Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
Expand all | Collapse all

SSG5 with startup problems

  • 1.  SSG5 with startup problems

    Posted 06-30-2009 02:14

    Got a demo SSG5 back from customer, and now have a problem resetting it. When I start it up it runs thru some config then halts. Have tried the reset button that won’t work. Anyone that got any good idée’s how to resolve this. Here is a picture of the consol:

    Juniper Networks, Inc
    SSG5/SSG20 System Software
    Copyright, 1997-2008

    Version 6.2.0r2.0
    Load Manufacture Information ... Done

    Initialize FBTL 0........ Done
    Load NVRAM Information ... (6.2.0)Done
    Install module init vectors
    Install modules (01124800,0209ef70) ...
    PPP IP-POOL initiated, 256 pools

    Initializing DI 1.1.0-ns
    w3g_cfg_init

    System config (1178 bytes) loaded

    Done.
    Load System Configuration .
    Unsupported command - Config for SSG router /Ventelo2
    ....
    Unsupported command - unset interface wireless0/0 dhcp server service
    .
    Unsupported command - unset interface bgroup0 dhcp server service
    .
    Unsupported command - unset interface adsl1/0 dhcp server service
    .
    Unsupported command - unset interface wireless0/0 ip
    .
    Unsupported command - unset interface adsl1/0 ip
    ...
    Unsupported command - unset interface bgroup0 port ethernet0/2
    .
    Unsupported command - unset interface bgroup0 port ethernet0/3
    .
    Unsupported command - unset interface bgroup0 port ethernet0/4
    .
    Unsupported command - unset interface bgroup0 port ethernet0/5
    .
    Unsupported command - unset interface bgroup0 port ethernet0/6
    ...
    Unsupported command - unset interface adsl1/0 zone
    .
    Unsupported command - unset interface wireless0/0 zone
    ..
    Unsupported command - set ssh enable
    ..
    Unsupported command - ----  Support diagnostic tunnel ----
    ..
    Failed command - unset admin user "rsgadm"
    ...........
     

    (Here is where its halts and I can't get into console)

    Message Edited by Bjarne on 30-06-2009 11:14 AM


  • 2.  RE: SSG5 with startup problems

    Posted 06-30-2009 07:40

    yup i  have seen that kind of error before. you can try to downgrade the screenOS to 6.06 and see if that helps.

    It may or may not work as the configuration is already corrupted.

     

    If that doesnt work, you can open a jtac case. we have specific patch which can ignore the config and allow the box to boot in this kind of situation.



  • 3.  RE: SSG5 with startup problems

    Posted 07-01-2009 02:16
    Thank you WL. I tried to downgrade it to 6.0.0r6 but I did not resolve the problem. Ill open a jtac case and get the patch.


  • 4.  RE: SSG5 with startup problems

    Posted 08-05-2009 15:17

    Is that patch available anywhere else? My SSG-5 is out of support/warranty?

     

    "If that doesnt work, you can open a jtac case. we have specific patch which can ignore the config and allow the box to boot in this kind of situation."



  • 5.  RE: SSG5 with startup problems

    Posted 08-05-2009 15:27
      |   view attached
    You can try and do a hardware reset of the device. Attached is a description of how to do this from the pinhole button.

    Attachment(s)

    zip
    ResetSSG5.zip   996 B 1 version


  • 6.  RE: SSG5 with startup problems

    Posted 08-05-2009 15:36

    Hey,

    Thanks for the reply. I tried reseting both via pin-reset & console, upgrades/downgrades. The issue seems to be the corrupt config, causing it to hang during the boot process.  Exactly what's described in the orignal post.

     

    I guess I'll have to buy a new one... oh well 🙂

     

    Thanks, -Jay



  • 7.  RE: SSG5 with startup problems

    Posted 08-17-2009 00:35
    I have tried every trick in the book now. Nothing works. My solution was to get a HW replacement from Juniper.
    Thank you all for your replays.


  • 8.  RE: SSG5 with startup problems
    Best Answer

    Posted 08-23-2009 13:19

    Hi,

     

    I had the same issue tonight with a SSG-20 that was running 6.20r3.

    I uploaded a new config that included some new commands supported in 6.20r3, the unit rebooted but never came back online (I was working remotely via VPN).

     

    Anyway once onsite I established a console connection via serial port and found the SSG-20 had booted properly through the boot loader, it had loaded the software image from flash and loaded the software image into memory all without issue.

    When it started loading the configuration I found I had the same issue as you where it would freeze there and no continue loading the configuration, bringing up the interfaces etc...

