Jump to content

Recommended Posts

Posted

Hi all

I have just installed 5.6.22 version of the controller on our system - all went as usual - no apparent problems

 

However when I try to use it to upgrade the APs to the new version they won't upgrade

APs currently on 3.8.3.6587

error message is upgrade failed: download failed (error: 7)

 

I've done this many times and it always works fine - until now

 

anyone seen this before and have an idea what to do??

 

Thanks

 

Mike

Posted (edited)

Never seen it before this version but yes I have the same error with 5.6.22

 

5.6.24 has been released for testing, should be in the channel soon. I'm ignoring the error until the next version is out then I might get concerned....

Edited by AJWhite1970
  • Thanks 1
Posted
working here, although very slow to start

 

Which Java version are you using? I'm seeing a lot of reported issues with Unifi and 8.151 but 8.144 works fine (which is what I'm staying with for the time being....)

  • Thanks 1
Posted

We've also had this problem and been unable to fix it. There's some discussion on the unified forums that it's due to firewalls stopping access to the fw site although we've tried local updates and via SSH on the AP itself with no luck.

I've actually taken one home to try and update there to prove it. Some people found that DNS settings or incorrect time were to blame. I'll update with my home test results.

Posted

Are your APs able to access the firmware file from Ubiquiti directly? With the newer controller, firmware is no longer bundled so each device will reach out to the UBNT servers to download it IIRC.

 

On the controller, under maintenance, towards the bottom there is a section where you can download the firmwares to your controller, then the devices will use this version rather than every device downloading a copy from Ubiquiti.

  • Thanks 3
Posted

Update

I have updated Java on the relevant machine - version 151 seemed to be the latest available

 

I also had to physically move the server so it has been restarted as well

 

Result - the update started to go better and seemed to complete

 

but now the AP won't adopt - itt says the adopt failed - also on the console the IP address is wrong - looks like it hasn't seen the DHCP server

 

I will try a hard reset tomorrow morning

Posted
Update

I have updated Java on the relevant machine - version 151 seemed to be the latest available

 

I also had to physically move the server so it has been restarted as well

 

Result - the update started to go better and seemed to complete

 

but now the AP won't adopt - itt says the adopt failed - also on the console the IP address is wrong - looks like it hasn't seen the DHCP server

 

I will try a hard reset tomorrow morning

 

EDIT

Turned out that the server had decided that things were far to simple so didn't start DHCP properly when I restarted it

Hence DHCP wasn't responding to requests and the whole Internet was inaccessible this morning

which explains why the AP wouldn't adopt - it hadn't got a valid IP address

 

So not DHCP is fixed and the AP is adopted

 

and the problems are back to how they were

except for another random AP that not sems to not want to start at all

Posted

I've now tested an AP-Pro at home to see if I can find out a bit more.Clean win7x64 install, windows updated, chrome, javax64 8.151 unifi controller v5.6.20 and restore config, so it's basically the same config as at school.I was able to update the fw cache to the latest versions off the website ok.I could then update the AP-Pro to fw v.3.9.3.7953 okLooking at the wireshark logs I could see the AP itself trying to contact the unifi NTP server and dl.ubnt.com, although I stupidly had IPv6 enabled which has overcomplicated things.So my thoughts are that this looks to me like our (SWGfL) firewall or DNS? is the problem, or even that the AP needs a proxy setting, so I may try wireshark again at work to see if I can narrow down what is required.I also wonder if manually copying the c:\users\%username%\ubiquiti unifi\data\firmware\ folder and firmware.json files across might make them available in the unifi controller - even if that's a bit of a bodge....

