mikeprice Posted November 22, 2017 Posted November 22, 2017 Hi all I have just installed 5.6.22 version of the controller on our system - all went as usual - no apparent problems However when I try to use it to upgrade the APs to the new version they won't upgrade APs currently on 3.8.3.6587 error message is upgrade failed: download failed (error: 7) I've done this many times and it always works fine - until now anyone seen this before and have an idea what to do?? Thanks Mike
AJWhite1970 Posted November 22, 2017 Posted November 22, 2017 (edited) Never seen it before this version but yes I have the same error with 5.6.22 5.6.24 has been released for testing, should be in the channel soon. I'm ignoring the error until the next version is out then I might get concerned.... Edited November 22, 2017 by AJWhite1970 1
Gurtlush Posted November 22, 2017 Posted November 22, 2017 5.6.24 is out :- https://community.ubnt.com/t5/UniFi-Updates-Blog/UniFi-5-6-24-Stable-Candidate-has-been-released/ba-p/2141297 working here, although very slow to start, ap's are upgrading fine 1
AJWhite1970 Posted November 22, 2017 Posted November 22, 2017 working here, although very slow to start Which Java version are you using? I'm seeing a lot of reported issues with Unifi and 8.151 but 8.144 works fine (which is what I'm staying with for the time being....) 1
mikeprice Posted November 22, 2017 Author Posted November 22, 2017 Thanks all I have java 151 so I will try updating that - and I will try ne newer version of the controller as well Thanks again Mike
LeMarchand Posted November 22, 2017 Posted November 22, 2017 Java 8.144, Controller 5.6.24: still no joy with upgrades. Though it did restart all the controllers, so you can imagine how that went down.
southhamster Posted November 22, 2017 Posted November 22, 2017 We've also had this problem and been unable to fix it. There's some discussion on the unified forums that it's due to firewalls stopping access to the fw site although we've tried local updates and via SSH on the AP itself with no luck. I've actually taken one home to try and update there to prove it. Some people found that DNS settings or incorrect time were to blame. I'll update with my home test results.
Gurtlush Posted November 22, 2017 Posted November 22, 2017 i'm on java 8.101 have you tried the direct firmware link from inside your network to see if its blocked? ? http://dl.ubnt.com/unifi/firmware/U7PG2/3.9.3.7537/BZ.qca956x.v3.9.3.7537.171013.1101.bin
southhamster Posted November 22, 2017 Posted November 22, 2017 i'm on java 8.101 have you tried the direct firmware link from inside your network to see if its blocked? ? http://dl.ubnt.com/unifi/firmware/U7PG2/3.9.3.7537/BZ.qca956x.v3.9.3.7537.171013.1101.bin Yes we have and it seems ok but still won't update. We are on java 8.151 from memory as we usually update java and then update the unifi s/w. Last successful fw. update was in July from memory.
Chris_ Posted November 22, 2017 Posted November 22, 2017 Are your APs able to access the firmware file from Ubiquiti directly? With the newer controller, firmware is no longer bundled so each device will reach out to the UBNT servers to download it IIRC. On the controller, under maintenance, towards the bottom there is a section where you can download the firmwares to your controller, then the devices will use this version rather than every device downloading a copy from Ubiquiti. 3
caffrey Posted November 22, 2017 Posted November 22, 2017 I had an issue upgrading a USG pro 4 today via the interface so I used custom firmware upgrade and pointed it to the relevant ubiquiti link - then it upgraded fine There is a warning on the ubiquiti forums about problems with Java https://community.ubnt.com/t5/UniFi-Wireless-Beta/NOTICE-Oracle-Java-8-update-151-152-and-the-UniFi-Controller/m-p/2110938
mikeprice Posted November 22, 2017 Author Posted November 22, 2017 Update I have updated Java on the relevant machine - version 151 seemed to be the latest available I also had to physically move the server so it has been restarted as well Result - the update started to go better and seemed to complete but now the AP won't adopt - itt says the adopt failed - also on the console the IP address is wrong - looks like it hasn't seen the DHCP server I will try a hard reset tomorrow morning
mikeprice Posted November 23, 2017 Author Posted November 23, 2017 Update I have updated Java on the relevant machine - version 151 seemed to be the latest available I also had to physically move the server so it has been restarted as well Result - the update started to go better and seemed to complete but now the AP won't adopt - itt says the adopt failed - also on the console the IP address is wrong - looks like it hasn't seen the DHCP server I will try a hard reset tomorrow morning EDIT Turned out that the server had decided that things were far to simple so didn't start DHCP properly when I restarted it Hence DHCP wasn't responding to requests and the whole Internet was inaccessible this morning which explains why the AP wouldn't adopt - it hadn't got a valid IP address So not DHCP is fixed and the AP is adopted and the problems are back to how they were except for another random AP that not sems to not want to start at all
southhamster Posted November 26, 2017 Posted November 26, 2017 I've now tested an AP-Pro at home to see if I can find out a bit more.Clean win7x64 install, windows updated, chrome, javax64 8.151 unifi controller v5.6.20 and restore config, so it's basically the same config as at school.I was able to update the fw cache to the latest versions off the website ok.I could then update the AP-Pro to fw v.3.9.3.7953 okLooking at the wireshark logs I could see the AP itself trying to contact the unifi NTP server and dl.ubnt.com, although I stupidly had IPv6 enabled which has overcomplicated things.So my thoughts are that this looks to me like our (SWGfL) firewall or DNS? is the problem, or even that the AP needs a proxy setting, so I may try wireshark again at work to see if I can narrow down what is required.I also wonder if manually copying the c:\users\%username%\ubiquiti unifi\data\firmware\ folder and firmware.json files across might make them available in the unifi controller - even if that's a bit of a bodge.... It also still doesn't explain why the AP won't do a local update trying SSH - maybe it still needs to contact the unifi ntp/http site itself as well?connection to time server 0.ubnt.pool.ntp.org 1 0.000000 (AP IP) (serverIP) DNS 79 Standard query 0x000b A 0.ubnt.pool.ntp.org31 5.798458 Server IP Gateway DNS 71 Standard query 0x11aa A dl.ubnt.com32 5.843296 GatewayIP ServerIP DNS 411 Standard query response 0x11aa A dl.ubnt.com CNAME d2cnv2pop2xy4v.cloudfront.net A 54.192.10.221 NS ns-841.awsdns-41.net NS ns-1431.awsdns-50.org NS ns-1787.awsdns-31.co.uk NS ns-20.awsdns-02.com A 205.251.197.151 AAAA 2600:9000:5305:9700::1 A 205.251.198.251 AAAA 2600:9000:5306:fb00::1 A 205.251.192.20 AAAA 2600:9000:5300:1400::1 A 205.251.195.73
