Repository files navigation

iosfw

Automatic Cisco IOS firmware upgrades

Code style: black

Requires:

Overview

Automates the entire upgrade process:

  • Determines correct upgrade image for each platform
  • Transfer the new image
  • Verify image integrity
  • Extract archive and install
  • Optionally remove old image(s)
  • Set boot parameters
  • Schedule reload

Auto-detects best upgrade method available:

  • archive download-sw
  • software install
  • request platform software package install
  • If those fail, plain copy followed by set boot ...

Supported platforms:

  • Catalyst 3550
  • Catalyst 3560
  • Catalyst 3560-X
  • Catalyst 3750
  • Catalyst 3750-X
  • Catalyst 2960-S
  • Catalyst 2960-X
  • Catalyst 3650
  • Catalyst 3850
  • ISR 2921
  • ISR 4331
  • C892FSP
  • ME3400

Experimentally supported platforms:

  • ASR920
  • Catalyst 9k series

Currently unsupported platforms:

  • Nexus 3k/9k series

NOTE: Use at your own risk. It works well in my environment, but serious bugs are possible. Test thoroughly in a lab environment, and see known issues below.

Usage

Preparation

  1. Rename config/config.yaml.example to config.yaml, and review config/images.yaml, matching both to your requirements. Defaults are sane, but don't take any chances :)
  2. Copy your IOS images defined in images.yaml to the src_image_path defined in config.yaml.

Note: Pay special attention if you have devices of the same model, but need different IOS images (e.g., ipbase vs ipservices). In that case, define both images in images.yaml and add the same model to their respective models lists. Then, change match_feature_set to true in config.yaml.

Interactive Example

>>> from iosfw import iosfw
>>> device = iosfw('ios-sw-1')
>>> device.open()
Username [austindcc]:
Password:
Enable secret:
Opening connection to ios-sw-1...
Connected to ios-sw-1 (WS-C3560X-48P) as austind via ssh
Running version: 12.2(55)SE8
Upgrade version: 15.2(4)E8
Upgrade status: NEEDS UPGRADE
>>> device.upgrade()
Starting upgrade on ios-sw-1 at 14:34:09 06/13/19...
Checking free space...
Found enough free space!
Installing new firmware...
NOTE: No status updates possible during install, which may take 10 minutes or longer.
Install successful!
Removing running image...
Deleting flash:/c3560e-universalk9-mz.122-55.SE8...
Running image deleted.
Scheduling reload...
Reload scheduled for 00:00:00 PDT Fri Jun 14 2019 (9 hours and 16 minutes away)
Upgrade on ios-sw-1 completed at 14:43:32 06/13/19
Total time elapsed: 0:09:23.224298

Automated Example

See example/batch_example.py

Known issues

  • Only supports BUNDLE mode on cat9k. As of 2021-06-16, INSTALL mode reloads the device immediately, with no option to delay reload for image activation. This is not only inconvenient, but also complicates iosfw's state awareness.
  • As of 0.9.0, SCP image transfer directly from iosfw no longer works. I recommend setting up an FTP server on a separate host and setting config.yaml accordingly.
  • Catalyst 3k series (3650 and 3850) with IOS running in BUNDLE mode (booted directly to the .bin file), will not succeed in upgrading with request platform software package install. Upgrading them requires a different manual process that is not yet implemented:
    • Remove existing IOS packages: del /force flash:/cat*.pkg
    • Remove existing packages.conf: del /force flash:/packages.conf
    • Remove boot variables: no boot system in config mode
    • Copy upgrade image: copy <source> flash:
    • Install upgrade image: request platform software package expand switch all file flash:/<file>
    • Set boot variable: boot system flash:/<file>
    • Schedule reload: reload at 00:00
  • Currently, iosfw does not check to ensure transfer_source is reachable. If not reachable, the install command will fail, but not timeout for more than 30 minutes. Most commonly, transfer_source may not be reachable due to sending the requests out the incorrect interface. You can specify the source interface for TFTP and FTP transfers with ip (ftp|tftp) source-interface <iface> in config mode.
  • When using SSH proxy, iosfw throws a ProcessLookupError on exit. I have not found a way to catch or suppress this.
  • When remove_old_images is set to always on platforms using request software... install method, iosfw may incorrectly remove the newly installed image files. Net result is no change to system. Workaround: use remove_old_images = as_needed.
  • Totally untested on stacks.

Wishlist

  • Nornir integration
  • Fix native SCP image transfer option (broken as of 0.9.0)
  • Accept a pre-existing napalm connection object
  • Verify reachability of transfer_source, attempting fix as needed
  • More consistent debug output
  • N3K/N9K support

Contributions welcome.

Changelog

See CHANGELOG.md

Notes

  • Expect most upgrades to take 8-10 minutes per device, with one notable exception: Catalyst 3750-X took no less than 40 minutes in testing.
  • Expect devices to take between 10 and 30 minutes to come back after reload, especially if upgrading trains or major versions, due to microcode updates.
  • The automated install commands (archive download-sw and request platform software package install) download the upgrade package twice, for reasons I did not determine.
  • FTP and HTTP seem to be the fastest transfer methods. Even then, the download appears constrained by platform CPU resources, averaging about 4Mbps in most tests, while some newer platforms achieved 20Mbps.
  • The iosfw class exposes all of NAPALM's config parameters, and stores the NAPALM session under self.napalm, so you can use all of NAPALM's features easily.
  • Same goes for netmiko - stored as self.device - so you can send arbitrary commands with iosfw.device.send_command('my arbitrary command')

About

Automatic Cisco IOS firmware upgrades

Resources

Stars

89 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

iosfw

Automatic Cisco IOS firmware upgrades

Code style: black

Requires:

Overview

Automates the entire upgrade process:

  • Determines correct upgrade image for each platform
  • Transfer the new image
  • Verify image integrity
  • Extract archive and install
  • Optionally remove old image(s)
  • Set boot parameters
  • Schedule reload

Auto-detects best upgrade method available:

  • archive download-sw
  • software install
  • request platform software package install
  • If those fail, plain copy followed by set boot ...

