04-08-2019 01:40 AM
I am running ISE 2.4 with patch 5.
I have scheduled a SFTP weekly configuration backup to a NAS protected by a FW.(See config attached).
the port 22 is open.
The weekly configuration backup runs on Sunday. On Monday, when I check the backup is frozen at 0 percent.
When I run the same backup with the CLI :
backup UKL78PTAC01_Weekly_Backup_xxx repository SFTP_NAS ise-config encryption-key plain xxxx
UKL78PTAC01/admin# backup UKL78PTAC01_Weekly_Backup_xxxx repository SFTP_NAS ise-config encryption-key plain xxxx
% Internal CA Store is not included in this backup. It is recommended to export it using "application configure ise" CLI command
% Creating backup with timestamped filename: UKL78PTAC01_Weekly_Backup_xxxx-CFG10-190408-0758.tar.gpg
% backup in progress: Starting Backup...10% completed
% backup in progress: Validating ISE Node Role...15% completed
% backup in progress: Backing up ISE Configuration Data...20% completed
% backup in progress: Backing up ISE Indexing Engine Data...45% completed
% backup in progress: Backing up ISE Logs...50% completed
% backup in progress: Completing ISE Backup Staging...55% completed
% backup in progress: Backing up ADEOS configuration...55% completed
% backup in progress: Moving Backup file to the repository...75% completed
% backup in progress: Completing Backup...100% completed
UKL78PTAC01/admin#
It works.
When I select the NAS_SFTP repository, I cannot see the stored backup files.
Any idea ?
Do I have to open another port in the FW which may be used by the GUJI and not with the CLI backup command?
Thanks
Solved! Go to Solution.
04-10-2019 02:16 AM
I can confirm that:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp12131
Exists also in ISE 2.4 Patch 7.
04-10-2019 11:24 PM
Hi mate,
Was their any event that occured during the scheduled date.
I have had this experience before where WAN link was under maintenance and we lost communication to ISE.
We noticed that backup was stuck to some percentage and the only way to clear it was through the Root access on ISE.
TAC should be able to generate Root Patch for you and will clear the session that is stuck.
Thanks.
04-08-2019 04:12 AM
This patch level is after the SFTP backup failures have been fixed.
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvj86877/?rfs=iqvred
Since you can perform the SFTP backup via CLI, this means that your SFTP server supports the SSH client you have installed for ISE (sometimes there can be incompatibilities due to key-exchange mechanisms and such).
What this leaves us with is a bug.
Here are known bugs you may be encountering:
1) https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvo21622/?rfs=iqvred
2) https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg52304/?rfs=iqvred
If neither of them seem to be the cause, I'd try the following:
1) Rather than scheduled, try a manual backup to the repository via GUI. Does this work? If so, the problem is with scheduled backups. Open a TAC case.
2) If manual backups via GUI don't work, try performing a manual backup with a simple password (less than 16 characters, alpha-numeric characters only). Does this work? If so, the problem is supported password characters/length via GUI. Open a TAC case.
04-08-2019 06:40 AM
Thanks.
i have tried several sftp transfers as you advised (manual with GUI and/or short password) but no way. I will check the Firewall with the IT team, just in case some other ports are needed. Only the CLI sftp transfer works.
04-08-2019 06:46 AM
04-10-2019 02:16 AM
I can confirm that:
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvp12131
Exists also in ISE 2.4 Patch 7.
04-10-2019 11:11 AM
04-10-2019 11:24 PM
Hi mate,
Was their any event that occured during the scheduled date.
I have had this experience before where WAN link was under maintenance and we lost communication to ISE.
We noticed that backup was stuck to some percentage and the only way to clear it was through the Root access on ISE.
TAC should be able to generate Root Patch for you and will clear the session that is stuck.
Thanks.
04-11-2019 08:33 AM
Hi,
This specific bug is a matter of configuration persistence. Something is configured, the PAN is reset, that configuration no longer sticks and needs to be reconfigured. The backup isn't even attempted at the scheduled time until you enable and disable scheduled backups.
04-08-2019 10:19 AM
05-20-2019 01:59 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide