Network Maintenance Tomorrow, Friday March 2, 2012 @ 0530hrs CST for 30 minutes
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Here is my draft ... I need help with the impact statement as I am unsure what is actually running out of 221 these days. I want to get this out ASAP today, so please comment at your earliest convenience. - ---------------- In response to the JC3-CIRC Tech Bulletin U-107, we will be performing a software upgrade on our core cisco nexus 5020 switch. There is currently an exploit in the wild which can cause the device to be rebooted remotely. There is currently no way to defend against this attack other than to upgrade. We will be migrating from version 4.2.1.N2.1 to 5.1.3.N1.1a. This is a major upgrade which may result in an extended upgrade period. For this reason, I am reserving a 30 minute timeslot for the work. I expect the upgrade to take no more than 10 minutes, but I cannot be sure. We have upgraded other units in the same way and have seen the times in the 10 minute range, but the vendor has stated that there can be complications causing it to take up to 30 minutes. If, by chance, we are exploited and the 5020 reboots, I have pre-staged the images such that when it comes back up it will be patched and no longer vulnerable. During the upgrade window access to many internal MCS systems will be impacted. This includes, but is not limited to, login nodes, compute nodes, file services, etc. Services that will NOT be impacted are cryptocard, core web services and email. I will provide an all-clear message when the work is done. Based on the impact to file services, it may be necessary to reboot desktop systems to clear problems. Please reboot your system if you are experiencing problems on Friday morning. If the problem persists, please contact the helpdesk. If you have any questions or concerns, please contact me at your earliest convenience. - -- Corby Schmitz Network Communication Operations and Support Manager Computer and Information Systems Division - - Network Engineer MREN/Starlight - -- Argonne National Laboratory 9700 S. Cass Ave. Argonne, IL 60439 Desk: 630-252-7664 Cell: 630-512-1502 E-mail: [email protected] -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.16 (Darwin) iD8DBQFPT4QNQhpwH3ALVFERAjDuAJ9XdYIN3RKp/PnRt36se2XMeqYumQCg05rZ gXITIKHZKOoEhn9lAtv1P74= =K86Z -----END PGP SIGNATURE-----
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 How about this? - ------------------ All: In response to an open vulnerability, we will be performing an upgrade of some network gear within MCS tomorrow morning (3/2/2012). I have reserved a 30 minute slot from 5:30-6:00AM tomorrow morning. I expect the outage to last no more than 10 minutes, but due to possible complications, I wanted to reserve a full 30 minute window. During this window, you can expect interruptions accessing: Login nodes Compute nodes File services etc. Services that will NOT be interrupted: Crypto-card authentication Core web services Email access I will provide an all-clear message when the work is done. Based on the impact to file services, it may be necessary to reboot desktop systems to clear problems. Please reboot your system if you are experiencing problems on Friday morning. If the problem persists, please contact the helpdesk. If you have any questions or concerns, please contact me at your earliest convenience. If you would like to read the more technical details, please read the bottom of this message. - -- Corby Schmitz Network Communication Operations and Support Manager Computer and Information Systems Division - - Network Engineer MREN/Starlight - -- Argonne National Laboratory 9700 S. Cass Ave. Argonne, IL 60439 Desk: 630-252-7664 Cell: 630-512-1502 E-mail: [email protected] In response to the JC3-CIRC Tech Bulletin U-107, we will be performing a software upgrade on our core cisco nexus 5020 switch. There is currently an exploit in the wild which can cause the device to be rebooted remotely. There is currently no way to defend against this attack other than to upgrade. We will be migrating from version 4.2.1.N2.1 to 5.1.3.N1.1a. This is a major upgrade which may result in an extended upgrade period. For this reason, I am reserving a 30 minute timeslot for the work. I expect the upgrade to take no more than 10 minutes, but I cannot be sure. We have upgraded other units in the same way and have seen the times in the 10 minute range, but the vendor has stated that there can be complications causing it to take up to 30 minutes. If, by chance, we are exploited and the 5020 reboots, I have pre-staged the images such that when it comes back up it will be patched and no longer vulnerable. -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.16 (Darwin) iD8DBQFPT7YrQhpwH3ALVFERAmrcAJ9p7ZnrefoAGZaP1nmdzvoyeYvgSQCfWHpk lf3suq9anuWve+4ocp8PVZY= =Ozyt -----END PGP SIGNATURE-----
I recommend adding Linux Workstations above the etc. Everything else looks good. ---- Daniel Murphy-Olson Systems Administrator Mathematics & Computer Science Division Argonne National Laboratory 630-252-0055 ----- Original Message ----- From: "Schmitz Corby" <[email protected]> To: "Core Admins" <[email protected]> Sent: Thursday, March 1, 2012 11:47:23 AM Subject: DRAFT: Network Maintenance Tomorrow, Friday March 2, 2012 @ 5:30AM CST for 30 minutes -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 How about this? - ------------------ All: In response to an open vulnerability, we will be performing an upgrade of some network gear within MCS tomorrow morning (3/2/2012). I have reserved a 30 minute slot from 5:30-6:00AM tomorrow morning. I expect the outage to last no more than 10 minutes, but due to possible complications, I wanted to reserve a full 30 minute window. During this window, you can expect interruptions accessing: Login nodes Compute nodes File services etc. Services that will NOT be interrupted: Crypto-card authentication Core web services Email access I will provide an all-clear message when the work is done. Based on the impact to file services, it may be necessary to reboot desktop systems to clear problems. Please reboot your system if you are experiencing problems on Friday morning. If the problem persists, please contact the helpdesk. If you have any questions or concerns, please contact me at your earliest convenience. If you would like to read the more technical details, please read the bottom of this message. - -- Corby Schmitz Network Communication Operations and Support Manager Computer and Information Systems Division - - Network Engineer MREN/Starlight - -- Argonne National Laboratory 9700 S. Cass Ave. Argonne, IL 60439 Desk: 630-252-7664 Cell: 630-512-1502 E-mail: [email protected] In response to the JC3-CIRC Tech Bulletin U-107, we will be performing a software upgrade on our core cisco nexus 5020 switch. There is currently an exploit in the wild which can cause the device to be rebooted remotely. There is currently no way to defend against this attack other than to upgrade. We will be migrating from version 4.2.1.N2.1 to 5.1.3.N1.1a. This is a major upgrade which may result in an extended upgrade period. For this reason, I am reserving a 30 minute timeslot for the work. I expect the upgrade to take no more than 10 minutes, but I cannot be sure. We have upgraded other units in the same way and have seen the times in the 10 minute range, but the vendor has stated that there can be complications causing it to take up to 30 minutes. If, by chance, we are exploited and the 5020 reboots, I have pre-staged the images such that when it comes back up it will be patched and no longer vulnerable. -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.16 (Darwin) iD8DBQFPT7YrQhpwH3ALVFERAmrcAJ9p7ZnrefoAGZaP1nmdzvoyeYvgSQCfWHpk lf3suq9anuWve+4ocp8PVZY= =Ozyt -----END PGP SIGNATURE-----
participants (2)
-
Dan Olson -
Schmitz Corby