Supported platforms:

  • Catalyst 3550
  • Catalyst 3560
  • Catalyst 3560-X
  • Catalyst 3750
  • Catalyst 3750-X
  • Catalyst 2960-S
  • Catalyst 2960-X
  • Catalyst 3650
  • Catalyst 3850
  • ISR 2921
  • ISR 4331
  • C892FSP
  • ME3400

Experimentally supported platforms:

  • ASR920
  • Catalyst 9k series

Currently unsupported platforms:

  • Nexus 3k/9k series

NOTE: Use at your own risk. It works well in my environment, but serious bugs are possible. Test thoroughly in a lab environment, and see known issues below.

Usage

Preparation

  1. Rename config/config.yaml.example to config.yaml, and review config/images.yaml, matching both to your requirements. Defaults are sane, but don't take any chances :)
  2. Copy your IOS images defined in images.yaml to the src_image_path defined in config.yaml.

Note: Pay special attention if you have devices of the same model, but need different IOS images (e.g., ipbase vs ipservices). In that case, define both images in images.yaml and add the same model to their respective models lists. Then, change match_feature_set to true in config.yaml.

Interactive Example

>>> from iosfw import iosfw
>>> device = iosfw('ios-sw-1')
>>> device.open()
Username [austindcc]:
Password:
Enable secret:
Opening connection to ios-sw-1...
Connected to ios-sw-1 (WS-C3560X-48P) as austind via ssh
Running version: 12.2(55)SE8
Upgrade version: 15.2(4)E8
Upgrade status: NEEDS UPGRADE
>>> device.upgrade()
Starting upgrade on ios-sw-1 at 14:34:09 06/13/19...
Checking free space...
Found enough free space!
Installing new firmware...
NOTE: No status updates possible during install, which may take 10 minutes or longer.
Install successful!
Removing running image...
Deleting flash:/c3560e-universalk9-mz.122-55.SE8...
Running image deleted.
Scheduling reload...
Reload scheduled for 00:00:00 PDT Fri Jun 14 2019 (9 hours and 16 minutes away)
Upgrade on ios-sw-1 completed at 14:43:32 06/13/19
Total time elapsed: 0:09:23.224298

Automated Example

See example/batch_example.py

Known issues

  • Only supports BUNDLE mode on cat9k. As of 2021-06-16, INSTALL mode reloads the device immediately, with no option to delay reload for image activation. This is not only inconvenient, but also complicates iosfw's state awareness.
  • As of 0.9.0, SCP image transfer directly from iosfw no longer works. I recommend setting up an FTP server on a separate host and setting config.yaml accordingly.
  • Catalyst 3k series (3650 and 3850) with IOS running in BUNDLE mode (booted directly to the .bin file), will not succeed in upgrading with request platform software package install. Upgrading them requires a different manual process that is not yet implemented:
    • Remove existing IOS packages: del /force flash:/cat*.pkg
    • Remove existing packages.conf: del /force flash:/packages.conf
    • Remove boot variables: no boot system in config mode
    • Copy upgrade image: copy <source> flash:
    • Install upgrade image: request platform software package expand switch all file flash:/<file>
    • Set boot variable: boot system flash:/<file>
    • Schedule reload: reload at 00:00
  • Currently, iosfw does not check to ensure transfer_source is reachable. If not reachable, the install command will fail, but not timeout for more than 30 minutes. Most commonly, transfer_source may not be reachable due to sending the requests out the incorrect interface. You can specify the source interface for TFTP and FTP transfers with ip (ftp|tftp) source-interface <iface> in config mode.
  • When using SSH proxy, iosfw throws a ProcessLookupError on exit. I have not found a way to catch or suppress this.
  • When remove_old_images is set to always on platforms using request software... install method, iosfw may incorrectly remove the newly installed image files. Net result is no change to system. Workaround: use remove_old_images = as_needed.
  • Totally untested on stacks.

Wishlist

  • Nornir integration
  • Fix native SCP image transfer option (broken as of 0.9.0)
  • Accept a pre-existing napalm connection object
  • Verify reachability of transfer_source, attempting fix as needed
  • More consistent debug output
  • N3K/N9K support

Contributions welcome.

Changelog

See CHANGELOG.md

Notes

  • Expect most upgrades to take 8-10 minutes per device, with one notable exception: Catalyst 3750-X took no less than 40 minutes in testing.
  • Expect devices to take between 10 and 30 minutes to come back after reload, especially if upgrading trains or major versions, due to microcode updates.
  • The automated install commands (archive download-sw and request platform software package install) download the upgrade package twice, for reasons I did not determine.
  • FTP and HTTP seem to be the fastest transfer methods. Even then, the download appears constrained by platform CPU resources, averaging about 4Mbps in most tests, while some newer platforms achieved 20Mbps.
  • The iosfw class exposes all of NAPALM's config parameters, and stores the NAPALM session under self.napalm, so you can use all of NAPALM's features easily.
  • Same goes for netmiko - stored as self.device - so you can send arbitrary commands with iosfw.device.send_command('my arbitrary command')

About

Automatic Cisco IOS firmware upgrades

Resources

Stars

89 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

iosfw

Automatic Cisco IOS firmware upgrades

Code style: black

Requires:

Overview

Automates the entire upgrade process:

  • Determines correct upgrade image for each platform
  • Transfer the new image
  • Verify image integrity
  • Extract archive and install
  • Optionally remove old image(s)
  • Set boot parameters
  • Schedule reload

Auto-detects best upgrade method available:

  • archive download-sw
  • software install
  • request platform software package install
  • If those fail, plain copy followed by set boot ...

