diff --git a/docs/infrastructure/network.rst b/docs/infrastructure/network.rst --- a/docs/infrastructure/network.rst +++ b/docs/infrastructure/network.rst @@ -73,19 +73,22 @@ * Connect to the `principal `_ (pushkin here) * Check the `CARP status `_ to ensure the firewall is the principal (must have the status MASTER for all the IPS) * Connect to the `backup `_ (glytotek here) -* Check the `CARP status `_ to ensure the firewall is the backup (must have the status BACKUP for all the IPS) +* Check the `CARP status `__ to ensure the firewall is the backup (must have the status BACKUP for all the IPS) * Ensure the 2 firewalls are in sync: * On the principal, go to the `High availability status `_ and force a synchronization * click on the button on the right of ``Synchronize config to backup`` - .. image:: ../images/infrastructure/network/sync.png + +.. image:: ../images/infrastructure/network/sync.png * Switch the principal/backup to prepare the upgrade of the master (The switch is transparent from the user perspective and can be done without service interruption) * [1] On the principal, go to the `Virtual IPS status `_ page * Activate the CARP maintenance mode + .. image:: ../images/infrastructure/network/carp_maintenance.png + * check the status of the VIPs, they must be ``BACKUP`` on pushkin and ``PRIMARY`` on glyptotek @@ -93,7 +96,6 @@ If everything is ok, proceed to the next section. - Upgrade the first firewall ^^^^^^^^^^^^^^^^^^^^^^^^^^ @@ -111,17 +113,23 @@ If not, be sure of what you are doing and adapt the links accordingly -* [2] go to the `System Firmware: status `_ page (pushkin here) +* [2] go to the `System Firmware: status `_ page (pushkin here) * Click on the ``Check for upgrades`` button + .. image:: ../images/infrastructure/network/check_for_upgrade.png + * follow the interface indication, one or several reboots can be necessary depending to the number of upgrade to apply + .. image:: ../images/infrastructure/network/proceed_update.png + * repeat from the ``Check for upgrades`` operation until there is no upgrades to apply * Switch the principal/backup to restore ``pushkin`` as the principal: * on the current backup (pushkin here) go to `Virtual IPS status `_ * [3] click on `Leave Persistent CARP Maintenance Mode` + .. image:: ../images/infrastructure/network/reactivate_carp.png + * refresh the page, the role should have changed from ``BACKUP`` to ``MASTER`` * check on the other firewall, if the roles is indeed ``BACKUP`` for all the IPs