cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1266
Views
5
Helpful
1
Replies

Config missing on vDefense Center 6.0.0.1-26 after restore

brianjp2472
Level 1
Level 1

Testing restore operation and after I uploaded and restored the backup, I am now missing config. The following information did not get restored during the process.

  • Sensors were missing
  • my SSH remote storage profile was gone
  • My backup profile was gone

What WAS there:

  • scheduled task for backup job
  • Licensing ( because I preserved the MAC)
  • Custom time server

What I have done:

Since the system came back up and finished the restore, I decided to reboot the DC. Once I did that and it came back up, Both sensors were there and were showing online, although my SSH remote storage profile and backup profile was still missing. BUT...about 5 minutes later the sensors were removed, or "unregistered". I am also seeing a "Unable to restore CSM" on the restore file job.

Selection_090.png

I am not sure whats going on here but here is my scenario that led to all this:

1. Built and updated the Defense Center to 6.0.0.1

2- Attached 2 sensors and updated to 6.0.0.1

3- Configured SSH remote storage, a backup profile, and a scheduled task for daily backups.

4 - Imported rules.

5. Licensed the DC and the sensors

6. Setup NTP

7. Took a backup using my SSH remote storage to a RHEL 6 box

8. Blew the VM for the DC away.

9. Redeployed using the OVF ( and reverted to the old MAC address)

10. Updated the new DC to 6.0.0.1

11. Restored the backup

12. Missing info as I have already reported.

13. Rebooted.

14. Senors returned but were in a "disabled" state.

15. Re-applied the backup and rebooted.

16. After reboot sensors came back up and returned to a normal state.

15. Sensors then went "ungregistered" and missing after about 3 minutes.

NOTE: This is a virtual environment of Cisco Firepower Mgmt Center for Vmware. Has anyone ever ran into this issue before?

UPDATE:

I also want to add that on the DC itself, the sftunnel process is running however the deamon is not listening on 8305 as it should be. On the sensors themselves, the sftunnel.conf file is gone and the process is not running or listening on 8305.

1 Reply 1

keglass
Level 7
Level 7

brianjp2472,

I recommend you also post this to the Cisco Support Community for additional feedback and information.

https://supportforums.cisco.com/

Thank you for participating in the community.

Kelli Glass

Moderator for Cisco Customer Communities

Review Cisco Networking for a $25 gift card