Supported platforms:

  • Catalyst 3550
  • Catalyst 3560
  • Catalyst 3560-X
  • Catalyst 3750
  • Catalyst 3750-X
  • Catalyst 2960-S
  • Catalyst 2960-X
  • Catalyst 3650
  • Catalyst 3850
  • ISR 2921
  • ISR 4331
  • C892FSP
  • ME3400

Experimentally supported platforms:

  • ASR920
  • Catalyst 9k series

Currently unsupported platforms:

  • Nexus 3k/9k series

NOTE: Use at your own risk. It works well in my environment, but serious bugs are possible. Test thoroughly in a lab environment, and see known issues below.

Usage

Preparation

  1. Rename config/config.yaml.example to config.yaml, and review config/images.yaml, matching both to your requirements. Defaults are sane, but don't take any chances :)
  2. Copy your IOS images defined in images.yaml to the src_image_path defined in config.yaml.

Note: Pay special attention if you have devices of the same model, but need different IOS images (e.g., ipbase vs ipservices). In that case, define both images in images.yaml and add the same model to their respective models lists. Then, change match_feature_set to true in config.yaml.

Interactive Example

>>> from iosfw import iosfw
>>> device = iosfw('ios-sw-1')
>>> device.open()
Username [austindcc]:
Password:
Enable secret:
Opening connection to ios-sw-1...
Connected to ios-sw-1 (WS-C3560X-48P) as austind via ssh
Running version: 12.2(55)SE8
Upgrade version: 15.2(4)E8
Upgrade status: NEEDS UPGRADE
>>> device.upgrade()
Starting upgrade on ios-sw-1 at 14:34:09 06/13/19...
Checking free space...
Found enough free space!
Installing new firmware...
NOTE: No status updates possible during install, which may take 10 minutes or longer.
Install successful!
Removing running image...
Deleting flash:/c3560e-universalk9-mz.122-55.SE8...
Running image deleted.
Scheduling reload...
Reload scheduled for 00:00:00 PDT Fri Jun 14 2019 (9 hours and 16 minutes away)
Upgrade on ios-sw-1 completed at 14:43:32 06/13/19
Total time elapsed: 0:09:23.224298

Automated Example

See example/batch_example.py

Known issues

  • Only supports BUNDLE mode on cat9k. As of 2021-06-16, INSTALL mode reloads the device immediately, with no option to delay reload for image activation. This is not only inconvenient, but also complicates iosfw's state awareness.
  • As of 0.9.0, SCP image transfer directly from iosfw no longer works. I recommend setting up an FTP server on a separate host and setting config.yaml accordingly.
  • Catalyst 3k series (3650 and 3850) with IOS running in BUNDLE mode (booted directly to the .bin file), will not succeed in upgrading with request platform software package install. Upgrading them requires a different manual process that is not yet implemented:
    • Remove existing IOS packages: del /force flash:/cat*.pkg
    • Remove existing packages.conf: del /force flash:/packages.conf
    • Remove boot variables: no boot system in config mode
    • Copy upgrade image: copy <source> flash:
    • Install upgrade image: request platform software package expand switch all file flash:/<file>
    • Set boot variable: boot system flash:/<file>
    • Schedule reload: reload at 00:00
  • Currently, iosfw does not check to ensure transfer_source is reachable. If not reachable, the install command will fail, but not timeout for more than 30 minutes. Most commonly, transfer_source may not be reachable due to sending the requests out the incorrect interface. You can specify the source interface for TFTP and FTP transfers with ip (ftp|tftp) source-interface <iface> in config mode.
  • When using SSH proxy, iosfw throws a ProcessLookupError on exit. I have not found a way to catch or suppress this.
  • When remove_old_images is set to always on platforms using request software... install method, iosfw may incorrectly remove the newly installed image files. Net result is no change to system. Workaround: use remove_old_images = as_needed.
  • Totally untested on stacks.

Wishlist

  • Nornir integration
  • Fix native SCP image transfer option (broken as of 0.9.0)
  • Accept a pre-existing napalm connection object
  • Verify reachability of transfer_source, attempting fix as needed
  • More consistent debug output
  • N3K/N9K support

Contributions welcome.

Changelog

See CHANGELOG.md

Notes

  • Expect most upgrades to take 8-10 minutes per device, with one notable exception: Catalyst 3750-X took no less than 40 minutes in testing.
  • Expect devices to take between 10 and 30 minutes to come back after reload, especially if upgrading trains or major versions, due to microcode updates.
  • The automated install commands (archive download-sw and request platform software package install) download the upgrade package twice, for reasons I did not determine.
  • FTP and HTTP seem to be the fastest transfer methods. Even then, the download appears constrained by platform CPU resources, averaging about 4Mbps in most tests, while some newer platforms achieved 20Mbps.
  • The iosfw class exposes all of NAPALM's config parameters, and stores the NAPALM session under self.napalm, so you can use all of NAPALM's features easily.
  • Same goes for netmiko - stored as self.device - so you can send arbitrary commands with iosfw.device.send_command('my arbitrary command')

About

Automatic Cisco IOS firmware upgrades

Resources

Stars

89 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

iosfw

Automatic Cisco IOS firmware upgrades

Code style: black

Requires:

Overview

Automates the entire upgrade process:

  • Determines correct upgrade image for each platform
  • Transfer the new image
  • Verify image integrity
  • Extract archive and install
  • Optionally remove old image(s)
  • Set boot parameters
  • Schedule reload

Auto-detects best upgrade method available:

  • archive download-sw
  • software install
  • request platform software package install
  • If those fail, plain copy followed by set boot ...

