Dell EMC Unity: Code upgrade failed due to switch port security set (Dell EMC Correctable)
Summary: Code upgrade failed due to HA service cannot fail over to first upgraded SP, because the management port
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
Code upgrade fails, the first SP finishes rebooting, but cannot take over cf_ha service. HA services are bouncing between two SPs.
For example in a case, SPA is at old version, SPB is upgraded to a new version.
1. By checking SPB_upgrade.log, it failed at waiting for system ready.
==========================Time Estimate for All Tasks==========================
Task name [ 7 tasks in total ] Estimated Status
Time(Minutes)
1 Upgrade upgrade image repository@local 0 completed
2 Upgrade upgrade alternate root@local 0 completed
3 Upgrade update firmware@local 0 completed
4 Upgrade backup cores config@local 0 completed
5 Upgrade upgrade flash@local 0 completed
6 Upgrade pre reboot scripts@local 0 completed
7 Core wait for system ready (local) 2 <<<<<<<<<<<<<<<<<<<<<
2. By checking SPB start_c4.log, HA service starts and stops constantly, it records connectivity up and down with interval 7 minutes.
Mon Mar 2 09:40:18 UTC 2020 carrier.sh: changing Connectivity state to 0
Mon Mar 2 09:47:01 UTC 2020 carrier.sh: changing Connectivity state to 1
Mon Mar 2 09:48:33 UTC 2020 carrier.sh: changing Connectivity state to 0
Mon Mar 2 09:55:16 UTC 2020 carrier.sh: changing Connectivity state to 1
3. By checking SPB /var/log/messages, it shows LInk up and down.
2020-03-02T15:10:13+00:00 self kernel: [323137.046939] tg3 0000:7d:00.0 mgmt: Link is down
2020-03-02T15:16:55+00:00 self kernel: [323539.142881] tg3 0000:7d:00.0 mgmt: Link is up at 1000 Mbps, full duplex
.....
2020-03-02T15:33:25+00:00 self kernel: [324529.174992] tg3 0000:7d:00.0 mgmt: Link is up at 1000 Mbps, full duplex
2020-03-02T15:35:00+00:00 self kernel: [324623.928993] tg3 0000:7d:00.0 mgmt: Link is down
Cause
There is port sticky secure MAC addresses setting in customer's network switch.
If customer set as:
Maximum number of secure MAC addresses =1
Violation mode = shutdown (A port security violation causes the interface to shut down immediately.)
Once the HA service tries to take over management IP/MAC from SPA to SPB, the switch port detects the violation and shuts down the port.
It can also customized that the time to recover port from the specified error disable cause (default is 300 seconds) , in the above case it is 7 minutes.
Here is command to check port security setting.
Switch# show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count) (Count) (Count)
---------------------------------------------------------------------------
Fa3/1 2 2 0 Restrict
Fa3/2 2 2 0 Restrict
Fa3/3 2 2 0 Shutdown <<<<<<<<<<
Fa3/4 2 2 0 Shutdown
If customer set as:
Maximum number of secure MAC addresses =1
Violation mode = shutdown (A port security violation causes the interface to shut down immediately.)
Once the HA service tries to take over management IP/MAC from SPA to SPB, the switch port detects the violation and shuts down the port.
It can also customized that the time to recover port from the specified error disable cause (default is 300 seconds) , in the above case it is 7 minutes.
Here is command to check port security setting.
Switch# show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count) (Count) (Count)
---------------------------------------------------------------------------
Fa3/1 2 2 0 Restrict
Fa3/2 2 2 0 Restrict
Fa3/3 2 2 0 Shutdown <<<<<<<<<<
Fa3/4 2 2 0 Shutdown
Resolution
Please disable the the port security setting. Let HA service start on SPB, then resume the code upgrade procedure.
Products
Dell EMC Unity Family |Dell EMC Unity All FlashArticle Properties
Article Number: 000072336
Article Type: Solution
Last Modified: 16 Oct 2025
Version: 4
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.