southhamster Posted November 27, 2017 Posted November 27, 2017 Right. I copied the \firmware folder from the successful home install to \\servername\c$\Users\Administrator\Ubiquiti UniFi\data\firmware, logged out and back in and the firmware updates were then available in maintenance cached. I was then able to update the AP's normally via the cache. Hurrah. Warning: I suggest you make backups first of course, and bear in mind that I duplicated the school config which known what AP models you have to download the firmware updates for. Yes, it's a bodge but at least it bought us some time as I really wanted to fix the vulnerability issues. We will still need to look at the firewall issue later though.
Cache Posted November 27, 2017 Posted November 27, 2017 (edited) We've had issues previously and it was caused by NTP. The AP's by default try to download from https://dl.ubnt.com which if they can't access an NTP server produces an error about certificate validity. I can't remember what version, but there's been 2 changes - the 1st changed the firmware update location to go direct to the UBNT site, the 2nd then switched from http to https but they've been fairly staggered in there releasing of those changes. In the latest version of the console you can go to Settings - Services - NTP and specify your ntp server in there and that solved all the issues for us. Earlier versions of the console require editing config files. I don't know whether it's the case with the UAP's but I've previously had issues getting HP switches to use a Windows time server so mine point to a Linux timeserver currently as it was a faff to edit the files at the time. Edit: It was also compounded by me then discovering that for some reason our ISP was blocking all NTP requests, when queried they couldn't provide an answer as to why but they weren't going to unblock it. Edited November 27, 2017 by Cache 3
mikeprice Posted November 28, 2017 Author Posted November 28, 2017 for the last couple of days one of the APs has been frequently loosing heartbeat since trying (and failing) to update This morning (we were not in yesterday due to INSET day) I have tried SSH to the AP - set to default using the command (I typed in Help) and it restarted and now connects OK with the old firmware - no idea where it got it from or if it just kept it even after 'reset to default'
dry Posted November 28, 2017 Posted November 28, 2017 In the latest version of the console you can go to Settings - Services - NTP and specify your ntp server in there and that solved all the issues for us. Earlier versions of the console require editing config files. Thanks for the tip, upgraded controller to 5.6.22 and now APs are updating to latest firmware successfully!
mikeprice Posted November 28, 2017 Author Posted November 28, 2017 Just tried changing teh GUI setting for NTP and it knocked all the APs offline for a short time - or it appeared to - no-one has complained (yet?) but they still won't upgrade and the time is still set to 1970 I'm going to leave them for a while in case they look for the time later in the day - and also I don't want to be resetting the whole wifi during the day (or not too often anyway!)
AJWhite1970 Posted November 28, 2017 Posted November 28, 2017 Still banging my head with this one. All my AP's have the correct time and date, my NTP setting in the controller is right, all my proxies can happily download from ubnt.com and yet still I can't cache the new firmwares using 5.6.24 Grrrrr.....
Cache Posted November 28, 2017 Posted November 28, 2017 I have to admit I didn't haven't tried caching the firmware. You could try a Custom Firmware upgrade using the http link to try and download to the AP, just to rule that out. The other thing I did was SSH into the AP and initate the upgrade while the log file was running https://help.ubnt.com/hc/en-us/articles/204959834-UniFi-What-log-files-exist-and-where-can-I-view-them-#unifi%20ap%20and%20switch That's how I eventually narrowed ours down to being an SSL problem caused by NTP.
Priscilla110 Posted November 29, 2017 Posted November 29, 2017 My UniFi Controller is running on cloud key and since Update to 5.6.22 I'm not able to connect the controller anymore. Any suggstions on that issue?
Mr_Jiminy Posted November 29, 2017 Posted November 29, 2017 Pardon me if this has been mentioned, but isn't the recommendation to revert to a previous version of Java - 144 for example? I'm sure something iffy happened to hotspots with the latest Java version, which is why we choose to downgrade all of our Unifi sites (temporarily).
derf Posted February 3, 2018 Posted February 3, 2018 I had the exact same issue last week when I finally upgrade the unifi controller. The latest version downloads from the internet and not from the controller, and our smoothwall was doing a proxy for the requests which caused the download to fail. Adding an exception for management VLAN our access points sit on fixed the problem instantly.
jurrel23 Posted June 6, 2018 Posted June 6, 2018 Hi you need to contact unifi, they will give you the ssh command to connect directly to them to upgrade. You need putty if you dont already have it. Sent from my SM-G955F using EduGeek mobile app
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now