Supported platforms:

  • Catalyst 3550
  • Catalyst 3560
  • Catalyst 3560-X
  • Catalyst 3750
  • Catalyst 3750-X
  • Catalyst 2960-S
  • Catalyst 2960-X
  • Catalyst 3650
  • Catalyst 3850
  • ISR 2921
  • ISR 4331
  • C892FSP
  • ME3400

Experimentally supported platforms:

  • ASR920
  • Catalyst 9k series

Currently unsupported platforms:

  • Nexus 3k/9k series

NOTE: Use at your own risk. It works well in my environment, but serious bugs are possible. Test thoroughly in a lab environment, and see known issues below.

Usage

Preparation

  1. Rename config/config.yaml.example to config.yaml, and review config/images.yaml, matching both to your requirements. Defaults are sane, but don't take any chances :)
  2. Copy your IOS images defined in images.yaml to the src_image_path defined in config.yaml.

Note: Pay special attention if you have devices of the same model, but need different IOS images (e.g., ipbase vs ipservices). In that case, define both images in images.yaml and add the same model to their respective models lists. Then, change match_feature_set to true in config.yaml.

Interactive Example

>>> from iosfw import iosfw
>>> device = iosfw('ios-sw-1')
>>> device.open()
Username [austindcc]:
Password:
Enable secret:
Opening connection to ios-sw-1...
Connected to ios-sw-1 (WS-C3560X-48P) as austind via ssh
Running version: 12.2(55)SE8
Upgrade version: 15.2(4)E8
Upgrade status: NEEDS UPGRADE
>>> device.upgrade()
Starting upgrade on ios-sw-1 at 14:34:09 06/13/19...
Checking free space...
Found enough free space!
Installing new firmware...
NOTE: No status updates possible during install, which may take 10 minutes or longer.
Install successful!
Removing running image...
Deleting flash:/c3560e-universalk9-mz.122-55.SE8...
Running image deleted.
Scheduling reload...
Reload scheduled for 00:00:00 PDT Fri Jun 14 2019 (9 hours and 16 minutes away)
Upgrade on ios-sw-1 completed at 14:43:32 06/13/19
Total time elapsed: 0:09:23.224298

Automated Example

See example/batch_example.py

Known issues

  • Only supports BUNDLE mode on cat9k. As of 2021-06-16, INSTALL mode reloads the device immediately, with no option to delay reload for image activation. This is not only inconvenient, but also complicates iosfw's state awareness.
  • As of 0.9.0, SCP image transfer directly from iosfw no longer works. I recommend setting up an FTP server on a separate host and setting config.yaml accordingly.
  • Catalyst 3k series (3650 and 3850) with IOS running in BUNDLE mode (booted directly to the .bin file), will not succeed in upgrading with request platform software package install. Upgrading them requires a different manual process that is not yet implemented:
    • Remove existing IOS packages: del /force flash:/cat*.pkg
    • Remove existing packages.conf: del /force flash:/packages.conf
    • Remove boot variables: no boot system in config mode
    • Copy upgrade image: copy <source> flash:
    • Install upgrade image: request platform software package expand switch all file flash:/<file>
    • Set boot variable: boot system flash:/<file>
    • Schedule reload: reload at 00:00
  • Currently, iosfw does not check to ensure transfer_source is reachable. If not reachable, the install command will fail, but not timeout for more than 30 minutes. Most commonly, transfer_source may not be reachable due to sending the requests out the incorrect interface. You can specify the source interface for TFTP and FTP transfers with ip (ftp|tftp) source-interface <iface> in config mode.
  • When using SSH proxy, iosfw throws a ProcessLookupError on exit. I have not found a way to catch or suppress this.
  • When remove_old_images is set to always on platforms using request software... install method, iosfw may incorrectly remove the newly installed image files. Net result is no change to system. Workaround: use remove_old_images = as_needed.
  • Totally untested on stacks.

Wishlist

  • Nornir integration
  • Fix native SCP image transfer option (broken as of 0.9.0)
  • Accept a pre-existing napalm connection object
  • Verify reachability of transfer_source, attempting fix as needed
  • More consistent debug output
  • N3K/N9K support

Contributions welcome.

Changelog

See CHANGELOG.md

Notes

  • Expect most upgrades to take 8-10 minutes per device, with one notable exception: Catalyst 3750-X took no less than 40 minutes in testing.
  • Expect devices to take between 10 and 30 minutes to come back after reload, especially if upgrading trains or major versions, due to microcode updates.
  • The automated install commands (archive download-sw and request platform software package install) download the upgrade package twice, for reasons I did not determine.
  • FTP and HTTP seem to be the fastest transfer methods. Even then, the download appears constrained by platform CPU resources, averaging about 4Mbps in most tests, while some newer platforms achieved 20Mbps.
  • The iosfw class exposes all of NAPALM's config parameters, and stores the NAPALM session under self.napalm, so you can use all of NAPALM's features easily.
  • Same goes for netmiko - stored as self.device - so you can send arbitrary commands with iosfw.device.send_command('my arbitrary command')

About

Automatic Cisco IOS firmware upgrades

Resources

Stars

89 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

iosfw

Automatic Cisco IOS firmware upgrades

Code style: black

Requires:

Overview

Automates the entire upgrade process:

  • Determines correct upgrade image for each platform
  • Transfer the new image
  • Verify image integrity
  • Extract archive and install
  • Optionally remove old image(s)
  • Set boot parameters
  • Schedule reload

Auto-detects best upgrade method available:

  • archive download-sw
  • software install
  • request platform software package install
  • If those fail, plain copy followed by set boot ...

