General considerations
• MACsec in FastIron 08.0.20a and later releases is not compatible with previous versions of the
MACsec feature due to changes in CLI functionality. An upgrade is required.
• The erase startup-config command erases all startup configuration files (startup-config.txt and
also the backup files).
• FSX devices with FastIron 08.0.xx installed, as well as all ICX 6430 and ICX 6450 devices, support
only one configured system boot preference.
• In an FSX device, using an SX Series 0-Port Third Generation XL management module together
with an SX Series 2-Port 10GbE Third Generation XL management module is not supported.
• On an FSX device with the SX Series 0-Port Third Generation XL management module, a hitless
upgrade from FastIron 08.0.00a or 08.0.01 to 08.0.10 is not supported.
• For ICX 6430 devices, the system-max mac-filter-sys parameter value changed from 512 to 508
in FastIron 08.0.xx. If the current value of system-max mac-filter-sys is more than 508, you should
change this value to 508 before upgrading. Otherwise, during upgrade, its value will be set to the
default value of 64.
• To use a FastIron 07.x.xx configuration on a device upgraded to a FastIron 08.0.xx image, replacing
the running configuration with the FastIron 07.x.xx configuration is not supported. Instead, you must
copy the FastIron 07.x.xx configuration onto the startup configuration file and reload the device.
Deprecated or removed features and commands
• SNTP is no longer supported. NTPv4 replaces SNTP.
• The stack persistent-mac-timer command is deprecated in FastIron 08.0.20.
• The Port Speed Down-Shift feature is deprecated in FastIron 08.0.xx.
• The link-config gig copper autoneg-control down-shift ethernet command is deprecated.
• The show cpu-utilization command replaces the show process cpu command.
Flash memory capacity
Consider the following limitations of different devices when upgrading software:
• All FastIron devices except ICX 6430 devices can hold two Layer 2 or Layer 3 images (for example,
ICX64S08030.bin for Layer 2 and ICX64R08030.bin for Layer 3).
• ICX 6430 devices can hold only two Layer 2 images.
Security
• SSHv2 RSA host key format differs between FastIron 07.x.xx and 08.0.xx software versions.
• When you upgrade from FastIron 07.x.xx or 08.0.00 to a FastIron 08.0.xx software version, if an
RSA key is present in the FastIron 07.x.xx or 08.0.00 software version, the same size key is
regenerated in the FastIron 08.0.xx software version. The old SSHv2 host key is also retained. Old
keys can be cleared using the crypto key zeroize command.
• SSH host keys created with the DSA method are interoperable with FastIron 07.x.xx, 08.0.00, and
08.0.xx software versions.
• By default, the RADIUS server key encryption type is 2 (simple_encryption_base64) in FastIron
08.0.xx. This is in contrast to earlier releases, where the default value for simple_encryption is 1. If
you do not follow the upgrade procedure, the RADIUS server key configuration is removed during
downgrade.
General considerations
14 FastIron Ethernet Switch Software Upgrade Guide
53-1003632-02