     

    In short I could not even ping a network interface.  I could not use the console to login using the serial number to reset the configuration to factory default as the console was locked trying to load the corrupt configuration and stayed unresponsive.

    I tried holding down the reset button (4-6 sec down) but the status light would not go orange (but the power light did).

     

    In short none of the methods would work to reset the configuration to factory default and I could not load the SSG-20 up to fix the configuration as the configuration it had was corrupt.

     

    The fix was this

    1) I conencted a PC directly to the SSG-20 network interface ethernet0/4 (its a Trust interface by default in my config and factory default).  Normally this interface is connected to a internal switch but to increase the chance of success I patched the PC directly to the port

    2) I downloaded ScreenOS 6.1.0r6 for the SSG-20 to the PC, checked the MD5 and extracted the file to C:\Temp

    3) I disabled all AV and firewalls on the PC

    4) I started a TFTP server (daemon) on the PC and shared the C:\Temp folder that contained .  I use TFTPD32 from http://tftpd32.jounin.net

    5) I disabled the DHCP server thats in TFTPD32 by default

    6) I connected to the SSG-20 using a console cable connected to COM1 using 9600 baud

    7) I rebooted the SSG-20 (by pulling the power cable)

    😎 As the boot loader was loading it prompts you to press a key to break out of the automatic load

    Hit any key to run loader

     

     9) Press a key, you should now be prompted for the boot file name.  Enter the name of the firmware file you extracted to C:\Temp in step 2).  In my case ssg5ssg20.6.1.0r6.0

    10) You should now be prompted for the IP address to give the SSG-20, I entered the IP the trust interface normally had

    11) Next you are prompted for the IP address of your TFTP server (the IP address or the PC running TFTPD32)

    12) Now it should say Loading file ssg5ssg20.6.1.0r6.0, this is it download the firmware from the TFTP server.  It writes a series of "at" characters to the console

    13)  It should then say Load successful and tell you the size of the file it TFTP'ed

    14) It will then say Ignore image authentication!

    15) It will ask you if you want to save the new firmware to the on-board flash disk, say yes (y).  It will count up in percent as it does this

    16) Once thats done it will ask you if you want to run the downloaded system image, say yes (y)

    17) It should now load properly.  Being an old version of ScreenOS it did not support a lot of the commands in the config it had but at least I now had a working device

     

    The theroy here is to load a older, more robust firmware that could handle the corrupt configuration (in fact it basically just ignored any part of the configuration it could not understand).

     

    I was then able to factory reset it (I used the method of logging in at the console using the serial number of the SSG-20 as the username and password.

    Once that had rebooted, I then uploaded the my config

    Once that had rebooted I then upgraded the  the firmware to 6.2.0r3 again

    Once that had rebooted I loaded my final configuration again, this time it understood everything being the correct version of ScreenOS

     

    I know had by SSG-20 working normally again, running the ScreenOS it was running before and with a full working copy of my configuration instead of a corrupt copy

     

    Hope this helps someone

     

    MC

     



  • 9.  RE: SSG5 with startup problems

    Posted 07-01-2009 15:04
    You can also use the serial number as user and password before getting into that state. This will change the box to factory default configuration.


  • 10.  RE: SSG5 with startup problems

    Posted 07-02-2009 18:08

    Agreed - It looks like there is a corrupted configuration in the flash. The best bet at this point is to perform a complete reset:

     

    1. Attach the console Cable to the SSG5 and start the terminal application
    2. Choose the correct Port (COM1 or COM2) and set the bitrate to 9600
    3. Plug in the power of the SSG5 and start the firewall
    4. After it has booted up you’re at the login prompt where you put in the device’s serial number as username and again as password.
    5. The device ask you for a reset twice. Say “y” and that’s it.

     

    Another option is to run though a tftpboot via the bootloader reinstall of screenOS.



  • 11.  RE: SSG5 with startup problems

    Posted 07-03-2009 00:16

     Thank you for the suggestions. I already tried to do this. Problem is that I can’t get to the logon part,
    cause after the Failed command - unset admin user "rsgadm"  the box locks up… can’t do anything.
    I does not help to press the reset button, nothing happen.



  • 12.  RE: SSG5 with startup problems

    Posted 08-23-2009 23:40
    Great thanks JustMike for an extensive and good method for getting around this problem. I did the same as what you did, but I uploaded only newer builds and special versions. If I experience this problem again I will make sure to try and older version as per your guide.