Supported platforms:

  • Catalyst 3550
  • Catalyst 3560
  • Catalyst 3560-X
  • Catalyst 3750
  • Catalyst 3750-X
  • Catalyst 2960-S
  • Catalyst 2960-X
  • Catalyst 3650
  • Catalyst 3850
  • ISR 2921
  • ISR 4331
  • C892FSP
  • ME3400

Experimentally supported platforms:

  • ASR920
  • Catalyst 9k series

Currently unsupported platforms:

  • Nexus 3k/9k series

NOTE: Use at your own risk. It works well in my environment, but serious bugs are possible. Test thoroughly in a lab environment, and see known issues below.

Usage

Preparation

  1. Rename config/config.yaml.example to config.yaml, and review config/images.yaml, matching both to your requirements. Defaults are sane, but don't take any chances :)
  2. Copy your IOS images defined in images.yaml to the src_image_path defined in config.yaml.

Note: Pay special attention if you have devices of the same model, but need different IOS images (e.g., ipbase vs ipservices). In that case, define both images in images.yaml and add the same model to their respective models lists. Then, change match_feature_set to true in config.yaml.

Interactive Example

>>> from iosfw import iosfw
>>> device = iosfw('ios-sw-1')
>>> device.open()
Username [austindcc]:
Password:
Enable secret:
Opening connection to ios-sw-1...
Connected to ios-sw-1 (WS-C3560X-48P) as austind via ssh
Running version: 12.2(55)SE8
Upgrade version: 15.2(4)E8
Upgrade status: NEEDS UPGRADE
>>> device.upgrade()
Starting upgrade on ios-sw-1 at 14:34:09 06/13/19...
Checking free space...
Found enough free space!
Installing new firmware...
NOTE: No status updates possible during install, which may take 10 minutes or longer.
Install successful!
Removing running image...
Deleting flash:/c3560e-universalk9-mz.122-55.SE8...
Running image deleted.
Scheduling reload...
Reload scheduled for 00:00:00 PDT Fri Jun 14 2019 (9 hours and 16 minutes away)
Upgrade on ios-sw-1 completed at 14:43:32 06/13/19
Total time elapsed: 0:09:23.224298

Automated Example

See example/batch_example.py

Known issues

  • Only supports BUNDLE mode on cat9k. As of 2021-06-16, INSTALL mode reloads the device immediately, with no option to delay reload for image activation. This is not only inconvenient, but also complicates iosfw's state awareness.
  • As of 0.9.0, SCP image transfer directly from iosfw no longer works. I recommend setting up an FTP server on a separate host and setting config.yaml accordingly.
  • Catalyst 3k series (3650 and 3850) with IOS running in BUNDLE mode (booted directly to the .bin file), will not succeed in upgrading with request platform software package install. Upgrading them requires a different manual process that is not yet implemented:
    • Remove existing IOS packages: del /force flash:/cat*.pkg
    • Remove existing packages.conf: del /force flash:/packages.conf
    • Remove boot variables: no boot system in config mode
    • Copy upgrade image: copy <source> flash:
    • Install upgrade image: request platform software package expand switch all file flash:/<file>
    • Set boot variable: boot system flash:/<file>
    • Schedule reload: reload at 00:00
  • Currently, iosfw does not check to ensure transfer_source is reachable. If not reachable, the install command will fail, but not timeout for more than 30 minutes. Most commonly, transfer_source may not be reachable due to sending the requests out the incorrect interface. You can specify the source interface for TFTP and FTP transfers with ip (ftp|tftp) source-interface <iface> in config mode.
  • When using SSH proxy, iosfw throws a ProcessLookupError on exit. I have not found a way to catch or suppress this.
  • When remove_old_images is set to always on platforms using request software... install method, iosfw may incorrectly remove the newly installed image files. Net result is no change to system. Workaround: use remove_old_images = as_needed.
  • Totally untested on stacks.

Wishlist

  • Nornir integration
  • Fix native SCP image transfer option (broken as of 0.9.0)
  • Accept a pre-existing napalm connection object
  • Verify reachability of transfer_source, attempting fix as needed
  • More consistent debug output
  • N3K/N9K support

Contributions welcome.

Changelog

See CHANGELOG.md

Notes

  • Expect most upgrades to take 8-10 minutes per device, with one notable exception: Catalyst 3750-X took no less than 40 minutes in testing.
  • Expect devices to take between 10 and 30 minutes to come back after reload, especially if upgrading trains or major versions, due to microcode updates.
  • The automated install commands (archive download-sw and request platform software package install) download the upgrade package twice, for reasons I did not determine.
  • FTP and HTTP seem to be the fastest transfer methods. Even then, the download appears constrained by platform CPU resources, averaging about 4Mbps in most tests, while some newer platforms achieved 20Mbps.
  • The iosfw class exposes all of NAPALM's config parameters, and stores the NAPALM session under self.napalm, so you can use all of NAPALM's features easily.
  • Same goes for netmiko - stored as self.device - so you can send arbitrary commands with iosfw.device.send_command('my arbitrary command')

About

Automatic Cisco IOS firmware upgrades

Resources

Stars

89 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

iosfw

Automatic Cisco IOS firmware upgrades

Code style: black

Requires:

Overview

Automates the entire upgrade process:

  • Determines correct upgrade image for each platform
  • Transfer the new image
  • Verify image integrity
  • Extract archive and install
  • Optionally remove old image(s)
  • Set boot parameters
  • Schedule reload

Auto-detects best upgrade method available:

  • archive download-sw
  • software install
  • request platform software package install
  • If those fail, plain copy followed by set boot ...

