cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1804
Views
0
Helpful
4
Replies

CUPS Backup issue

ankit.joshi
Level 1
Level 1

Hi All,

I am trying to configure Backup for CUPS 7.0.2. Initially when I checked(before doing any troubleshooting) in DRF to see any Backup devices are configured I found below message.

Status:  Local Agent is not responding. This may be due to Master or Local Agent being down.

I verified that bot DRF Master and local services were running. I restarted them but did not make any difference.
After doing some research I found this error may be related to bug "CSCsz44417". I followed work around procedure as below

Workaround
Download CUP Publisher IPSec cert through OS admin GUI (Security ->
Certificate mgmt -> Find -> "ipsec.pem" -> download. Download to PC/Laptop.
Then go to each node of the cluster (including CUP Pub) and upload "ipsec.pem" as ipsec-trust through OS admin GUI (Security -> Certificate mgmt -> upload cert -> Certficate Name = ipsec-trust -> Browser the PC where ipsec.pem was downloaded ->
Upload file).

Uploaded new ipsec.pem certificate as ipsec.trust and restarted DRF master and local service.

When I checked status was still same.

On one of the ciscosupport forrum, suggestion was to regenerate ipsec.pem and then upload it as ipsec-trust.

I followed procedure and regenerated ipsec.pem. Deleted old ipsec-trust that I uploaded earlier.
Issue is now when I try to upload regenerated ipsec.pem cert as ipsec-trust it is giving me below error
"The file /usr/local/platform/upload/certs/ipsec.pem could not be uploaded" AND also  status of DRF Master and Local services is
Cisco DRF Local[STOPPED]  Component is not running
Cisco DRF Master[STOPPED]  Component is not running

Any ideas or suggestions?

TIA, Ankit

4 Replies 4

bvanturn
Cisco Employee
Cisco Employee

Hi Ankit,

You can remove first the old ipsec.pem file that you uploaded as the ipsec-trust certificate. It will no longer be valid anyways as you regenerated the ipsec certificate. Then try if you can reupload the newly generated ipsec.pem file as an ipsec-trust on all nodes followed by a reboot of the cluster.

If still no luck you may want to try to upgrade, 7.0(9) is the latest version available. Upgrading to the latest maintenance release should be part of best practice.

Thanks, I already tried that but did not make any difference. I deleted ipsec-trust after regenerating ipsec.pem. But now It wont let me upload again as ipsec-trust file and I am not sure why I DRF Master and Local service is failing to start?, any idea?. Yes, upgrade is also an option.

Hi Ankit,

Too bad that did not help. Did you try to reboot the server already before uploading again? I would try the upgrade route first to see if that way the system can fix itself. If that does not help probably best to open a TAC case so we can take a look at the system to see what certs are present.

Did rebooted server, DRF Mast and Local services are running and I can upload ipsec.pem certificate as well. But still getting same error message

as before while trying to configure Scheduled backup.

Status:Local Agent is not responding. This may be due to Master or Local Agent being down.


Looks like upgrade is the only option