Netscreen ScreenOS

Oct 03, 2005 28 Replies

I said I have a problem with vendors who won't sell me an available update, hoping I will spend more for the current product. I did not say I would solve that problem by obtaining the update illicitly. I'd be more likely to take my business elsewhere.

My intent was to elicit debate. You assumed I was taking a position.

Agreed, but in this case the vendor is not offering the update, via a support contract or otherwise, at any price. I fail to see a downside to their making it freely available on an as-is (unsupported) basis, indeed doing so might enhance their reputation somewhat and reduce the probability of complaints from users of illicit (potentially compromised) firmware.

Triffid

I wasn't aware that you could still get support for the 5XP. If so, then of course that's the correct thing to do and pirating firmware is not.

Curious: how much do you pay for your support on a box that is no longer having new firmware developed for it?

We probably could re-start this disussion using some other out-of-date product like an NS10, NS100, NS1000, I'm pretty sure you can't buy support for those units any more.

-Russ.

I have a support contract for my WatchGuard firewall units, with the support contract I can download any version of their software for any appliance that I am marked as owning - you register their serial numbers and they provide access to the firmware/software. All updates, supported or not, are available to me because I have kept the support agreement on at least one current product.

First of all, I didn't download the firmware to Robert because I do not understand what is legal or not.

I have a story which doesn't really applies because I got maintenance for all the product. Once, I ordered 10 NS-25 to a official Netscreen reseller. I received first 3 NS-25 labelled Netscreen shipped with 5.0.0 realese. Few weeks later, I received 5 NS-25 labelled Juniper shipped with

5.0.0r4 release. And few weeks later, I received the 2 NS-25 left labelled Juniper whipped with 5.0.0r6. Hopefully I got maintenance so I upgraded them with 5.0.0r8. But without maintenance, what should I have to do ? Upgrade the 8 first NS-25 to 5.0.0r8 release or downgrade the 7 last NS-25 to 5.0.0 ? According to your messages, there is no legal solution except pay a maintenance for all units (what i have done). But this was the same order, so I am awaiting to received 10 units with the same release. Some of you will say this is release and not version as the Robert's case. Is there a legal difference between release and version ?

Is someone able to get the official answer of Juniper ?

Netscreen used to work that way. I'm not sure anyone is entirely clear how Juniper works it.

Triffid

Yes, and they still do. The question is how they are handling obsolete products for which customers run but don't have the last (old) firmware.

-Russ.

Not consistently, IME - see below

Indeed - especially cases where the user obtained the unit as a discard from work, or perhaps on ebay, and would like to update and run it at home. Not state of the art, but still safer than the NAT router they probably have now, and an opportunity to learn. Overall, a good thing for both user and vendor IMHO.

I bought new-in-box 5GT on ebay to replace my NAT router - came with

4.something, and the DI and AV subscriptions had expired since it originally shipped just over 12 months before I bought it. Juniper said I would have to ship the unit to them (at my cost both ways) for 'inspection' before they would take my $ for a support contract. They refused to sell updates or subscriptions otherwise - send it to us, or run it as-is. Screw that.

So I log into my TAC account and grab the latest 5GT firmware. Legal? I dunno, AFAIK the smallest unit registered on my account is a 500, but I appear to have access to all firmware for all boxes. The other day a colleague at work needed to update a 208, he's sure he has several registered, but his TAC account wouldn't give him the file. Mine did. Fouled up or what?

You're even worse off if you own a unit Juniper considers obsolete - so I won't be berating individuals who own one old NS box for asking after firmware updates on the newsgroups. I won't give (or sell) them firmware updates either - but Juniper should IMHO.

Triffid

We've been beating on them hard to offer non-hardware support, but so far they won't budge. Imagine your 500 was off support and you realize that your needs have changed, you need tech support and firmware support, but the same thing happens -- they won't debundle it from the hardware support and you have to pay all the back-dues since the hardware support went off, or, send it to them for inspection. Now imagine it's a 5200 and a year of back-support is gonna cost you five figures... just to earn the privledge of paying another 5 figures for the current year's support...

Juniper really, really has to just give themselves a shake and put themselves in their customer's shoes for a bit... they have great products that they are somehow managing to turn into a nightmare for their clients. Hopefully somebody up there will fix it soon. The fixes truly aren't that complicated.

  1. Offer 1-time obsolete firmware purchase option for very little money, or even free
  2. Break up tech support, software support, hardware support into separate packages
  3. Publish DI and AV throughput number ranges
  4. Track ticket response times and FIX them when they see how broken they are

-Russ.

Couldn't agree more.

  1. Clean up and document debug (without crippling it, please), then teach tech support how to use it effectively.

Not only are ticket response times abysmal, tech support rarely resolves a damn thing.

IME the way to nail down ScreenOS issues is to bang away with debug in the lab. The problem with debug is it spits out whatever the module developer found useful during coding - so there is no consistency of format or content across modules, and no documentation. Consequently, few of the techs know how to configure debug effectively or interpret the results - especially when clustered virtual systems are in play.

I find it more efficient to do my own debugging, interpreting the output as best I can, and open a ticket only when I have clear evidence of anomalous behavior I can't work around, or I need help decoding debug babble.

I've managed to extract rudimentary scraps of documentation from developers a couple of times, occasionally they'll suggest trying something that may not have occurred to me yet proves helpful, but in general tech support has been fairly useless. I often resolve tickets myself, by finding a fix or workaround. I've been known to sit on a fix for 3 weeks waiting for them to toss the ticket back :-) To give them some credit, fixes often appear in a subsequent release note.

Triffid

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required