Supported platforms:

  • Catalyst 3550
  • Catalyst 3560
  • Catalyst 3560-X
  • Catalyst 3750
  • Catalyst 3750-X
  • Catalyst 2960-S
  • Catalyst 2960-X
  • Catalyst 3650
  • Catalyst 3850
  • ISR 2921
  • ISR 4331
  • C892FSP
  • ME3400

Experimentally supported platforms:

  • ASR920
  • Catalyst 9k series

Currently unsupported platforms:

  • Nexus 3k/9k series

NOTE: Use at your own risk. It works well in my environment, but serious bugs are possible. Test thoroughly in a lab environment, and see known issues below.

Usage

Preparation

  1. Rename config/config.yaml.example to config.yaml, and review config/images.yaml, matching both to your requirements. Defaults are sane, but don't take any chances :)
  2. Copy your IOS images defined in images.yaml to the src_image_path defined in config.yaml.

Note: Pay special attention if you have devices of the same model, but need different IOS images (e.g., ipbase vs ipservices). In that case, define both images in images.yaml and add the same model to their respective models lists. Then, change match_feature_set to true in config.yaml.

Interactive Example

>>> from iosfw import iosfw
>>> device = iosfw('ios-sw-1')
>>> device.open()
Username [austindcc]:
Password:
Enable secret:
Opening connection to ios-sw-1...
Connected to ios-sw-1 (WS-C3560X-48P) as austind via ssh
Running version: 12.2(55)SE8
Upgrade version: 15.2(4)E8
Upgrade status: NEEDS UPGRADE
>>> device.upgrade()
Starting upgrade on ios-sw-1 at 14:34:09 06/13/19...
Checking free space...
Found enough free space!
Installing new firmware...
NOTE: No status updates possible during install, which may take 10 minutes or longer.
Install successful!
Removing running image...
Deleting flash:/c3560e-universalk9-mz.122-55.SE8...
Running image deleted.
Scheduling reload...
Reload scheduled for 00:00:00 PDT Fri Jun 14 2019 (9 hours and 16 minutes away)
Upgrade on ios-sw-1 completed at 14:43:32 06/13/19
Total time elapsed: 0:09:23.224298

Automated Example

See example/batch_example.py

Known issues

  • Only supports BUNDLE mode on cat9k. As of 2021-06-16, INSTALL mode reloads the device immediately, with no option to delay reload for image activation. This is not only inconvenient, but also complicates iosfw's state awareness.
  • As of 0.9.0, SCP image transfer directly from iosfw no longer works. I recommend setting up an FTP server on a separate host and setting config.yaml accordingly.
  • Catalyst 3k series (3650 and 3850) with IOS running in BUNDLE mode (booted directly to the .bin file), will not succeed in upgrading with request platform software package install. Upgrading them requires a different manual process that is not yet implemented:
    • Remove existing IOS packages: del /force flash:/cat*.pkg
    • Remove existing packages.conf: del /force flash:/packages.conf
    • Remove boot variables: no boot system in config mode
    • Copy upgrade image: copy <source> flash:
    • Install upgrade image: request platform software package expand switch all file flash:/<file>
    • Set boot variable: boot system flash:/<file>
    • Schedule reload: reload at 00:00
  • Currently, iosfw does not check to ensure transfer_source is reachable. If not reachable, the install command will fail, but not timeout for more than 30 minutes. Most commonly, transfer_source may not be reachable due to sending the requests out the incorrect interface. You can specify the source interface for TFTP and FTP transfers with ip (ftp|tftp) source-interface <iface> in config mode.
  • When using SSH proxy, iosfw throws a ProcessLookupError on exit. I have not found a way to catch or suppress this.
  • When remove_old_images is set to always on platforms using request software... install method, iosfw may incorrectly remove the newly installed image files. Net result is no change to system. Workaround: use remove_old_images = as_needed.
  • Totally untested on stacks.

Wishlist

  • Nornir integration
  • Fix native SCP image transfer option (broken as of 0.9.0)
  • Accept a pre-existing napalm connection object
  • Verify reachability of transfer_source, attempting fix as needed
  • More consistent debug output
  • N3K/N9K support

Contributions welcome.

Changelog

See CHANGELOG.md

Notes

  • Expect most upgrades to take 8-10 minutes per device, with one notable exception: Catalyst 3750-X took no less than 40 minutes in testing.
  • Expect devices to take between 10 and 30 minutes to come back after reload, especially if upgrading trains or major versions, due to microcode updates.
  • The automated install commands (archive download-sw and request platform software package install) download the upgrade package twice, for reasons I did not determine.
  • FTP and HTTP seem to be the fastest transfer methods. Even then, the download appears constrained by platform CPU resources, averaging about 4Mbps in most tests, while some newer platforms achieved 20Mbps.
  • The iosfw class exposes all of NAPALM's config parameters, and stores the NAPALM session under self.napalm, so you can use all of NAPALM's features easily.
  • Same goes for netmiko - stored as self.device - so you can send arbitrary commands with iosfw.device.send_command('my arbitrary command')

About

Automatic Cisco IOS firmware upgrades

Resources

Stars

89 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

iosfw

Automatic Cisco IOS firmware upgrades

Code style: black

Requires:

Overview

Automates the entire upgrade process:

  • Determines correct upgrade image for each platform
  • Transfer the new image
  • Verify image integrity
  • Extract archive and install
  • Optionally remove old image(s)
  • Set boot parameters
  • Schedule reload

Auto-detects best upgrade method available:

  • archive download-sw
  • software install
  • request platform software package install
  • If those fail, plain copy followed by set boot ...

