Drag to reposition cover

Brocade ICX Series (cheap & powerful 10gbE/40gbE switching)

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

TonyArrr

Active Member
Sep 22, 2021
151
76
28
Straylia
I'm finally jumping onto the enterprise networking train and picked up a pretty nice 6450-48P and have been going through the @fohdeesha (thanks for all of the work that goes into creating such an awesome guide, btw -- you're a rock star!), but unable to get past this error message during the update_primary step.

View attachment 41238
Just checking definitely connected the management port of the switch to the network, not one of the regular ports?
And can you ping the s

I have confirmed that the TFTP server is running and I can download the files onto other machines on my network.

I have also tried setting up TFTP servers on MacOS, Linux, and Windows, and I done some searching, but haven't found anything helpful so far. I'm not really sure what else to try at this point -- anyone have any ideas?
any output in the logs for your TFTP server?
 

rjrobert

New Member
Mar 7, 2023
7
2
3
Just checking definitely connected the management port of the switch to the network, not one of the regular ports?
And can you ping the s



any output in the logs for your TFTP server?
Yeah, definitely connected to the management port -- always good to double check. I can also ping my TFTP server from the console.

Here are the most recent logs from my windows box.
Connection received from 192.168.1.50 on port 1052 [08/01 16:41:36.856]
Read request for file <ICX64xx/ICX64R08030u.bin>. Mode octet [08/01 16:41:36.856]
OACK: <timeout=5,blksize=1468,> [08/01 16:41:36.856]
Using local port 57706 [08/01 16:41:36.856]
Ack block 19 ignored (received twice) [08/01 16:41:56.886]
Ack block 29 ignored (received twice) [08/01 16:42:04.896]
Ack block 34 ignored (received twice) [08/01 16:42:09.899]
TIMEOUT waiting for Ack block #35 [08/01 16:42:32.938]
No firewalls enabled anywhere either. I am able connect to this TFTP server from other machines and download the files without issue, too. It seems like it connects to the server, but there's an issue when trying to download.

I came across this post that seemed relevant since my bootloader appears to be version 7.4, but the >enable level is locked down from the previous owner, so I cannot access the >configure terminal level to complete these steps.
 

fohdeesha

Kaini Industries
Nov 20, 2016
2,857
3,323
113
34
fohdeesha.com
Yeah, definitely connected to the management port -- always good to double check. I can also ping my TFTP server from the console.

Here are the most recent logs from my windows box.


No firewalls enabled anywhere either. I am able connect to this TFTP server from other machines and download the files without issue, too. It seems like it connects to the server, but there's an issue when trying to download.

I came across this post that seemed relevant since my bootloader appears to be version 7.4, but the >enable level is locked down from the previous owner, so I cannot access the >configure terminal level to complete these steps.
What's the output of printenv in the bootloader
 

fohdeesha

Kaini Industries
Nov 20, 2016
2,857
3,323
113
34
fohdeesha.com
Also triple check the .50 IP you gave the switch isn't already assigned to something else on your network, chance it to a different IP just in case
 

TonyArrr

Active Member
Sep 22, 2021
151
76
28
Straylia
View attachment 41239

And to your other point, I've used a few other IPs for the switch to make sure there was no collision.
Here are the most recent logs from my windows box.

No firewalls enabled anywhere either. I am able connect to this TFTP server from other machines and download the files without issue, too. It seems like it connects to the server, but there's an issue when trying to download.
that’s more or less how my scanner would act when I accidentally had it set statically to an address that was also a dhcp reservation… start a connection, run for a (very) little while, then just vanish. These addresses you’re using are definitely outside the pool of addresses your dhcp server hands out, and not assigned to any reservations right?

It might be worth just connecting your computer and the switch directly and putting static IPs on both, then retrying, takes the entirety of the rest of your network out of the picture as possible causes.

edit: if doing this, you reconnect your computer and the switch back to the rest of your network after running

Bash:
factory set-default
reset
I came across this post that seemed relevant since my bootloader appears to be version 7.4, but the >enable level is locked down from the previous owner, so I cannot access the >configure terminal level to complete these steps.
If the boot loader is too old to run factory set-default, you could follow fohdeesha’s much earlier advice to reset the enable password. But if you really have to use the webUI, move the firmware bins to the root folder of your TFTP server cause as I remember it, the webUI was interesting with slashes…
 

rjrobert

New Member
Mar 7, 2023
7
2
3
that’s more or less how my scanner would act when I accidentally had it set statically to an address that was also a dhcp reservation… start a connection, run for a (very) little while, then just vanish. These addresses you’re using are definitely outside the pool of addresses your dhcp server hands out, and not assigned to any reservations right?

