Upgrading the SAC Signature File
Context
- Online upgrade
- If the device can access the security center platform, you can upgrade the signature file through the security center platform.
- If the device cannot access the security center platform, you can upgrade the signature file through the internal upgrade server.
- Ensure that the internal upgrade server can normally access the security center platform.
- Ensure that there are reachable routes between the device and the internal upgrade server.
Local upgrade
When the device cannot be connected to the security center platform through a network, you can log in to the security center platform to download the upgrade package, and then upload the signature file to the device through FTP or TFTP, to upgrade the SAC signature file.
After the SAC signature file is upgraded, the new SAC signature file may adjust categories of application groups and application protocols. If there is the configuration based on the application group on the device, some services may be unavailable. You can run the display sa category command to check categories in the new signature file and run the display application command to check information about applications. Then you can adjust the configuration.
Procedure
- Perform an online upgrade.
- Terminate the upgrade.
After the upgrade is started, if many network resources are occupied, you can terminate the upgrade.
The update can be terminated only during file downloading.
Run system-view
The system view is displayed.
Run update abort
The upgrade is terminated.
- Perform a version rollback.
If an error occurs after the upgrade or the new SAC signature file does not meet requirements, use this command to roll back the version of the SAC signature file.
Before the version rollback, you are advised to run the display version sa-sdb command to check the rollback version. Then you can choose whether to perform the version rollback. If no rollback version is available, the version rollback fails. The version in the device remains unchanged.
Run system-view
The system view is displayed.
Run update rollback sa-sdb
The SAC signature file version is rolled back.
- Perform a local upgrade.
Run system-view
The system view is displayed.
Run update local sa-sdb file filename
The SAC signature file is upgraded locally.
Terminate upgrade are not supported in the local upgrade.
- Restore the version.
If the signature file is restored to the factory default version, all other versions on the device are deleted.
Run system-view
The system view is displayed.
Run update restore sdb-default sa-sdb
The SAC signature file is restored to the factory default version.