Supported platforms:

  • Catalyst 3550
  • Catalyst 3560
  • Catalyst 3560-X
  • Catalyst 3750
  • Catalyst 3750-X
  • Catalyst 2960-S
  • Catalyst 2960-X
  • Catalyst 3650
  • Catalyst 3850
  • ISR 2921
  • ISR 4331
  • C892FSP
  • ME3400

Experimentally supported platforms:

  • ASR920
  • Catalyst 9k series

Currently unsupported platforms:

  • Nexus 3k/9k series

NOTE: Use at your own risk. It works well in my environment, but serious bugs are possible. Test thoroughly in a lab environment, and see known issues below.

Usage

Preparation

  1. Rename config/config.yaml.example to config.yaml, and review config/images.yaml, matching both to your requirements. Defaults are sane, but don't take any chances :)
  2. Copy your IOS images defined in images.yaml to the src_image_path defined in config.yaml.

Note: Pay special attention if you have devices of the same model, but need different IOS images (e.g., ipbase vs ipservices). In that case, define both images in images.yaml and add the same model to their respective models lists. Then, change match_feature_set to true in config.yaml.

Interactive Example

>>> from iosfw import iosfw
>>> device = iosfw('ios-sw-1')
>>> device.open()
Username [austindcc]:
Password:
Enable secret:
Opening connection to ios-sw-1...
Connected to ios-sw-1 (WS-C3560X-48P) as austind via ssh
Running version: 12.2(55)SE8
Upgrade version: 15.2(4)E8
Upgrade status: NEEDS UPGRADE
>>> device.upgrade()
Starting upgrade on ios-sw-1 at 14:34:09 06/13/19...
Checking free space...
Found enough free space!
Installing new firmware...
NOTE: No status updates possible during install, which may take 10 minutes or longer.
Install successful!
Removing running image...
Deleting flash:/c3560e-universalk9-mz.122-55.SE8...
Running image deleted.
Scheduling reload...
Reload scheduled for 00:00:00 PDT Fri Jun 14 2019 (9 hours and 16 minutes away)
Upgrade on ios-sw-1 completed at 14:43:32 06/13/19
Total time elapsed: 0:09:23.224298

Automated Example

See example/batch_example.py

Known issues

  • Only supports BUNDLE mode on cat9k. As of 2021-06-16, INSTALL mode reloads the device immediately, with no option to delay reload for image activation. This is not only inconvenient, but also complicates iosfw's state awareness.
  • As of 0.9.0, SCP image transfer directly from iosfw no longer works. I recommend setting up an FTP server on a separate host and setting config.yaml accordingly.
  • Catalyst 3k series (3650 and 3850) with IOS running in BUNDLE mode (booted directly to the .bin file), will not succeed in upgrading with request platform software package install. Upgrading them requires a different manual process that is not yet implemented:
    • Remove existing IOS packages: del /force flash:/cat*.pkg
    • Remove existing packages.conf: del /force flash:/packages.conf
    • Remove boot variables: no boot system in config mode
    • Copy upgrade image: copy <source> flash:
    • Install upgrade image: request platform software package expand switch all file flash:/<file>
    • Set boot variable: boot system flash:/<file>
    • Schedule reload: reload at 00:00
  • Currently, iosfw does not check to ensure transfer_source is reachable. If not reachable, the install command will fail, but not timeout for more than 30 minutes. Most commonly, transfer_source may not be reachable due to sending the requests out the incorrect interface. You can specify the source interface for TFTP and FTP transfers with ip (ftp|tftp) source-interface <iface> in config mode.
  • When using SSH proxy, iosfw throws a ProcessLookupError on exit. I have not found a way to catch or suppress this.
  • When remove_old_images is set to always on platforms using request software... install method, iosfw may incorrectly remove the newly installed image files. Net result is no change to system. Workaround: use remove_old_images = as_needed.
  • Totally untested on stacks.

Wishlist

  • Nornir integration
  • Fix native SCP image transfer option (broken as of 0.9.0)
  • Accept a pre-existing napalm connection object
  • Verify reachability of transfer_source, attempting fix as needed
  • More consistent debug output
  • N3K/N9K support

Contributions welcome.

Changelog

See CHANGELOG.md

Notes

  • Expect most upgrades to take 8-10 minutes per device, with one notable exception: Catalyst 3750-X took no less than 40 minutes in testing.
  • Expect devices to take between 10 and 30 minutes to come back after reload, especially if upgrading trains or major versions, due to microcode updates.
  • The automated install commands (archive download-sw and request platform software package install) download the upgrade package twice, for reasons I did not determine.
  • FTP and HTTP seem to be the fastest transfer methods. Even then, the download appears constrained by platform CPU resources, averaging about 4Mbps in most tests, while some newer platforms achieved 20Mbps.
  • The iosfw class exposes all of NAPALM's config parameters, and stores the NAPALM session under self.napalm, so you can use all of NAPALM's features easily.
  • Same goes for netmiko - stored as self.device - so you can send arbitrary commands with iosfw.device.send_command('my arbitrary command')

About

Automatic Cisco IOS firmware upgrades

Resources

Stars

89 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

iosfw

Automatic Cisco IOS firmware upgrades

Code style: black

Requires:

Overview

Automates the entire upgrade process:

  • Determines correct upgrade image for each platform
  • Transfer the new image
  • Verify image integrity
  • Extract archive and install
  • Optionally remove old image(s)
  • Set boot parameters
  • Schedule reload

Auto-detects best upgrade method available:

  • archive download-sw
  • software install
  • request platform software package install
  • If those fail, plain copy followed by set boot ...

