<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE SFTP backup failing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5144278#M590606</link>
    <description>&lt;P&gt;A similar SFTP setup is working for me.&lt;/P&gt;
&lt;P&gt;Have you added the username that ISE backup is using to the "sshd_config_default" file in Windows' OpenSSH?&lt;/P&gt;
&lt;PRE&gt;#CISCO ISE Backups&lt;BR /&gt;Match User domain\BackupISE&lt;BR /&gt;ChrootDirectory E:\Backups\ISEBackups&lt;/PRE&gt;
&lt;P&gt;Have you added that username as SFTP user account in Windows?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavonM_0-1720793793247.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223374i8D82C22C4E59E052/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavonM_0-1720793793247.png" alt="JPavonM_0-1720793793247.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 14:16:39 GMT</pubDate>
    <dc:creator>JPavonM</dc:creator>
    <dc:date>2024-07-12T14:16:39Z</dc:date>
    <item>
      <title>Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5142185#M590495</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have Cisco ISE cluster&amp;nbsp;&lt;SPAN&gt;3.2.0.542 and we brought up SFTP server on some Windows machine&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can validate SFTP server from ISE, and can start a backup process, but it fails at 75%, here are the logs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ciscoise01/admin#backup testbackup repository SFTP_BACKUP ise-config encryption-key plain xxxx&lt;BR /&gt;Warning: Do not use CTRL+C or close this terminal window until the backup is completed.&lt;BR /&gt;% backup in progress: Starting Backup...10% completed&lt;BR /&gt;% Internal CA Store is not included in this backup. It is recommended to export it using "application configure ise" CLI command&lt;BR /&gt;% Creating backup with timestamped filename: testbackup-CFG10-240709-1718.tar.gpg&lt;BR /&gt;% backup in progress: Validating ISE Node Role...15% completed&lt;BR /&gt;% backup in progress: Backing up ISE Configuration Data...20% completed&lt;BR /&gt;% backup in progress: Backing up ISE Indexing Engine Data...45% completed&lt;BR /&gt;% backup in progress: Backing up ISE Logs...50% completed&lt;BR /&gt;% backup in progress: Completing ISE Backup Staging...55% completed&lt;BR /&gt;% backup in progress: Backing up ADEOS configuration...55% completed&lt;BR /&gt;% backup in progress: Moving Backup file to the repository...75% completed&lt;BR /&gt;File transfer error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Anyone faced such problem?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 13:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5142185#M590495</guid>
      <dc:creator>Kamran Mustafayev</dc:creator>
      <dc:date>2024-07-09T13:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5142257#M590504</link>
      <description>&lt;P&gt;Is there enough space on your repository? Can you see anything in the logs on ISE or the SFTP server?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 15:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5142257#M590504</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2024-07-09T15:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5142470#M590509</link>
      <description>&lt;P&gt;debugging transfer issues with this command&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;debug transfer 7&lt;/LI-CODE&gt;
&lt;P&gt;And then run the backup command again - should give some clues.&lt;/P&gt;
&lt;P&gt;You say it's validated?&amp;nbsp; Does a "show repo ..." produce a directory listing?&amp;nbsp; Does the user account have write permissions?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 04:29:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5142470#M590509</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-07-10T04:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143023#M590532</link>