It also still doesn't explain why the AP won't do a local update trying SSH - maybe it still needs to contact the unifi ntp/http site itself as well?connection to time server 0.ubnt.pool.ntp.org 1 0.000000 (AP IP) (serverIP) DNS 79 Standard query 0x000b A 0.ubnt.pool.ntp.org31 5.798458 Server IP Gateway DNS 71 Standard query 0x11aa A dl.ubnt.com32 5.843296 GatewayIP ServerIP DNS 411 Standard query response 0x11aa A dl.ubnt.com CNAME d2cnv2pop2xy4v.cloudfront.net A 54.192.10.221 NS ns-841.awsdns-41.net NS ns-1431.awsdns-50.org NS ns-1787.awsdns-31.co.uk NS ns-20.awsdns-02.com A 205.251.197.151 AAAA 2600:9000:5305:9700::1 A 205.251.198.251 AAAA 2600:9000:5306:fb00::1 A 205.251.192.20 AAAA 2600:9000:5300:1400::1 A 205.251.195.73

Posted

Right. I copied the \firmware folder from the successful home install to \\servername\c$\Users\Administrator\Ubiquiti UniFi\data\firmware, logged out and back in and the firmware updates were then available in maintenance cached. I was then able to update the AP's normally via the cache. Hurrah.

Warning: I suggest you make backups first of course, and bear in mind that I duplicated the school config which known what AP models you have to download the firmware updates for.

Yes, it's a bodge but at least it bought us some time as I really wanted to fix the vulnerability issues. We will still need to look at the firewall issue later though.

Posted (edited)

We've had issues previously and it was caused by NTP.

 

The AP's by default try to download from https://dl.ubnt.com which if they can't access an NTP server produces an error about certificate validity. I can't remember what version, but there's been 2 changes - the 1st changed the firmware update location to go direct to the UBNT site, the 2nd then switched from http to https but they've been fairly staggered in there releasing of those changes.

 

In the latest version of the console you can go to Settings - Services - NTP and specify your ntp server in there and that solved all the issues for us. Earlier versions of the console require editing config files.

 

I don't know whether it's the case with the UAP's but I've previously had issues getting HP switches to use a Windows time server so mine point to a Linux timeserver currently as it was a faff to edit the files at the time.

 

Edit: It was also compounded by me then discovering that for some reason our ISP was blocking all NTP requests, when queried they couldn't provide an answer as to why but they weren't going to unblock it.

Edited by Cache
  • Thanks 3
Posted

for the last couple of days one of the APs has been frequently loosing heartbeat since trying (and failing) to update

 

This morning (we were not in yesterday due to INSET day) I have tried SSH to the AP - set to default using the command (I typed in Help)

 

and it restarted

 

and now connects OK with the old firmware - no idea where it got it from or if it just kept it even after 'reset to default'

Posted
In the latest version of the console you can go to Settings - Services - NTP and specify your ntp server in there and that solved all the issues for us. Earlier versions of the console require editing config files.

 

Thanks for the tip, upgraded controller to 5.6.22 and now APs are updating to latest firmware successfully!

Posted

Just tried changing teh GUI setting for NTP and it knocked all the APs offline for a short time - or it appeared to - no-one has complained (yet?)

 

but they still won't upgrade and the time is still set to 1970

I'm going to leave them for a while in case they look for the time later in the day - and also I don't want to be resetting the whole wifi during the day (or not too often anyway!)

Posted

Still banging my head with this one. All my AP's have the correct time and date, my NTP setting in the controller is right, all my proxies can happily download from ubnt.com and yet still I can't cache the new firmwares using 5.6.24

 

Grrrrr.....

Posted

I have to admit I didn't haven't tried caching the firmware.

 

You could try a Custom Firmware upgrade using the http link to try and download to the AP, just to rule that out.

 

The other thing I did was SSH into the AP and initate the upgrade while the log file was running https://help.ubnt.com/hc/en-us/articles/204959834-UniFi-What-log-files-exist-and-where-can-I-view-them-#unifi%20ap%20and%20switch

 

That's how I eventually narrowed ours down to being an SSL problem caused by NTP.

Posted

Pardon me if this has been mentioned, but isn't the recommendation to revert to a previous version of Java - 144 for example?

I'm sure something iffy happened to hotspots with the latest Java version, which is why we choose to downgrade all of our Unifi sites (temporarily).

  • 2 months later...
Posted
I had the exact same issue last week when I finally upgrade the unifi controller. The latest version downloads from the internet and not from the controller, and our smoothwall was doing a proxy for the requests which caused the download to fail. Adding an exception for management VLAN our access points sit on fixed the problem instantly.
  • 4 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...