Problem Statement
A G450 media gateway firmware upload over SCP fails before any bytes are transferred. The download status shows the running state as idle and the failure display reports that the SCP server offered a non-approved Diffie-Hellman group.
Impact
The firmware image is not copied to the target image bank, so the media gateway cannot be upgraded until the SCP key-exchange compatibility issue is resolved. The gateway may remain on the current firmware until the boot bank is set and the gateway is rebooted after a successful upload.
Alarm
SCP - Aborted: server offered non-Approved DH group
Troubleshooting Steps
- Check the software download status for the affected module using a command such as `show download software status <module-number>`. Confirm the source file, destination image bank, running state, failure display, and bytes downloaded.
- If the failure display is `SCP - Aborted: server offered non-Approved DH group` and `Bytes Downloaded` is `0`, treat the issue as an SCP/SSH key-exchange compatibility problem between the media gateway and the SCP server.
- Review the media gateway SSH server configuration with commands such as `show ciphers`, `show kex-algorithms`, and `show macs`. Record the configured ciphers, key-exchange algorithms, and MAC algorithms.
- Review the media gateway SSH client configuration with commands such as `show ciphers`, `show kex-algorithms`, and `show macs`. Confirm that the client side includes an approved key-exchange algorithm compatible with the SCP server.
- Review the SCP server SSH configuration with the server support team. Ensure the SCP server offers an approved Diffie-Hellman key-exchange group that is compatible with the media gateway configuration.
- After correcting the SCP/SSH compatibility issue, retry the firmware upload to the intended image bank and recheck `show download software status <module-number>` to confirm the transfer no longer aborts.
- Check the installed image banks with `show image version` to confirm the new firmware is present in the alternate bank.
- Set the boot bank to the bank containing the new firmware, then reboot the media gateway during an approved maintenance or break/fix window.
- After reboot, verify the new firmware is active using `show image version` and confirm the media gateway is registered to the core using a command such as `list media-gateway`.
- Monitor the gateway after the reboot to confirm it remains stable and registered.
Resolution
The SCP firmware upload issue was resolved after the SSH/SCP Diffie-Hellman group compatibility problem was addressed. The boot bank was then set to the bank containing the new firmware and the media gateway was rebooted. After reboot, firmware version 43.28.0 was active, the G450 media gateway was registered to the core, and it remained stable overnight.