cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2406
Views
5
Helpful
9
Replies

How to replace C670 appliance with C690

pbabu6001
Level 1
Level 1

I am going to replace C670 appliance with C690 IronPort appliance. Could you please provide a step by step document or video to complete this. Actually we have 4 C670 appliances in our evnironment with M1070.

-C670 appliances are running with 9.7.1-066 version and M1070 at 9.6.0-051.

2 Accepted Solutions

Accepted Solutions

Libin Varghese
Cisco Employee
Cisco Employee

Hi,

In order to move configuration from one appliance to another, both devices should be on the same Async OS release.

You would need to start by upgrading the appliances so that they are on the same Async OS version.

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117793-technote-esa-00.html

The configuration file can be exported from the GUI System Administration -> Configuration File.

Note: Please ensure the configuration file is exported with passwords unmasked.

Alternatively, you could also add a device to an existing cluster to copy over the cluster level configuration.

Steps to import the configuration file is available below:
http://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117841-technote-esareplace-00.html

For appliances of different models such as x70 and x90 series in your scenario, when importing the configuration file between different models of appliances, you will frequently receive errors. These are caused by differences in available Ethernet ports, and database sizes for tracking and reporting.

You will need to make some manual modifications to the file in order for it to import:

1. Export the configuration file from both the source and destination ESAs. Be sure to uncheck the 'Mask passwords' option
2. Open both configuration files in a text editor
3. Find the following entries in both configuration files, and copy the values from the destination appliance's configuration file to the source configuration file:
<db_environment_actual_size>
<tracking_global_max_db_size>
4. If the appliances have a different number of Ethernet interfaces, you will need to completely remove the following sections from the source configuration file:
<ethernet_settings> ... </ethernet_settings>
<ports> ... </ports>
5. Save a copy of the modified source configuration file
6. Import the modified configuration file on the destination appliance
7. Commit the changes

Only configuration files are transferred between ESA's. All local logs, tracking, reports, quarantines, etc would need to be moved to the SMA or pushed to syslog/scp servers.

Thank You!
Libin Varghese

View solution in original post

Below article explains configuring scp push for mail_logs on the appliance.

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/200985-Configuring-SCP-push-of-mail-logs-on-ESA.html

You can choose to set this up for all available logs on the appliance or the major ones of your choice. This would require understanding and knowledge of linux servers to set up a server to receive the logs from the ESA.

You could also FTP/SCP using application such as winscp to the interface of the appliance and manually download copies of the logs to your computer of choice.

Install winscp and connect to the IP of the appliance using ftp.

Note: FTP access must be enabled on the interface under Network -> IP Interfaces for this to work.

This would allow you access to the configuration directory of the appliance which has all the logs stored.

- Libin V

View solution in original post

9 Replies 9

Libin Varghese
Cisco Employee
Cisco Employee

Hi,

In order to move configuration from one appliance to another, both devices should be on the same Async OS release.

You would need to start by upgrading the appliances so that they are on the same Async OS version.

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117793-technote-esa-00.html

The configuration file can be exported from the GUI System Administration -> Configuration File.

Note: Please ensure the configuration file is exported with passwords unmasked.

Alternatively, you could also add a device to an existing cluster to copy over the cluster level configuration.

Steps to import the configuration file is available below:
http://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117841-technote-esareplace-00.html

For appliances of different models such as x70 and x90 series in your scenario, when importing the configuration file between different models of appliances, you will frequently receive errors. These are caused by differences in available Ethernet ports, and database sizes for tracking and reporting.

You will need to make some manual modifications to the file in order for it to import:

1. Export the configuration file from both the source and destination ESAs. Be sure to uncheck the 'Mask passwords' option
2. Open both configuration files in a text editor
3. Find the following entries in both configuration files, and copy the values from the destination appliance's configuration file to the source configuration file:
<db_environment_actual_size>
<tracking_global_max_db_size>
4. If the appliances have a different number of Ethernet interfaces, you will need to completely remove the following sections from the source configuration file:
<ethernet_settings> ... </ethernet_settings>
<ports> ... </ports>
5. Save a copy of the modified source configuration file
6. Import the modified configuration file on the destination appliance
7. Commit the changes

Only configuration files are transferred between ESA's. All local logs, tracking, reports, quarantines, etc would need to be moved to the SMA or pushed to syslog/scp servers.

Thank You!
Libin Varghese

Thank you Libin!

We are using SMA to save Message tracking and spam quarantine and I would like to take the backup of Mail_logs and policy,virus and outbreak quarantines. Let me know what are the other important things which I need to take backup?

Could you please explain how to move to SMA or pushed to syslog/scp servers as this is new thing to me?

Below article explains configuring scp push for mail_logs on the appliance.

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/200985-Configuring-SCP-push-of-mail-logs-on-ESA.html

You can choose to set this up for all available logs on the appliance or the major ones of your choice. This would require understanding and knowledge of linux servers to set up a server to receive the logs from the ESA.

You could also FTP/SCP using application such as winscp to the interface of the appliance and manually download copies of the logs to your computer of choice.

Install winscp and connect to the IP of the appliance using ftp.

Note: FTP access must be enabled on the interface under Network -> IP Interfaces for this to work.

This would allow you access to the configuration directory of the appliance which has all the logs stored.

- Libin V

I would like to know on how to import End user Safelist/Blocklist file to new appliance from old appliance.  

Go to System Administration/Configuration File menu, there's a section to back it up and restore it.

Back it up on the C670, copy it from the 670 using FTP (its in the configuration directory), then copy it to the 690 using FTP (put it in the configuration directory), then you can restore it on the 690

You can backup the SLBL for the ESA from System Administraion -> Configuration File.

 

Scroll to the End-User Safelist/Blocklist Database (Spam Quarantine) section.

 

The appliance saves a .csv file to the /configuration directory of the appliance using the following naming convention:
slbl<serial number><timestamp>.csv

 

You can FTP to the appliance to retrieve the file and then send it to the replacement appliance over ftp as described in the beloew article.

 

https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/117922-technote-esa-00.html

 

Regards,

Libin Varghese

Hi Libin,

We have almost 120 domains in our environment and would like to migrate 5 domains each time to C690. So, could you please advice on how can we import configuration file on replacement ESA?

Many thanks in advance.

Hi there,

There is nothing preventing you from having all 120 domains in the configuration file on the new appliance, and redirecting Mail Exchanger records 5 domains at a time when you're ready. I would recommend to cluster the old and the new appliance, synchronise their configuration, and then gradually port MXs to new hostname.

Hi,
Could you please suggest us, how to cluster Old and New appliance? and after synchronization need to remove the old appliance.
Please explain us in detail merits/de-merits as well. Many Thanks