Wireless Access

 View Only
  • 1.  MSM 325 Firmware

    Posted Feb 25, 2023 10:40 AM
    MSM325 access point - fails to update firmware

    my MSM 325's are running firmware 5.3.5, I see there is a 5.4.0 available;-

    https://support.hpe.com/connect/s/softwaredetails?language=en_US&softwareId=nw_88575_1&tab=Installation+Instructions

    Have downloaded the file and pointed the "firmware update tab" to it but I get an error message that the file is truncated/invalid.
    Ditto if I try an incremental upgrade to 5.3.6

    What am I missing...

    I tried posting to the HPE site but was directed here - feels like I'm falling between the cracks.



  • 2.  RE: MSM 325 Firmware

    Posted Feb 25, 2023 07:03 PM

    i think the time has come for you to replace those APs.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: MSM 325 Firmware

    Posted Feb 25, 2023 07:48 PM

    And, I think the time has come to call out those who disrespect the planet and rush headlong over the cliff of premature obsolescence ! 
    There are many of these out there and indeed you can still buy New in Box, which are in plentiful supply and cheap!  (just bought a couple more for spares - sealed in original boxes)
    For an industrial IOT solution they work well and delivering lightweight data bridges to SBC's running sensor arrays on machinery is never going to challenge them!
    (I am not running a campus with dozens of AP's for thousands of users) 
    I DO expect to be able to run technology for more than a couple of years before turning it into e-waste, otherwise what is the point in investing in quality hardware?
    I am well aware that these run a deprecated security protocol out of the box, but once TLS1.0 is enabled in modern browsers (Enter "about:config" in the Firefox search bar for e.g. (and why is that not in the Knowledgebase.... ?)) 
    So, Ariyap, if you don't know why the firmware link on the HPE site is giving me a truncated file error, then you're not really answering the question I asked ?
    I run several of these and I don't regard it as unreasonable to expect to have them all on the same version of/ latest firmware.




  • 4.  RE: MSM 325 Firmware

    Posted Feb 26, 2023 01:51 AM

    good that you pointed out the security aspects of those AP/firmware. Anyway the file that you are downloading is a zipped MIB file which is not a firmware. As you have already pointed out the product is pretty old and when I search for it in MNP I get this. 

    check this link where the last suggestion is to log a case with support perhaps they will help you to provide the version. 

    also note that if the firmware you are after (5.3.5) had critical security advisory against it, it will not be available for people to download.



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 5.  RE: MSM 325 Firmware

    Posted Feb 27, 2023 08:30 AM

    "And, I think the time has come to call out those who disrespect the planet and rush headlong over the cliff of premature obsolescence !"

    I think is is PAST time to call out those who insist on old, insecure hardware while berating any volunteers trying to helpfully respond to a request for assistance,



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 6.  RE: MSM 325 Firmware

    Posted Feb 27, 2023 06:25 PM

    "insecure" ?  Did you just assume this based on the age of the units ?  I suspect security had nothing to do with it, more likely phased out in favour newer units running more scalable (profitable) management utilities ...  They're certainly capable of more security than a typical "designer coffee" shop offers.

    Anyway;-
    1) this is on an IoT Intranet, not connected to the web. 

    2) the 'Users' are SBC's - single board computers - they typically provide telemetry for a couple of dozen analog and digital parameters - they generate Kilobytes of data per day - not Megabytes, not Gigabytes. And they work best with static IP addresses, there is no public login and they use a securely generated password to connect, no 'live' users. 

    3) the data they send has no commercial sensitivity, indeed if someone emailed me asking for a copy, I'd probably send them it!

    4) Surely, it is in everyone's interest to find appropriate uses for older hardware;- The UK generates half a million tons of e-waste per annum, the pertinent question isn't "why are you using old hardware", but "what is needed to keep these in service" - They operate on exactly the same frequencies as current retail models, plug into the same RJ45 ports, and indeed exceed all required performance parameters for the given task - Is the issue that the hardware no longer works, or that the support infrastructure has been deleted 
    If there were a current firmware, well, they'd be current. Which sort of comes back to what I originally asked for...
    Frankly with a modern firmware, access points like these would be a boon throughout the developing world, so do you still think they belong in landfill!  Cars have been around for 125 years, is it curious that people still ride bikes: what works, works!

    5) I was directed here by HPE, though feels a little inappropriate - I'm NOT running a campus scale network and the budget is more Ramen Noodle than Steak... 

    6) And while Ariya missed the point at first, kudos is due (and was given) for the later one where he confirmed that the linked file on the HPE site is indeed not the correct one!

    7) the main issue with them is that the native TLS support version is set to 1.0 !  This is frankly a dropped ball by HP given 1.1 was released in 2006 and 1.2 in 2008 and so should certainly have been factored in for a product still being manufactured after 2010 ?
    Even after a factory reset, you can't access the management interface using any current browser (unless you know how to rewind the browser TLS settings) - so the unit appears 'bricked'...