Description

This article outlines a minimal downtime upgrade procedure for an SRX5000 Series chassis cluster.
The process upgrades one node at a time, shifts traffic to the upgraded node, and then upgrades the second node before restoring the cluster.

Symptoms

This is an informational KB.

Use this procedure when:

  • An SRX5k chassis cluster needs to be upgraded with minimal service interruption
  • A staged node-by-node upgrade is preferred
  • You want to validate traffic on the upgraded node before upgrading the peer node

Solution

  • Perform the upgrade during a planned maintenance window using the steps below:

    1. Perform a health check of the cluster and confirm all redundancy groups are stable.
    2. Isolate the cluster nodes by:
      • Deleting the fabric interface configuration
      • Changing the control interface configuration to unused or non-existent ports
    3. Upgrade Node 1 and confirm the upgrade completes successfully.
    4. Shift traffic from Node 0 to Node 1.
    5. Validate that applications and traffic are working normally through Node 1 on the upgraded firmware.
    6. Upgrade Node 0 and confirm the upgrade completes successfully.
    7. Halt Node 0 and add it back into the cluster.
    8. Perform a post-upgrade health check and confirm the cluster is operating normally.

    Summary

    A minimal downtime SRX5k cluster upgrade can be completed by isolating the nodes, upgrading one node first, validating live traffic on the upgraded node, and then upgrading and rejoining the second node.

Modification History

2024-09-11 : Article Created