< Home

Upgrading the SSL VPN Client Patch

This section describes how to load the SSL VPN client patch on the FW to upgrade SSL VPN client components.

Uploading the Patch File to the FW

Log in to http://support.huawei.com/enterprise, choose Enterprise Network > Security > Firewall & VPN Gateway > (Select a model) > Software Download, and select the correct client patch.

You can use FTP, TFTP, or SFTP to upload the patch file to the FW.

The clients and server programs described in the following context should be purchased and installed by the customer. They are not delivered with the FW.

  • Uploading the patch file using FTP

    • The FW functions as an FTP client.

      In such cases, the FTP server and FW can reside on different subnets, but they must be mutually reachable.

      Run the FTP server program on the FTP host, place the patch file to be downloaded in the corresponding FTP directory, and then run the specified command in the FW user view to download the patch file to a directory on the FW. For details, see Configuring the FW as an FTP Client.

    • The FW functions as an FTP server.

      In such cases, the FTP client and FW can reside on different subnets, but they must be mutually reachable.

      Start the FTP server on the FW. For details, see Configuring the FW as an FTP Server. Use the FTP client to log in to the FW and upload the patch file to the corresponding directory on the FW.

  • Uploading the patch file using TFTP

    The FW functions as a TFTP client to download the patch file from the TFTP server. In such cases, the TFTP server and FW can reside on different subnets, but they must be mutually reachable.

    Run the TFTP server program on the TFTP host and upload the patch file to the corresponding TFTP directory. In the FW user view, run the specified command to download the patch file to a directory on the FW. For details, see Configuring the FW as a TFTP Client.

  • Uploading the patch file using SFTP

    • The FW functions as an SFTP client.

      In such cases, the SFTP server and FW can reside on different subnets, but they must be mutually reachable.

      Run the SFTP server program on the SFTP host, place the patch file to be downloaded in the corresponding SFTP directory, and then run the specified command in the FW user view to download the patch file to a directory on the FW. For details, see Configuring the FW as an SFTP Client.

    • The FW functions as an SFTP server.

      In such cases, the SFTP client and FW can reside on different subnets, but they must be mutually reachable.

      Start the SFTP server on the FW. For details, see Configuring the FW as an SFTP Server. Use the SFTP client to log in to the FW and upload the patch file to the corresponding directory on the FW.

    You are advised to use SFTP to upload the patch file as SFTP is more secure than FTP and TFTP.

Installing the Patch

  1. Access the system view.

    system-view

  2. Load the patch.

    client-patch load

  3. Activate the patch.

    client-patch active

    If the patch has any problem, go to Deleting the Patch.

  4. Run the patch.

    client-patch run

    After the command is executed, the patch enters the running state.

    Patches that are not in running state enter the idle state after system restart. To bring them to the running state, you need to load, activate, and run them.

Deleting the Patch

You can uninstall the patch that is no longer required.

  • The patch in any state can be deleted.
  • To make the patch that has been deleted take effect again, you must reload it.
  1. Access the system view.

    system-view

  2. Deactivate the patch.

    client-patch deactive (user view)

  3. Delete the patch.

    client-patch delete

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
Next topic >