{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
{{sendMatomoQuery("Sangfor Cloud Platform (SCP)","Patch Upgrade")}}

Patch Upgrade

{{ $t('productDocDetail.updateTime') }}: 2026-01-08

Function Description:

Sangfor SCP platform supports online patch upgrades and can obtain the latest patch information regularly to ensure the stability and security of the equipment.

Precautions:

  1. When the SCP manages the HCI cluster, you only need to enable the online SP service on the SCP, and the HCI does not need to be configured.
  2. It is not recommended that the management network directly access the online SP service, which is not conducive to its security.
  3. After the online SP service is configured, the connectivity must be tested to ensure that the platform can connect to the patch server.
  4. Use the Sangfor network proxy virtual machine to access the Online SP Center mode. Do not modify the virtual machine name after importing the network proxy virtual machine (the default name is _SangforaOperation_VM_WorkStation_). Otherwise, the proxy service will become invalid.

Prerequisites:

The customer network needs to allow the address update1.sangfor.net of Sangfor's patch server to ensure that the platform can access the patch server.

Steps:

Step 1.Navigate to Resources > Management > System Maintenance and Upgrade > Service Packs > Settings, and check the Enable online SP service checkbox.

Graphical user interface, text, application, email  Description automatically generated

When the Online SP Service is not turned on or the patch platform is not connected, the Patch Alert icon will appear in the upper right corner of the platform, click to view the reminder, and you can scan the SCP or the QR

code of each cluster to obtain the corresponding patch information, according to the provided download link, completes the patch download.

Graphical user interface  Description automatically generated

Step 2.Click SP Central Addresses to obtain the access address of the online patch platform.

Graphical user interface, text, application  Description automatically generated

Users need to allow the address shown in the table below in the corresponding gateway device to ensure that the SCP or proxy can access it.

Server IP Address

Description

Requirement

https://cloudbgcop.sangfor.com

Cloud Server IP Address.

Must be allowed.

http://update1.sangfor.net

Online SP center IP Address.

Allow at least one of the IPs. It is recommended to allow multiple.

http://update2.sangfor.net

http://update3.sangfor.net

http://121.46.26.221

Step 3.Configure the communication method with the online SP center.

Scenario 1: Directly access to an online SP center.

Graphical user interface, text, application  Description automatically generated

Scenario 2: Use a third-party proxy server to access the SP server.

Click Download Deployment Guide. Refer to the Deployment Guide for Third-Party Proxy Server document to install and configure the third-party agent program and confirm that the agent server can access the online patch server address in Step 2. Deploy two incoming interfaces as shown in the figure below, one can access the Internet to connect to the Sangfor patch server, and the other can access the HCI platform of the intranet.

Text  Description automatically generated

Fill in the proxy address (IP + port, example: 10.250.0.20:3128) set above on the SCP platform. And the proxy authentication username and password are set during the deployment of the proxy server.

The IP address is the IP of the internal incoming interface of the proxy server.

The port is the publishing port of the proxy service, and the default is 3128.

Click the Test Connectivity button to confirm that the network is connected.

Graphical user interface, text, application, email  Description automatically generated

Scenario 3: The SCP platform cannot be connected to the Internet, and the SP server has been set up in the local data center.

Select Access Online SP Center via On-Premises Sangfor SP Server.

Graphical user interface, text, application  Description automatically generated

Contact Sangfor Technical Support to obtain the vma template of the offline patch server.

Import the virtual machine of the offline patch server under Virtual Machine > New > Import Virtual Machine.

After importing, click More >Edit on the specified virtual machine. Edit the network card and connect to the planned network.

Open the VM console and enter the default username and password: admin/Sangforupdater. After successful login, the system will ask to change the default password. Please configure a new password.

Text  Description automatically generated

Use the initsrv command to modify the IP address, netmask, gateway, and DNS. Pressing Y to save the configuration will automatically restart the olu server to complete the configuration.

Confirm the network card configuration and check the connectivity of the network.

Text  Description automatically generated

Confirm the network card configuration and check the connectivity of the network.

Text  Description automatically generated with low confidence

Enter the command moashell. The QR code pop up. The QR code pop up. Scan it with Sangfor Pocket Assistant (MOA), get the password from the Pocket Assistant Little Assistant, and enter it into the command line. (Need Sangfor technical support processing).

Shape, rectangle  Description automatically generated

Qr code  Description automatically generated with low confidence

Create a user used by the olu server, set a password, and change the group of the olu user to root.

Graphical user interface, text  Description automatically generated

Use the newly added olu account to log in to the patch server, upload the patch package of the SCP and NFV device to the /var/wwwroot directory through the sftp tool, and view it in the SCP patch list after decompression.

Shape, rectangle  Description automatically generated

After configuring the Olu server, test the connectivity of the SP patch server on the SCP interface, fill in the address of the SP patch server, and click Test Connectivity.

Graphical user interface, text, application, email  Description automatically generated

Step 4.NFV patch upgrade settings need to log in to a single cluster and go to System Maintenance and Upgrade > Upgrade to edit. For details, please refer to Sangfor Hyper-Converged HCI Version 6.7.0 User Manual.

Step 5.Set emergency contacts (Optional) and click Save after confirming the correct information.

Graphical user interface, text, application, email  Description automatically generated

Step 6.Navigate to the System Maintenance and Upgrade > Service Packs > SCP Service Packs. You can make patch upgrade-related settings.

Click Check for SPs, and the platform will immediately initiate a patch request.

Graphical user interface, text  Description automatically generated with medium confidence

Click Update Settings. Auto has been selected by default under SP installation. After the patch is obtained online, it will be automatically downloaded and upgraded from 1:00 to 6:00 in the morning. It is recommended to keep the default selection of automatic upgrade, and also support manual upgrade. If you choose to download manually, click OK for the un-upgraded patch in the patch list to start downloading and upgrading.

Graphical user interface, text, application  Description automatically generated

SP patches only support manual upgrade, which requires the user to display the pre-conditions and upgrade impact according to the patch list. When the impact is acceptable, the user clicks to execute Upgrade.