IBM Support

Firmware 3.0.0 update for QRadar M4 appliances (2U)(Updated)

Release Notes


Abstract

This firmware update (3.0.0) provided by IBM is the latest firmware for your IBM® Security QRadar® M4 appliances with easier to follow installations procedures. This update is only intended for 2U form factor QRadar appliances.

Content



This page outlines important information about the re-publication of the M4 appliance firmware upgrade for administrators who need to update QRadar M4 (2U form factor) appliances. This article covers the new installation process for QRadar M4 appliances. The firmware instructions listed in this article are the only supported method of updating firmware for QRadar appliances.


About firmware updates


To update the firmware on an M4 appliance, administrators can use a Windows host with the Bootable Media Creator (BoMC) software tool to create a USB drive that is suitable for applying firmware updates. Administrators must be on-site (on premise) with the appliance to complete this firmware update using a USB flash drive.



Supported appliances, types, and model information


This firmware update applies to the following IBM Security QRadar M4 (2U form factor) appliances, server type, or Machine type models:

Hardware Details
Appliance IBM Security QRadar xx05 G2
IBM Security QRadar xx28 G2
IBM Security QRadar Incident Forensics xx28
IBM Security QRadar Packet Capture xx28
IBM Security QRadar Packet Capture Data Node xx28
Server Type x3650 M4 BD
Server Machine Type 5466
Appliance Machine type models (MTM) 4380-Q1E
4380-Q2E
4531-G1E
4531-G2E
4531-G3E


Important file changes and prerequisites in this firmware update


The table below lists important updates in the Base System Pack and HDD update. Administrators must ensure that their M4 appliance includes the minimum version outlined in the Pre-requisite version column. If your M4 appliance does not meet the pre-requisite versions outlined in the table below, the administrator will need to contact IBM QRadar Support to have a custom upgrade path defined for the M4 appliance.

Component Pre-requisite version Firmware version in this update Updated from last firmware release? File name 
IMM2 4.35 or later 1aoo74f-5.80 Yes ibm_fw_imm2_1aoo74f-5.80_anyos_noarch
UEFI/BIOS  None yoe116b-1.70 Yes ibm_fw_uefi_yoe116b-1.70_anyos_32-64
DSA  None dsyte2r-9.65 No, same as 2.0.3 ibm_fw_dsa_dsyte2r-9.65_anyos_32-64
Emulex* None 15b-2.02x11-32 No, same as 2.0.3 elx_fw_fc_15b-2.02x11-32_linux_32-64
RAID Controller M5210 None 5200-24.12.0-0033 Yes ibm_fw_sraidmr_5200-24.12.0-0033_linux_32-64
RAID Controller M5110 None 6gb-23.34.0-0016 Yes ibm_fw_sraidmr_5100-6gb-23.34.0-0016_linux_32-64
HDD Update  None 1.21.00 Yes ibm_fw_hdd_sas-1.21.00_linux_32-64
Backplane None 6gb-v2-sas-52f5 No, same as 2.0.3 ibm_fw_exp-6gb-v2-sas-52f5_linux_32-64
For general firmware questions and information see our FAQ page at http://ibm.biz/qradarfirmware.
* If the Emulex card firmware does not install as intended or you experience an issue, you can continue the firmware installation and any Emulex issues will be addressed in the next firmware update.


Notes:

  • Administrators MUST enable IMM.Over.LAN on the xSeries appliance BEFORE the firmware update is applied. For information on how to enable this setting, see: http://www.ibm.com/support/docview.wss?uid=swg21982944.
  • A number of hard disk drives can be installed in this appliance. The HDD update tool examines the hard disk drives that are present and selects the most current firmware level that is available.
  • The base system pack contains other firmware packages that are not in QRadar appliances. Therefore, these packages appear when the tool runs, but have a status of "undetected" and not selected to be updated.
  • This firmware update installs IMM2 firmware version 5.60. Administrators should be aware that IMM2 v5.60 requires Java version 8 to function properly. If administrators are not on Java version 8 or are unable to install Java version 8, then they might need to postpone this M4 appliance firmware update.

