Mitch, I found this in the documentation and it leads you to believe that newer versions of FW do not have the restrictions that you are talking about.
Have you seen this before or tried using a scp host for FW upgrades?
Download from SCP-enabled file server procedure
This section describes the procedures for installing firmware from a file server
that is enabled for Secure Copy (SCP) and is on the customer's network.
Note: This capability is available only on Communication Manager Release 3.1 or
higher.
Hardware/software requirements
The procedures in this section describe how to use a central firmware depository
on an SCP-enabled file server to update one or all of your non-self-downloadable
circuit packs and the following versions of self-downloadable circuit packs:
- TN799DP CLAN circuit pack, firmware version 17 or higher
- TN2602AP IP Media Resource 320, firmware version 20 or higher
- TN2501AP VAL circuit pack, firmware version 10 or higher
If the previously-identified self-downloadable circuit packs do not have the
minimum firmware version, you must upgrade them manually first using the
procedure in Self and C-LAN-distributed download procedure on page 4.
Signed files
In order to upgrade circuit packs using firmware from a file server, the
firmware images that you install must be signed according to SCP encryption
guidelines. Signed firmware images have filenames with the format
tnXXXXXX_fXX_sig.bin, where _sig indicates the firmware is signed. For example,
tn2602AP_f212_sig.bin would be the name of a signed firmware images for the
TN2602 circuit pack. Signed firmware image files may also be installed using the
manual process. Signed firmware image files for non-self-downloadable circuit
packs may be installed on the target circuit pack regardless of the version of
the previous firmware image.
Checking the firewall settings
To check the firewall settings, perform the following steps:
1. On the Maintenance Web page menu, under Security, select Firewall.
The Firewall Web page appears.
2. Verify that the Input to Server and Output from Server check boxes are
selected for snmp and snmptrap.
A great teacher, does not provide answers, but methods to teach others "How and where to find the answers"
bsh
37 years Bell, AT&T, Lucent, Avaya
Tier 3 for 27 years and counting