It might be worth just connecting your computer and the switch directly and putting static IPs on both, then retrying, takes the entirety of the rest of your network out of the picture as possible causes.

edit: if doing this, you reconnect your computer and the switch back to the rest of your network after running

Bash:
factory set-default
reset


If the boot loader is too old to run factory set-default, you could follow fohdeesha’s much earlier advice to reset the enable password. But if you really have to use the webUI, move the firmware bins to the root folder of your TFTP server cause as I remember it, the webUI was interesting with slashes…

Yeah, I tried connecting the switch to my laptop (which is running TFTP) with static IPs, and turned off my wifi for good measure, with the same results -- it always seems to make the connection initially but timeout during the transfer.

It's too old for the factory set-default, apparently -- it gives an error when I try it.

I'll take a look for the steps to reset the enable password as that might be my only option.
 

rjrobert

New Member
Mar 7, 2023
7
2
3
Well, definitely something weird going on in my network. I just installed TFTP on my OpnSense firewall and connected the switch directly to it (no other switches in the way) and it’s working now. Can’t explain why, but I’ll take the win.

Thanks for the quick replies gents!
 

kickstart24

New Member
Jan 9, 2025
6
0
1
Looking to expand from the router on a stick config so I can do intervlan communication through the switch and offload the router.

On the Brocade, do I just need to set up the VLANs in the router config and then add the router-interfaces in the switch config (per Terry Henry's video). Anything else that needs to be done?
 

fohdeesha

Kaini Industries
Nov 20, 2016
2,857
3,323
113
34
fohdeesha.com
Looking to expand from the router on a stick config so I can do intervlan communication through the switch and offload the router.

On the Brocade, do I just need to set up the VLANs in the router config and then add the router-interfaces in the switch config (per Terry Henry's video). Anything else that needs to be done?
transit vlan to the router, default route on the switch pointing to firewalls ip on that transit net, routes on the firewall for all your subnets pointing to the ICXs IP on the transit subnet, probably new outbound nat rules on the firewall for all your other subnets on the switch
 
  • Like
Reactions: cyinite

kickstart24

New Member
Jan 9, 2025
6
0
1
transit vlan to the router, default route on the switch pointing to firewalls ip on that transit net, routes on the firewall for all your subnets pointing to the ICXs IP on the transit subnet, probably new outbound nat rules on the firewall for all your other subnets on the switch
Thanks. Would the transit VLAN just be VLAN 1 with the port number used to communicate with the router untagged?

Do you know of any documentation/guides/old threads for setting up the brocade *with intervlan routing) connected to a router?

It looks like I just need to setup the VLANs, the router-interfaces, transit VLAN to router, and default route on the switch pointing to firewalls ip on that transit net. The rest of the setup is on the router?
 
Last edited:

kapone

Well-Known Member
May 23, 2015
1,246
719
113
Thanks. Would the transit VLAN just be VLAN 1 with the port number used to communicate with the router untagged?

Do you know of any documentation/guides/old threads for setting up the brocade *with intervlan routing) connected to a router?

It looks like I just need to setup the VLANs, the router-interfaces, transit VLAN to router, and default route on the switch pointing to firewalls ip on that transit net. The rest of the setup is on the router?
https://forums.servethehome.com/index.php?threads/layer-3-switch-w-pfsense.23236/post-216621
 

jmdomini

New Member
Jan 30, 2024
15
0
1
:eek::eek:

There should be plenty of heatsinks...
Got all the parts today and finished the rebuild. Good news is the temperatures look MUCH better. Bad news is GL are the replacement fans loud! I tried to stick with the existing (quiet) fans but the temp was hanging around 82C, which while an improvement still seemed high.

Slot 1 Current Temperature: 63.5 deg-C (Sensor 1), 37.0 deg-C (Sensor 2)
Warning level.......: 100.0 deg-C
Shutdown level......: 105.0 deg-C

I suppose it's probably too much to ask for a quiet and powerful fan?
 

zinm

New Member
Jan 8, 2025
1
0
1
Last edited:

kickstart24

New Member
Jan 9, 2025
6
0
1
I'm following the Fohdeesha guide for setting up an ICX6450. when I type "ip dhcp-client disable" or "router-interface ve 1" after typing "vlan 1", I get the following


ICX6430-24P Switch(config)#ip dhcp-client disable
Invalid input -> disable
Type ? for a list
ICX6430-24P Switch(config)#


ICX6430-24P Switch(config-vlan-1)#router-interface ve 1
Invalid input -> router-interface ve 1
Type ? for a list

What am I doing wrong?
 

fohdeesha

Kaini Industries
Nov 20, 2016
2,857
3,323
113
34
fohdeesha.com
I'm following the Fohdeesha guide for setting up a ICX6450. when I type "router-interface ve 1", I get the following

ICX6430-24P Switch(config-vlan-1)#router-interface ve 1
Invalid input -> router-interface ve 1
Type ? for a list

what am i doing wrong?
you have an icx6430, not a 6450, and those do not support the routing.layer 3 firmware which the guide is based off of, it also has no 10gb