Full Release Notes from Lenovo for firmware 3.0 updates


Change files (.chg) can be opened by any text editor. These files contain the full release notes provided by Lenovo to IBM for both CVEs and resolved issues that administrators might want to review.
Component File name  CVEs resolved in this package
IMM2 ibm_fw_imm2_1aoo74f-5.80_anyos_noarch CVE-2016-4448, CVE-2016-2108, CVE-2016-2107, CVE-2016-2105, CVE-2016-2106, CVE-2016-2109, CVE-2015-8806, CVE-2016-4447, CVE-2016-4449, CVE-2015-8138, CVE-2015-5185, CVE-2016-3627, CVE-2016-3705, CVE-2008-5161, CVE-2015-5012, CVE-2011-1473, CVE-2016-2842, CVE-2013-7041, CVE-2013-4242, CVE-2014-3591, CVE-2015-0837
UEFI/BIOS  ibm_fw_uefi_yoe116b-1.70_anyos_32-64 None
DSA  ibm_fw_dsa_dsyte2r-9.65_anyos_32-64 CVE-2014-9761, CVE-2015-1819, CVE-2015-3197, CVE-2015-5312, CVE-2015-7497, CVE-2015-7498, CVE-2015-7499, CVE-2015-7500, CVE-2015-7547, CVE-2015-7941, CVE-2015-7942, CVE-2015-7981, CVE-2015-8126, CVE-2015-8241, CVE-2015-8242, CVE-2015-8317, CVE-2015-8704, CVE-2015-8710, CVE-2015-8776, CVE-2015-8777, CVE-2015-8778, CVE-2015-8779, CVE-2016-0702, CVE-2016-0705, CVE-2016-0755, CVE-2016-0797, CVE-2016-0800
Emulex* elx_fw_fc_15b-2.02x11-32_linux_32-64 None
RAID Controller M5210 ibm_fw_sraidmr_5200-24.12.0-0033_linux_32-64 None
RAID Controller M5110 ibm_fw_sraidmr_5100-6gb-23.34.0-0016_linux_32-64 None
HDD Update  ibm_fw_hdd_sas-1.21.00_linux_32-64 None
Backplane ibm_fw_exp-6gb-v2-sas-52f5_linux_32-64 None

NOTE: A full change log of all files that can be read by creating the USB drive and navigate to \BootableMediaCreatorv9_66\workingdir\.. This directory has a historical list of all files that are packaged with the firmware update, not just the latest changes as outlined below in the attached file. Qradar_2U_M4_MT5466_xx05_xx28_QIF_PCAP_Firmware_Update_3_0_0.chgQradar_2U_M4_MT5466_xx05_xx28_QIF_PCAP_Firmware_Update_3_0_0.chg


Where to find more information

Installing Firmware with the IBM Bootable Media Creator (BoMC)


This installation method uses the IBM Bootable media creator (BOMC) tool on a Windows host to create a bootable USB drive that is capable of installing the M4 firmware update for QRadar 2U appliances. The firmware update can take up to 60 minutes for each host. Use a USB drive of 4GB or larger to ensure enough free space to successfully create the bootable media.

You can use the IBM Bootable Media Creator to update the firmware on the following QRadar appliances:

Hardware Details
Appliance IBM Security QRadar xx05 G2
IBM Security QRadar xx28 G2
IBM Security QRadar Incident Forensics xx28
IBM Security QRadar Packet Capture xx28
IBM Security QRadar Packet Capture Data Node xx28
Server Type x3650 M4 BD
Server Machine Type 5466
Appliance Machine type models (MTM) 4380-Q1E
4380-Q2E
4531-G1E
4531-G2E
4531-G3E


Before you begin


Creating your USB flash drive for the firmware update requires a Windows host and the administrator or USB drive must be on-site with the appliance. The firmware update can take up to 60 minutes complete per appliance and the administrator will be required to reboot the appliance after the firmware install completes. The firmware upgrade procedures should only be done during a change window or during maintenance time for your QRadar appliances. A 4GB USB key is required to complete the procedure outlined below.

**IMPORTANT**: Administrators MUST enable IMM.Over.LAN on the xSeries appliance BEFORE the firmware update is applied. For information on how to enable this setting, see: http://www.ibm.com/support/docview.wss?uid=swg21982944.


Required files
Download the QRadar M4 appliance firmware update (2U form factor appliances) from IBM Fix Central: http://www.ibm.com/support/fixcentral/swg/quickorder?parent=Security%2BSystems&product=ibm/Other+software/IBM+Security+QRadar+SIEM&release=7.2.0&platform=Linux&function=fixId&fixids=7.2.0-QRADAR-FIRMWARE-M4-xx05-xx28-QVM-QRM-QIF-PCAP-3.0.0&includeRequisites=1&includeSupersedes=0&downloadMethod=http&source=fc

Preparing

  1. Copy the M4 appliance firmware EXE to a directory on the Windows host.

  2. Double-click on the Qradar_2U_M4_MT5466_xx05_xx28_QIF_PCAP_Firmware_Update_3_0_0.exe file.

  3. Select or type a directory path for the M4 firmware update and click Extract.

    (Click to enlarge image)