Supported platforms:

  • Catalyst 3550
  • Catalyst 3560
  • Catalyst 3560-X
  • Catalyst 3750
  • Catalyst 3750-X
  • Catalyst 2960-S
  • Catalyst 2960-X
  • Catalyst 3650
  • Catalyst 3850
  • ISR 2921
  • ISR 4331
  • C892FSP
  • ME3400

Experimentally supported platforms:

  • ASR920
  • Catalyst 9k series

Currently unsupported platforms:

  • Nexus 3k/9k series

NOTE: Use at your own risk. It works well in my environment, but serious bugs are possible. Test thoroughly in a lab environment, and see known issues below.

Usage

Preparation

  1. Rename config/config.yaml.example to config.yaml, and review config/images.yaml, matching both to your requirements. Defaults are sane, but don't take any chances :)
  2. Copy your IOS images defined in images.yaml to the src_image_path defined in config.yaml.

Note: Pay special attention if you have devices of the same model, but need different IOS images (e.g., ipbase vs ipservices). In that case, define both images in images.yaml and add the same model to their respective models lists. Then, change match_feature_set to true in config.yaml.

Interactive Example

>>> from iosfw import iosfw
>>> device = iosfw('ios-sw-1')
>>> device.open()
Username [austindcc]:
Password:
Enable secret:
Opening connection to ios-sw-1...
Connected to ios-sw-1 (WS-C3560X-48P) as austind via ssh
Running version: 12.2(55)SE8
Upgrade version: 15.2(4)E8
Upgrade status: NEEDS UPGRADE
>>> device.upgrade()
Starting upgrade on ios-sw-1 at 14:34:09 06/13/19...
Checking free space...
Found enough free space!
Installing new firmware...
NOTE: No status updates possible during install, which may take 10 minutes or longer.
Install successful!
Removing running image...
Deleting flash:/c3560e-universalk9-mz.122-55.SE8...
Running image deleted.
Scheduling reload...
Reload scheduled for 00:00:00 PDT Fri Jun 14 2019 (9 hours and 16 minutes away)
Upgrade on ios-sw-1 completed at 14:43:32 06/13/19
Total time elapsed: 0:09:23.224298

Automated Example

See example/batch_example.py

Known issues

  • Only supports BUNDLE mode on cat9k. As of 2021-06-16, INSTALL mode reloads the device immediately, with no option to delay reload for image activation. This is not only inconvenient, but also complicates iosfw's state awareness.
  • As of 0.9.0, SCP image transfer directly from iosfw no longer works. I recommend setting up an FTP server on a separate host and setting config.yaml accordingly.
  • Catalyst 3k series (3650 and 3850) with IOS running in BUNDLE mode (booted directly to the .bin file), will not succeed in upgrading with request platform software package install. Upgrading them requires a different manual process that is not yet implemented:
    • Remove existing IOS packages: del /force flash:/cat*.pkg
    • Remove existing packages.conf: del /force flash:/packages.conf
    • Remove boot variables: no boot system in config mode
    • Copy upgrade image: copy <source> flash:
    • Install upgrade image: request platform software package expand switch all file flash:/<file>
    • Set boot variable: boot system flash:/<file>
    • Schedule reload: reload at 00:00
  • Currently, iosfw does not check to ensure transfer_source is reachable. If not reachable, the install command will fail, but not timeout for more than 30 minutes. Most commonly, transfer_source may not be reachable due to sending the requests out the incorrect interface. You can specify the source interface for TFTP and FTP transfers with ip (ftp|tftp) source-interface <iface> in config mode.
  • When using SSH proxy, iosfw throws a ProcessLookupError on exit. I have not found a way to catch or suppress this.
  • When remove_old_images is set to always on platforms using request software... install method, iosfw may incorrectly remove the newly installed image files. Net result is no change to system. Workaround: use remove_old_images = as_needed.
  • Totally untested on stacks.

Wishlist

  • Nornir integration
  • Fix native SCP image transfer option (broken as of 0.9.0)
  • Accept a pre-existing napalm connection object
  • Verify reachability of transfer_source, attempting fix as needed
  • More consistent debug output
  • N3K/N9K support

Contributions welcome.

Changelog

See CHANGELOG.md

Notes

  • Expect most upgrades to take 8-10 minutes per device, with one notable exception: Catalyst 3750-X took no less than 40 minutes in testing.
  • Expect devices to take between 10 and 30 minutes to come back after reload, especially if upgrading trains or major versions, due to microcode updates.
  • The automated install commands (archive download-sw and request platform software package install) download the upgrade package twice, for reasons I did not determine.
  • FTP and HTTP seem to be the fastest transfer methods. Even then, the download appears constrained by platform CPU resources, averaging about 4Mbps in most tests, while some newer platforms achieved 20Mbps.
  • The iosfw class exposes all of NAPALM's config parameters, and stores the NAPALM session under self.napalm, so you can use all of NAPALM's features easily.
  • Same goes for netmiko - stored as self.device - so you can send arbitrary commands with iosfw.device.send_command('my arbitrary command')

About

Automatic Cisco IOS firmware upgrades

Resources

Stars

89 stars

Watchers

7 watching

Forks

Releases

Packages

Used by

Contributors

Languages