmware Upgrade.
  2. From the Firmware Upgrade page, select the Switches tab.
  3. Click Schedule Upgrade.
  4. Select the upgrade scope.
    1. To upgrade switches deployed across the entire organization, enable the Entire Org toggle.
    2. To upgrade switches deployed in specific sites, click the + button, select the sites for which you need to run switch upgrades, and then click Add.
    All the device models available for the selected scope are listed.
  5. For each device model listed, select a target Junos version from the Upgrade to Version drop-down list.
  6. If you want to apply upgrades only to specific switches belonging to the selected model, do the following:
    1. Enable the Match Criteria option. This option allows you to define certain additional parameters that need to be matched for a switch to be included in an upgrade schedule.
    2. Define the parameters to be matched. They include:
      • Switch Name—Specify a switch name to be matched. Optionally, specify an offset value, which indicates the starting character within the switch name (0 being the first character). For example, to match the keyword IDF-2 in the switch hostname JNPR-IDF-2, enter JNPR-IDF-2 as the switch name and set the offset value to 5.

      • Role—You can either select a switch role that is already defined by a user, or define a new role.

      • Campus Fabric Role—Select a campus fabric role from the drop-down list.

        Note: If multiple parameters (for example, a Switch Name and a Role) are specified, an upgrade is triggered only if all the specified parameters are matched. The keywords are case-sensitive.
      User interface for scheduling firmware upgrades for Juniper switches. Lists EX2300 and EX4400 models upgrading to version 23.4R2-S5.8 with match criteria toggle. Includes fields for switch name JNPR-IDF-2, offset 5, role CORE-EX4400, and campus fabric role Core. Checkbox selected for creating recovery snapshot post-upgrade. Buttons for Apply, Cancel, Next, and Back. Footer notes 2 switch models selected for upgrade.
    3. Click Apply.
      Match criteria configuration is available per device model.
    Note:

    For Virtual Chassis switches, firmware upgrades always trigger a full stack reboot, and all Virtual Chassis members are upgraded together, regardless of the order in which member upgrades are scheduled. Per‑member reboots are not supported for Virtual Chassis environments.

  7. Specify the upgrade schedule details by referring to the table below:
    Field Description
    Scheduling

    Select an upgrade schedule:

    • Upgrade Now: Choose this option if you want to execute upgrades and reboots immediately. This is the default option.

    • Upgrade Later: Choose this option to schedule switch upgrades for a future date and time. You need to also specify a date and time using the date picker in the Image Installation Time field.

      If you select this option, you can also choose to set a different reboot time for the switches being upgraded. To do that select Set a different reboot time and specify a date and time using the date picker.

    How should devices download firmware?

    (Expand the More Settings section to access this option.)

    Select an image installation strategy. These strategies will be applied separately to each upgrade run (generated for each site-model-SKU combination). The following strategies are available:

    • Simultaneous: Installs images on all switches at once without any specific priority. This is the default option.

    • Phased: Downloads and installs images on switches in user-defined phases (specified in percentage). If you select this option, you need to also specify the phases in percentages. For example, to upgrade 100 devices in four phases, you can specify the values 5, 25, 50, 100 in the Image Installation Canary Phases field.

    • Serial: Downloads and installs images on switches in a sequential, random order.

    Download Max Failure Percentage

    (Expand the More Settings section to access this option.)

    Maximum percentage of devices allowed to fail upgrade in each upgrade run (generated for each site-model-SKU combination). If the number of failures exceeds the set percentage:

    • The upgrade process is canceled for the remaining devices in the current run.

    • Reboot is not triggered for any of the devices included in the current upgrade run.

    How should devices reboot?

    (Expand the More Settings section to access this option.)

    Select a reboot strategy. These strategies will be applied separately to each upgrade run (generated for each site-model-SKU combination). The following strategies are available:

    • Simultaneous: Reboots all devices at once without any specific priority.

    • Phased: Reboots the switches in user-defined phases. If you select this option, you need to specify the phases in percentages. For example, to reboot 100 devices in four phases, you can specify the values 5, 25, 50, 100 in the Reboot Canary Phases field.

    • Serial: Reboots the switches in a sequential, random order.

    Reboot Max Failure percentage

    (Expand the More Settings section to access this option.)

    Maximum percentage of devices allowed to fail reboot in each upgrade run (generated for each site-model-SKU combination). If the number of failures exceeds the set percentage, the reboot process is canceled for the remaining devices in the current run.

  8. A recovery snapshot is automatically created on the switch post upgrade. If you don’t want that, clear the Create a recovery snapshot post upgrade check box.
  9. Select the I accept the End User License Agreement check box.
  10. Click Review.
  11. After reviewing the upgrade schedule, click Schedule.

If you configure multiple upgrade schedules for the same device, the most recently configured schedule will be applied.

Manage Switch Upgrade and Reboot Schedules

You can cancel, edit, or view switch upgrade schedules from the Firmware Upgrade page.

Note that the upgrade schedules will be available only if your inventory has switches that meet the upgrade schedule parameters defined. For example, if you specify a switch name in the upgrade schedule but your inventory does not have a switch with that name, you will not see a record for that upgrade schedule.

To view the schedule details and upgrade status, go to Organization > Firmware Upgrade page and expand the schedule by clicking the up arrow on the left of the line item.

To edit or cancel an upgrade or reboot-only schedule:

  1. Go to Organization > Firmware Upgrade.
  2. Click the Switches tab.
  3. Expand the upgrade schedule that you want to update or cancel, and use the following options as required:
    • To edit the schedule, click Edit, make the changes, and then click Save Changes. You can edit only those upgrades or reboots that have not yet started. You cannot edit in-progress upgrades or reboots. Only the following information can be edited: scheduled upgrade time, reboot time, and the upgrade to version.

    • To cancel a schedule, click Cancel Upgrade (Cancel Reboot for a reboot-only operation) and follow instructions. You can cancel the upgrades or reboots that are either in-progress or yet to start.

To view all the upgrades that were completed within the last 30 days, click the Past Upgrades tab (the Past Reboot tab for a reboot-only operation). You cannot edit these records.

Enable Automatic Upgrade for Switches

If you want newly onboarded switches in an organization to automatically upgrade to a specific Junos version when they connect to the Mist cloud for the first time, you can map switch models to relevant Junos upgrade versions. The automatic upgrade settings can be configured only at the organization level. This feature is not applicable to the switches that are already online.

Note:

We recommend enabling Auto Upgrade as a best practice to ensure that all the onboarded switches are on the suggested version right from the beginning.

To configure automatic upgrade settings:

  1. Click Organization > Firmware Upgrade.
  2. Select Auto Upgrade Settings.
  3. Select Switches.
  4. Select Upgrade To Version for each switch model listed.
  5. A recovery snapshot is automatically created on the switch post upgrade. If you don’t want that, clear the Create a recovery snapshot post upgrade check box.
  6. Select the I accept the End User License Agreement check box for the applicable switch families.
  7. Click Save.

When you claim a new switch, the claim window displays the automatic upgrade version of Junos that is configured for each switch model. If you want to update this configuration, click Firmware Upgrades to go to the Firmware Upgrade page and make the required changes.