  4. This will create a folder named Extract to path/Qradar_2U_M4_MT5466_xx05_xx28_QIF_PCAP_Firmware_Update_3_0_0\BootableMediaCreatorv9_66\


Creating your USB key


  1. Navigate to the directory containing the extracted M4 Firmware files.
    For example: C:\Qradar_2U_M4_MT5466_xx05_xx28_QIF_PCAP_Firmware_Update_3_0_0\BootableMediaCreatorv9_66\

  2. Right-click ibm_utl_bomc_9.66_windows_i386.exe and select Run As Administrator.


    (Click to enlarge image)
    NOTE: Depending on your current permissions, you might be required to type the username and password for the local administrator account.


  3. On the Welcome page, click Next.
    IMPORTANT: Do NOT select the Check for the latest version of this tool check box. These instructions are specific to IBM Bootable Media Creator 9.66, which is packaged with the EXE file.

    (Click to enlarge image)


  4. On the Media Purpose page, select the Updates check box and click Next.

    (Click to enlarge image)
  5. Select Look in a local directory.



    NOTE: The path to the workingdir should be inserted automatically when you select Look in a local directory.
    If the path is not populated, the local directory should be the "Extract to path"\Qradar_M4_MT5466_xx05_xx28_QIF_PCAP_Firmware_Update_3_0_0\BootableMediaCreatorv9_66\workingdir.
  6. Ensure that the USB has at least 4 GB of available space for the media format page and that your USB drive is inserted in to the Windows host.

  7. On the Media Format page, select USB as the Device Type, the Disk, select the Write directly to device option, and click Next.

    (Click to enlarge image)
  8. Select Do not use unattended mode option when prompted and click Next.

    (Click to enlarge image)

  9. Confirm the configuration for the USB drive and click Next.
    Important: Do NOT remove the USB device until the bootable media creation displays a notification that the process is complete. You might be prompted to erase the USB drive before you continue.


    (Click to enlarge image)



  10. RESULTS


    When complete, you are prompted to safely eject the USB drive, click Next, then click Finish.







Updating your QRadar M4 appliance


The instructions below are intended for M4 appliances that are not configured as HA (high-availability) pairs. If your appliance is in a HA pair, you must use the High-Availability update instructions found here: http://www.ibm.com/support/docview.wss?uid=swg27047121#HA


    Procedure
  1. Insert the USB drive that has the bootable image into the QRadar appliance.

  2. From the terminal of the KVM switch for the appliance, log in by using the root credentials.

  3. From the command prompt, type: reboot.
  4. As the appliance is rebooting, press the F12 key to select a boot device.

  5. Select the bootable firmware image, for example, USB Storage and Press Enter.

  6. Results The IBM ToolsCenter software is booted.

    IMPORTANT: Do not remove the USB flash drive until the IBM ToolsCenter completes the firmware installation.



Applying M4 firmware using the IBM Bootable Media Creator Tool

  1. The IBM ToolsCenter Welcome page is displayed.

  2. When prompted, select the Updates option.

  3. Verify that the bootable media shows the correct machine type for the appliance.
    Hardware Details
    Server Type x3650 M4 BD
    Server Machine Type 5466

    NOTE: Verify that the Updates list contains x3650 M4 BD -- machine type 5466 in the updates list.

  4. To start the update link, select Click here to start update.

  5. Select your language and click I accept the terms in the license agreement to continue.

    (Click to enlarge image)
  6. The IBM UpdateXpress System Pack Installer compares the current package with the installed firmware.

    (Click to enlarge image)
  7. From the list of selected firmware items, verify that the selected items match the firmware items to update.

    (Click to enlarge image)
  8. To start applying the updates, click Next on the Update Options page.
    The bootable media creator starts to install firmware on the M4 appliance.
  9. Verify that all the firmware updates are applied, and click Next to complete the update.

    (Click to enlarge image)
  10. After the update is complete, click Save Log to save the installation log to the USB flash drive. This file can be provided to support in case any issues occurred during the update.

    (Click to enlarge image)
  11. Select the USB flash drive and click OK.

    (Click to enlarge image)
  12. When all updates are complete, click Finish to reboot the appliance.

  13. The appliance reboots and starts up normally.


Where to find more information

Original Publication Date

14 December 2015

[{"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Hardware","Platform":[{"code":"PF016","label":"Linux"}],"Version":"7.3.1;7.3;7.2.8;7.2","Edition":"","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
10 May 2019

UID

swg27048983