Required Intermediate Firmware Upgrade for Controller-Managed APs running version earlier than V7.10

Options
Zyxel_Bella
Zyxel_Bella Posts: 569 image  Zyxel Employee
Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch 50 Answers
edited July 8 in WirelessLAN New Release

To enhance system security and maintain firmware integrity, Zyxel introduced changes to the AP firmware encryption mechanism in 7.10 version.

Therefore, administrators should first upgrade the AP to firmware 7.10 baseline version before upgrading to the latest firmware version to ensure compatibility with the latest encryption design.

Note: Models already running 7.10 based version or newer will not be affected

For controller-managed APs running firmware earlier than 7.10, please change the AP firmware upgrade source to 7.10 first. After the AP is upgraded to 7.10, change the firmware source back to the official release path, and then upgrade the AP to the latest firmware.

The steps to upgrade firmware for controller-managed APs:

Step 1: SSH to the controller to change the download firmware version of access point by entering the commands based on different platform.

  • ATP/USG FLEX platform

Router> configure terminal

Router(config)# capwap firmware-update source 7.10(.1)

  • USG FLEX H Series platform

usgflex100h> cmd apc firmware-update source 7.10(.1)

Step 2: Upgrade APs to 7.10 version

Go to the AP Firmware Page on controller GUI > Click Check then click Renew Firmware. Please wait around 3 minutes for the controller to download and prepare the AP firmware.

Go to the AP List page and upgrade the AP firmware to 7.10, wait for the AP to complete the upgrade and reconnect to the controller.

Step 3: change the download firmware version of access point back to latest official version.

  • ATP/USG platform

Router> configure terminal

Router(config)# capwap firmware-update source official

  • USG H Series platform

usgflex100h> cmd apc firmware-update source official

Step 4: Upgrade APs to latest official firmware version as same steps as Step 2.

Thank you for your understanding and cooperation as we continue improving the platform’s reliability and security.


Ref: SSH Security Enhancements in Zyxel APs (Firmware 7.10)