      <description>&lt;P&gt;I believe its some kind of permission to folder issues, just want to double check with you, here are the logs:&lt;/P&gt;&lt;P&gt;show repository SFTP_BACKUP&lt;BR /&gt;C:&lt;BR /&gt;E:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoise01/admin#debug transfer 7&lt;BR /&gt;ciscoise01/admin#backup testbackup repository SFTP_BACKUP ise-config encryption-key plain xxx&lt;BR /&gt;6 [888269]:[info] transfer: cars_xfer.c[333] [system]: sftp dir of repository SFTP_BACKUP requested&lt;BR /&gt;6 [888269]:[info] transfer: cars_xfer_util.c[2634] [system]: Server validation successful xx.xx.xx.xx&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[1215] [system]: Running sftp command: xx.xx.xx.xx xxx *** / ls -l /&lt;BR /&gt;6 [888269]:[info] transfer: sftp_handler.c[629] [system]: DEBUG: local user: admin UID: 0 sftp_run_parent FD: 5 remote host: xx.xx.xx.xx remote user: xxx command: ls -l /&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[639] [system]: fd is:5&lt;BR /&gt;7 [888270]:[debug] transfer: sftp_handler.c[322] [system]: Executing SFTP command: 0 admin /usr/bin/sftp -oIdentityFile=/home/admin/.ssh/id_rsa -oUserKnownHostsFile=/home/admin/.ssh/known_hosts -oPasswordAuthentication=yes xxx@ xx.xx.xx.xx&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[523] [system]: Found sftp prompt; No more data to read&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[1074] [system]: sftp parent status 0&lt;BR /&gt;7 [888269]:[debug] transfer: cars_xfer_util.c[2613] [system]: ssh_list xfer succeeded&lt;BR /&gt;Warning: Do not use CTRL+C or close this terminal window until the backup is completed.&lt;BR /&gt;% backup in progress: Starting Backup...10% completed&lt;BR /&gt;% Internal CA Store is not included in this backup. It is recommended to export it using "application configure ise" CLI command&lt;BR /&gt;% Creating backup with timestamped filename: testbackup-CFG10-240710-2144.tar.gpg&lt;BR /&gt;% backup in progress: Validating ISE Node Role...15% completed&lt;BR /&gt;% backup in progress: Backing up ISE Configuration Data...20% completed&lt;BR /&gt;% backup in progress: Backing up ISE Indexing Engine Data...45% completed&lt;BR /&gt;% backup in progress: Backing up ISE Logs...50% completed&lt;BR /&gt;% backup in progress: Completing ISE Backup Staging...55% completed&lt;BR /&gt;% backup in progress: Backing up ADEOS configuration...55% completed&lt;BR /&gt;% backup in progress: Moving Backup file to the repository...75% completed&lt;BR /&gt;6 [888269]:[info] transfer: cars_xfer.c[248] [system]: sftp copy out of /opt/backup/backup-testbackup-1720633445/testbackup-CFG10-240710-2144.tar.gpg requested&lt;BR /&gt;6 [888269]:[info] transfer: cars_xfer_util.c[2634] [system]: Server validation successful xx.xx.xx.xx&lt;BR /&gt;7 [888269]:[debug] transfer: cars_xfer_util.c[598] [system]: copying file to remote server: xx.xx.xx.xx with full path /testbackup-CFG10-240710-2144.tar.gpg&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[1313] [system]: Running sftp command: xx.xx.xx.xx xxx*** /testbackup-CFG10-240710-2144.tar.gpg put /opt/backup/backup-testbackup-1720633445/testbackup-CFG10-240710-2144.tar.gpg /testbackup-CFG10-240710-2144.tar.gpg&lt;BR /&gt;6 [888269]:[info] transfer: sftp_handler.c[629] [system]: DEBUG: local user: admin UID: 0 sftp_run_parent FD: 13 remote host: xx.xx.xx.xx remote user: xxx command: put /opt/backup/backup-testbackup-1720633445/testbackup-CFG10-240710-2144.tar.gpg /testbackup-CFG10-240710-2144.tar.gpg&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[639] [system]: fd is:13&lt;BR /&gt;7 [915332]:[debug] transfer: sftp_handler.c[322] [system]: Executing SFTP command: 0 admin /usr/bin/sftp -oIdentityFile=/home/admin/.ssh/id_rsa -oUserKnownHostsFile=/home/admin/.ssh/known_hosts -oPasswordAuthentication=yes xxx@xx.xx.xx.xx&lt;BR /&gt;&amp;gt; [888269]:[error] transfer: sftp_handler.c[1243] [system]: sftp_copy_callback: sftp copy failed. line:&amp;lt;dest open("/testbackup-CFG10-240710-2144.tar.gpg"): Permission denied&lt;BR /&gt;3 [888269]:[error] transfer: sftp_handler.c[934] [system]: sftp_run_parent Error: unable to handle sftp output&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[1074] [system]: sftp parent status -302&lt;BR /&gt;File transfer error&lt;BR /&gt;ciscoise01/admin#undebug all&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 18:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143023#M590532</guid>
      <dc:creator>Kamran Mustafayev</dc:creator>
      <dc:date>2024-07-10T18:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143024#M590533</link>
      <description>&lt;P&gt;Yes, there are enough space on repo, just posted the debugs from ISE below fyi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;will try to get logs from sftp as well&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 18:02:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143024#M590533</guid>
      <dc:creator>Kamran Mustafayev</dc:creator>
      <dc:date>2024-07-10T18:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143030#M590534</link>
      <description>&lt;P&gt;I believe its some kind of permission to folder issues, just want to double check with you, here are the logs:&lt;/P&gt;&lt;P&gt;show repository SFTP_BACKUP&lt;BR /&gt;C:&lt;BR /&gt;E:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoise01/admin#debug transfer 7&lt;BR /&gt;ciscoise01/admin#backup testbackup repository SFTP_BACKUP ise-config encryption-key plain xxx&lt;BR /&gt;6 [888269]:[info] transfer: cars_xfer.c[333] [system]: sftp dir of repository SFTP_BACKUP requested&lt;BR /&gt;6 [888269]:[info] transfer: cars_xfer_util.c[2634] [system]: Server validation successful xx.xx.xx.xx&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[1215] [system]: Running sftp command: xx.xx.xx.xx xxx *** / ls -l /&lt;BR /&gt;6 [888269]:[info] transfer: sftp_handler.c[629] [system]: DEBUG: local user: admin UID: 0 sftp_run_parent FD: 5 remote host: xx.xx.xx.xx remote user: xxx command: ls -l /&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[639] [system]: fd is:5&lt;BR /&gt;7 [888270]:[debug] transfer: sftp_handler.c[322] [system]: Executing SFTP command: 0 admin /usr/bin/sftp -oIdentityFile=/home/admin/.ssh/id_rsa -oUserKnownHostsFile=/home/admin/.ssh/known_hosts -oPasswordAuthentication=yes xxx@ xx.xx.xx.xx&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[523] [system]: Found sftp prompt; No more data to read&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[1074] [system]: sftp parent status 0&lt;BR /&gt;7 [888269]:[debug] transfer: cars_xfer_util.c[2613] [system]: ssh_list xfer succeeded&lt;BR /&gt;Warning: Do not use CTRL+C or close this terminal window until the backup is completed.&lt;BR /&gt;% backup in progress: Starting Backup...10% completed&lt;BR /&gt;% Internal CA Store is not included in this backup. It is recommended to export it using "application configure ise" CLI command&lt;BR /&gt;% Creating backup with timestamped filename: testbackup-CFG10-240710-2144.tar.gpg&lt;BR /&gt;% backup in progress: Validating ISE Node Role...15% completed&lt;BR /&gt;% backup in progress: Backing up ISE Configuration Data...20% completed&lt;BR /&gt;% backup in progress: Backing up ISE Indexing Engine Data...45% completed&lt;BR /&gt;% backup in progress: Backing up ISE Logs...50% completed&lt;BR /&gt;% backup in progress: Completing ISE Backup Staging...55% completed&lt;BR /&gt;% backup in progress: Backing up ADEOS configuration...55% completed&lt;BR /&gt;% backup in progress: Moving Backup file to the repository...75% completed&lt;BR /&gt;6 [888269]:[info] transfer: cars_xfer.c[248] [system]: sftp copy out of /opt/backup/backup-testbackup-1720633445/testbackup-CFG10-240710-2144.tar.gpg requested&lt;BR /&gt;6 [888269]:[info] transfer: cars_xfer_util.c[2634] [system]: Server validation successful xx.xx.xx.xx&lt;BR /&gt;7 [888269]:[debug] transfer: cars_xfer_util.c[598] [system]: copying file to remote server: xx.xx.xx.xx with full path /testbackup-CFG10-240710-2144.tar.gpg&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[1313] [system]: Running sftp command: xx.xx.xx.xx xxx*** /testbackup-CFG10-240710-2144.tar.gpg put /opt/backup/backup-testbackup-1720633445/testbackup-CFG10-240710-2144.tar.gpg /testbackup-CFG10-240710-2144.tar.gpg&lt;BR /&gt;6 [888269]:[info] transfer: sftp_handler.c[629] [system]: DEBUG: local user: admin UID: 0 sftp_run_parent FD: 13 remote host: xx.xx.xx.xx remote user: xxx command: put /opt/backup/backup-testbackup-1720633445/testbackup-CFG10-240710-2144.tar.gpg /testbackup-CFG10-240710-2144.tar.gpg&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[639] [system]: fd is:13&lt;BR /&gt;7 [915332]:[debug] transfer: sftp_handler.c[322] [system]: Executing SFTP command: 0 admin /usr/bin/sftp -oIdentityFile=/home/admin/.ssh/id_rsa -oUserKnownHostsFile=/home/admin/.ssh/known_hosts -oPasswordAuthentication=yes xxx@xx.xx.xx.xx&lt;BR /&gt;&amp;gt; [888269]:[error] transfer: sftp_handler.c[1243] [system]: sftp_copy_callback: sftp copy failed. line:&amp;lt;dest open("/testbackup-CFG10-240710-2144.tar.gpg"): Permission denied&lt;BR /&gt;3 [888269]:[error] transfer: sftp_handler.c[934] [system]: sftp_run_parent Error: unable to handle sftp output&lt;BR /&gt;7 [888269]:[debug] transfer: sftp_handler.c[1074] [system]: sftp parent status -302&lt;BR /&gt;File transfer error&lt;BR /&gt;ciscoise01/admin#undebug all&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 18:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143030#M590534</guid>
      <dc:creator>Kamran Mustafayev</dc:creator>
      <dc:date>2024-07-10T18:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143038#M590535</link>
      <description>&lt;P&gt;I agree, seems like a permission issue. What SFTP server software are you using?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 18:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143038#M590535</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2024-07-10T18:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143309#M590548</link>
      <description>&lt;P&gt;Its an OpenSSH on Windows VM&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 05:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5143309#M590548</guid>
      <dc:creator>Kamran Mustafayev</dc:creator>
      <dc:date>2024-07-11T05:38:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE SFTP backup failing</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5144278#M590606</link>
      <description>&lt;P&gt;A similar SFTP setup is working for me.&lt;/P&gt;
&lt;P&gt;Have you added the username that ISE backup is using to the "sshd_config_default" file in Windows' OpenSSH?&lt;/P&gt;
&lt;PRE&gt;#CISCO ISE Backups&lt;BR /&gt;Match User domain\BackupISE&lt;BR /&gt;ChrootDirectory E:\Backups\ISEBackups&lt;/PRE&gt;
&lt;P&gt;Have you added that username as SFTP user account in Windows?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JPavonM_0-1720793793247.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/223374i8D82C22C4E59E052/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JPavonM_0-1720793793247.png" alt="JPavonM_0-1720793793247.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 14:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-sftp-backup-failing/m-p/5144278#M590606</guid>
      <dc:creator>JPavonM</dc:creator>
      <dc:date>2024-07-12T14:16:39Z</dc:date>
    </item>
  </channel>
</rss>

